Hacker News new | past | comments | ask | show | jobs | submit | timsh's comments login

oops, here comes the price of a nice-looking Reddit embed. next time I’ll stick to a screenshot :) thanks!

agreed, however there are duplicates in that list + same app for ios / android. if I’m not mistaking I did a simple unique count on it (or catch the 2000 number from 404media post)

The “right” answer is not the one I end up with but rather the version sold by the vendor. this is what Apple and Google would say.

I think they are pretty clear if you read the documentation. Accessing to the exact value of these always need some privacy-related privilege on ios and android.

Without those privilege, all you can get is an approximate.


this is so precise. I guess we’ll need a global version of https://datacolada.org/ quite soon to not get hit by a bus in every scientific field

MAID = IDFA on ios + GAID on Android [https://www.start.io/glossary/mobile-ad-id-maid/]

I think he meant MAID <> PII

I decrypted them all by installing Charles SSL cert on the iphone. This is why the requests seem not SSL proxied.

This technique doesn't work anymore on android because you can no longer add certificates to the system store and apps are free to choose to accept the user store CAs or not. That was changed in Android 7. For "security" they say. Security of Googles business model I'm sure.

My apologies, thank you for clarifying and thank you for the brilliant article. Have updated my comment.

wow @apokryptein thanks for posting my article here... I'm shocked it's #1 rn. if anyone has any questions regarding the post - I'm here to answer & talk!

how the MAID/IDfV gets into the PII-ID databases?

It seems that part is completely missing. (Or I missed it.)

So for example can/do airlines sell it? Or telecom/utility companies, when you use their app?


I don’t know the answer to this, which is why I didn’t mention it in the post. However, I could speculate that these data-broker companies scrape leaked [hacked and stolen] data from various panels and then match records on their end. kinda OSINT for bad reasons.

Great article, thanks for taking the time to research and write it all up! Definitely learned some new things from it.

Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: