Loupe iOS Fingerprinting Explorer by Mysk

Just discovered Loupe, a new open-source iOS app by Mysk that shows you what device data apps can access for fingerprinting.

Pretty wild what’s all fingerprintable

GitHub

App Store

3 Likes

I respect the creator for being explicit that the app is vibe-coded but, no thanks.

Loupe was written almost entirely by AI coding tools.

1 Like

https://inv.nadeko.net/watch?v=_n_SpEWtqog

Here’s the app for people want to look at it. Hopefully Apple doesn’t remove it from the App Store!

Browser fingerprinting and app permissions are just really far behind the fingerprinting industry. Cookies are old news, browser fingerprinting is distrubingly effective at correlating anonymous users on normal browsers.

Tor and Mullvad browser are likely the most and only effective privacy browsers at preventing commercial fingerprinting but they sacrifice usability and security. And I’m not even sure of their efficacy. Perhaps there’s research on the topic.

While content blockers likely don’t harm your privacy besides increasing attack surface, they are certainly completely ineffective at cross-site tracking because of fingerprinting.

This is why LibRedirect or perhaps a MV3 version should be recommended more. It takes you off these websites automatically blocking any connection from the redirectee site.

It’s a shame that browsers like Brave and Vanadium don’t meaningfully improve on fingerprinting protection. They’re essentially telemetry - less Chrome. I do highly respect Brave’s rust shields implementation for web enjoyment, however.

I’d like to see a privacy focused anti detect browser like Donut browser with effective profiles. Donut browser is pretty cool because you can assign a proxy or VPN config per profile and the profiles aren’t detected as privacy hardened browsers, so you can easily sign up for things while seperating identities. I think Donut Browser is just like a launcher for different anti-detect browser profiles, so the app is open source but the browsers it launches aren’t. Could definitely be wrong on this.

Feel free to talk more on topic below me :sweat_smile: , this app is fascinating!

PS Apple could massively improve privacy protections by simply banning apps from collecting this data and not allowing location tracking for apps that sell data. Apple has huge power with the App store, so I respect when they make good decisions like the tracking function, but they could do a shit ton more.

2 Likes

Badness Enumeration is what im getting at.

Its the enumerating badness argument. The best way to not get tracked by apps is to not use apps with trackers.

1 Like

It uses public iOS APIs, so it is limited by trusting what Apple shows the application to begin with, and ignores other APIs that may be exfiltrating data, especially the privileged system paths Apple themselves uses.

I tried this and it wasn’t nearly as bad as it seemed before I used it. There’s a few egregious ones like creation/restart date, copy pastes, (which apple might have fixed maybe I saw something) and Apple’s own identifiers. The most concerning one to me was more privacy than fingerprinting, that is that any app can access sensors without asking.

I then tried their browser, which is not good in any regard.

1 Like

I’m tired…

I’m feeling like “fine, you win, have everything, my habits, aliases, nudes, chats.. I give up and lay bare before my overlords”

At least there’s nothing illegal. Well, until the government become less tolerant of something or other, then “guess I’ll die”?

1 Like

Do you have a threat model created? That’s the best way to avoid burning out and overdoing stuff.

3 Likes

In addition to providing relevant advice instead of generic suggestions.

It’s wild how much data native apps can silently collect passively without ever prompting for a single permission

1 Like

No offense, but you also gave 15+ times the exact comment “That/It depends on your threat model.” over the last months and I don’t see why you should call others out on responding generically when their comment fit and they shortly elaborate.

3 Likes

I tried by that article and ended up overthinking and catastrophising but that’s normal for me…

My threats and risks are nothing special to be fair. Mostly “surveillance capitalism” but I also (over)think about all this constant tracking and linking of accounts, browser profiles, apps and so on being leaked in some way and used against me by a stalker (I’ve had online stalking behavior towards me, nothing too bad just creepy) or someone on that site where someone can decide you’re a “lolcow” and harass you for giggles. Paranoia basically. Law enforcement not much of a threat as I don’t do anything that would upset them (maybe the odd copyright holder), at least for as long as what is legal now remains legal. I suppose there’s no point being scared of hypothetical changes that no one has even suggested.

I do sometimes worry when it comes to mass government surveillance about stumbling across one of those infamous Grok creations for example, which I wouldn’t want to, merely loading it being tracked and traced and having to try and prove that I didn’t look for it. It’s not happened though, and I’m especially careful these days around unregulated NSFW as well as mostly avoiding social media.

If I’m honest the tl;dr very rough “shape” of a threat model is your typical average person who just doesn’t want one little mention of a vacuum cleaner to mean being spammed with ads for them for the next 6 weeks and just finds it all very creepy. But is also chronically online, embodies a few things people hate (supporter of all the letters in LGBT for example) and with more than a fair share of paranoia and overthinking.

It just makes me wonder the point sometimes when it seems like no matter what you do, you’re always tracked and fingerprinted. You block cookies and other trackers and they just shrug and fingerprint your browser. You use the browser less and they just shrug and fingerprint your apps. Always one step ahead.