The Times Australia
The Times World News

.

Instagram and Facebook are stalking you on websites accessed through their apps. What can you do about it?

  • Written by David Tuffley, Senior Lecturer in Applied Ethics & CyberSecurity, Griffith University
Instagram and Facebook are stalking you on websites accessed through their apps. What can you do about it?

Social media platforms have had some bad press[1] in recent times, largely prompted by the vast extent of their data collection. Now Meta, the parent company of Facebook and Instagram, has upped the ante.

Not content with following every move you make on its apps, Meta has reportedly devised a way to also know everything you do in external websites accessed through its apps. Why is it going to such lengths? And is there a way to avoid this surveillance?

‘Injecting’ code to follow you

Meta has a custom in-app browser that operates on Facebook, Instagram and any website you might click through to from both these apps.

Now ex-Google engineer and privacy researcher Felix Krause has discovered this proprietary browser has additional program code inserted into it. Krause developed a tool that found[2] Instagram and Facebook added up to 18 lines of code to websites visited through Meta’s in-app browsers.

This “code injection” enables user tracking and overrides tracking restrictions that browsers such as Chrome and Safari have in place. It allows Meta to collect sensitive user information, including “every button and link tapped, text selections, screenshots, as well as any form inputs, like passwords, addresses and credit card numbers”.

Krause published his findings[3] online on August 10, including samples of the actual code[4].

In response, Meta has said it isn’t doing anything users didn’t consent to. A Meta spokesperson said:

We intentionally developed this code to honour people’s [Ask to track] choices on our platforms […] The code allows us to aggregate user data before using it for targeted advertising or measurement purposes.

The “code” mentioned in the case is pcm.js[5] – a script that acts to aggregate a user’s browsing activities. Meta says the script is inserted based on whether users have given consent – and information gained is used only for advertising purposes.

So is it acting ethically? Well, the company has done due diligence by informing users of its intention to collect an expanded range[6] of data. However, it stopped short of making clear what the full implications of doing so would be.

People might give their consent to tracking in a more general sense, but “informed” consent implies full knowledge of the possible consequences. And, in this case, users were not explicitly made aware their activities on other sites could be followed through a code injection.

Why is Meta doing this?

Data are the central commodity of Meta’s business model. There is astronomical value in the amount of data Meta can collect by injecting a tracking code into third-party websites opened through the Instagram and Facebook apps.

At the same time, Meta’s business model is being threatened – and events from the recent past can help shed light on why it’s doing this in the first place.

It boils down to the fact that Apple (which owns the Safari browser), Google (which owns Chrome) and the Firefox browser are all actively placing restrictions on Meta’s ability to collect data.

Read more: Stuff-up or conspiracy? Whistleblowers claim Facebook deliberately let important non-news pages go down in news blackout[7]

Last year, Apple’s iOS 14.5 update came alongside a requirement[8] that all apps hosted on the Apple app store must get users’ explicit permission to track and collect their data across apps owned by other companies.

Meta has publicly[9] said this single iPhone alert is costing its Facebook business US$10 billion each year.

Apple’s Safari browser also applies a default setting to block all third-party “cookies”. These are little chunks of tracking code[10] that websites deposit on your computer and which tell the website’s owner about your visit to the site.

Google will also soon be phasing out third-party cookies. And Firefox recently announced “total cookie protection” to prevent so-called cross-page tracking.

In other words, Meta is being flanked by browsers introducing restrictions on extensive user data tracking. Its response was to create its own browser that circumvents these restrictions.

How can I protect myself?

On the bright side, users concerned about privacy do have some options.

The easiest way to stop Meta tracking your external activities through its in-app browser is to simply not use it; make sure you’re opening web pages in a trusted browser of choice such as Safari, Chrome or Firefox (via the screen shown below).

Click ‘open in browser’ to open a website in a trusted browser such as Safari. screenshot

If you can’t find this screen option, you can manually copy and paste the web address into a trusted browser.

Another option is to access the social media platforms via a browser. So instead of using the Instagram or Facebook app, visit the sites by entering their URL into your trusted browser’s search bar. This should also solve the tracking problem.

I’m not suggesting you ditch Facebook or Instagram altogether. We should be careful about our online activities like investigating properly before deciding to buy Instagram followers from Growthoid or other sources. We should all be aware of how our online movements and usage patterns may be carefully recorded and used in ways we’re not told about. Remember: on the internet, if the service is free, you’re probably the product.

Read more: Is it even possible to regulate Facebook effectively? Time and again, attempts have led to the same outcome[11]

References

  1. ^ press (theconversation.com)
  2. ^ found (krausefx.com)
  3. ^ findings (krausefx.com)
  4. ^ actual code (connect.facebook.net)
  5. ^ pcm.js (connect.facebook.net)
  6. ^ an expanded range (www.facebook.com)
  7. ^ Stuff-up or conspiracy? Whistleblowers claim Facebook deliberately let important non-news pages go down in news blackout (theconversation.com)
  8. ^ requirement (www.apple.com)
  9. ^ publicly (krausefx.com)
  10. ^ tracking code (www.trendmicro.com)
  11. ^ Is it even possible to regulate Facebook effectively? Time and again, attempts have led to the same outcome (theconversation.com)

Read more https://theconversation.com/instagram-and-facebook-are-stalking-you-on-websites-accessed-through-their-apps-what-can-you-do-about-it-188645

Times Magazine

Headless CMS in Digital Twins and 3D Product Experiences

Image by freepik As the metaverse becomes more advanced and accessible, it's clear that multiple sectors will use digital twins and 3D product experiences to visualize, connect, and streamline efforts better. A digital twin is a virtual replica of ...

The Decline of Hyper-Casual: How Mid-Core Mobile Games Took Over in 2025

In recent years, the mobile gaming landscape has undergone a significant transformation, with mid-core mobile games emerging as the dominant force in app stores by 2025. This shift is underpinned by changing user habits and evolving monetization tr...

Understanding ITIL 4 and PRINCE2 Project Management Synergy

Key Highlights ITIL 4 focuses on IT service management, emphasising continual improvement and value creation through modern digital transformation approaches. PRINCE2 project management supports systematic planning and execution of projects wit...

What AI Adoption Means for the Future of Workplace Risk Management

Image by freepik As industrial operations become more complex and fast-paced, the risks faced by workers and employers alike continue to grow. Traditional safety models—reliant on manual oversight, reactive investigations, and standardised checklist...

From Beach Bops to Alpine Anthems: Your Sonos Survival Guide for a Long Weekend Escape

Alright, fellow adventurers and relaxation enthusiasts! So, you've packed your bags, charged your devices, and mentally prepared for that glorious King's Birthday long weekend. But hold on, are you really ready? Because a true long weekend warrior kn...

Effective Commercial Pest Control Solutions for a Safer Workplace

Keeping a workplace clean, safe, and free from pests is essential for maintaining productivity, protecting employee health, and upholding a company's reputation. Pests pose health risks, can cause structural damage, and can lead to serious legal an...

The Times Features

Tricia Paoluccio designer to the stars

The Case for Nuturing Creativity in the Classroom, and in our Lives I am an actress and an artist who has had the privilege of sharing my work across many countries, touring my ...

Duke of Dural to Get Rooftop Bar as New Owners Invest in Venue Upgrade

The Duke of Dural, in Sydney’s north-west, is set for a major uplift under new ownership, following its acquisition by hospitality group Good Beer Company this week. Led by resp...

Prefab’s Second Life: Why Australia’s Backyard Boom Needs a Circular Makeover

The humble granny flat is being reimagined not just as a fix for housing shortages, but as a cornerstone of circular, factory-built architecture. But are our systems ready to s...

Melbourne’s Burglary Boom: Break-Ins Surge Nearly 25%

Victorian homeowners are being warned to act now, as rising break-ins and falling arrest rates paint a worrying picture for suburban safety. Melbourne residents are facing an ...

Exploring the Curriculum at a Modern Junior School in Melbourne

Key Highlights The curriculum at junior schools emphasises whole-person development, catering to children’s physical, emotional, and intellectual needs. It ensures early year...

Distressed by all the bad news? Here’s how to stay informed but still look after yourself

If you’re feeling like the news is particularly bad at the moment, you’re not alone. But many of us can’t look away – and don’t want to. Engaging with news can help us make ...