Hacker News new | ask | show | jobs
by kevincox 2030 days ago
It seems like some of these features were loading images directly from the client. So presumably this could have been used to get info like your browser and IP as your phone made the request to the server that they provided.

The recommended work around to to just send the link which now makes it explicit to the user that they are connecting to the third party.

1 comments

If this theory is correct, sounds like they want to avoid another Cambridge Analytics incident.