After multiple EU-based users complained about not being able to access Threads app through VPN, Meta confirmed it is blocking such efforts.

  • GunnarRunnar@kbin.social
    link
    fedilink
    arrow-up
    0
    ·
    1 year ago

    Are they afraid of legality and doing something so fishy that there’s no way it would fly in EU?

    Or is it just that this day and age it’s expected that VPNs are blocked? Like with Netflix etc.

    • axum@kbin.social
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      Facebook isn’t interested in complying to EU’s privacy laws at this point, so they’re blocking it off entirely

  • Anomandaris@kbin.social
    link
    fedilink
    arrow-up
    0
    ·
    1 year ago

    It would be interesting to see exactly how Meta is managing to block VPN users. Is it simply a matter of looking up instagram or facebook account related to email addresses used to sign up? Is it evaluating some sort of browser fingerprint? That’s assuming VPN users are doing so via desktop, if it’s an Android device for example is the OS itself providing information that’s not getting obfuscated by the VPN?

    • SamsonSeinfelder@feddit.de
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      1 year ago

      I think Meta has very complex fingerprint service in their backend after all these years. They know what you are doing even when you are not using their service. Their tracking in bundled up in long chains of tracking services over many websites. As long as you use a non vanilla browser to access their service, they might have you in their database from a previous tracker that trapped you on one of the many websites that are selling/trading tracking fingerprints. Since a decade it is not about the IP anymore. You can data-triangulate personas and pinpoint them to an existing user-profile with a very high accuracy. It should be possible to visit the threads service with a VPN and a heavy neutered browser. But then again, if your request is to suspicious in its request (thinking tor-browser, command-line browser, etc.) they might put you as well on a detour for a captcha/recognizer that will look harmless in the fronted (“click all the cars!”) but its actual task is processing/scraping a fingerprint from your display-device (browser) that then again can be connected with this suspicious request for the future. I am sure that their VPN block is not 100% blocking Europeans, but will block most of the unsophisticated request from normal users that will just give up after some tries.

      Here are some vectors for identifying users (via browserleaks): IP, JavaScript, WebRTC, Canvas, WebGL, Installed Fonts, Geolocation, Feature Detection, SSL certs, content filter.

      Edit: I might get some downvotes for this, but iOS has some good protections build into their OS layer (so they say) to make it harder for advertisers to track you. See also this very well done 1 Minute ad showcasing how the modern internet ad industry works.

      • wanderingmagus@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 year ago

        Not that I’d ever want to touch Threads with a ten-foot pole, but what options would there be to circumvent that sort of intrusion?

        • Anomandaris@kbin.social
          link
          fedilink
          arrow-up
          0
          arrow-down
          1
          ·
          1 year ago

          One of the topics I’ve seen become more prevalent in recent years is the idea of limiting your use of privacy addons and softwares, with the aim of trying to prevent your fingerprint becoming too unique.

          For example, there are probably a billion users with 21 inch monitors, running Windows 11, browsing on Google Chrome. Providing them with that information just makes you one more in the bunch, but if you stack up privacy addons you end up creating a more easily identifiable picture of yourself through the hole you created by hiding information.

    • Fantasy@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      Probably by just looking at the IP address, either due to the IP addresses of the VPNs being public or by the fact that many users are accessing the service through a single IP address