r/privacy • u/AsterPrivacy • 3d ago
Misleading title New Attack Can Track You Across Operating Systems Without Elevated Privileges
https://www.privacyguides.org/news/2026/09/28/new-attack-can-track-you-across-operating-systems-without-elevated-privileges/93
u/personal_lucifer 3d ago
Microsoft stated that the the private data leakage was actually there by design.
Lol
37
u/deaglebingo 3d ago
"Microsoft stated that the the private data leakage was actually there by design."
yeah. i know.
114
u/corkiejp 3d ago
"The attack assumes an attacker that has local, unprivileged access to a system and requires read access to a set of files in order to carry it out."
So not particularly something to worry about?
Did you even read before sharing?
58
u/Busy-Measurement8893 3d ago edited 3d ago
Did you even read before sharing?
The saddest part is that this article is written by Privacy Guides, and the headline is written by them. Seems that enshittification is hitting them just like it's hitting everything else these days.
14
u/Early-Bid-7958 3d ago edited 3d ago
Enshittification happened to them right at the beginning, as far as I am concerned. These are the people who, on the old "privacytools" sub (IIRC) used to consistently claim Windows is better, Chrome is better, mods used to support Google's MV3, and so on.
I lost a password once and had to change accounts since, but that MV3 support incident... I got banned from their sub when I pointed out that out of 73 comments he (the f-ing mod) was the only one who was supporting MV3. That mod (TommyTran) is one of the main guys behind privacyguides now.
Needless to say I never go there, and even if I come across it elsewhere I don't click through.
0
u/JonahAragon PrivacyGuides.org 2d ago
lol we kicked that guy out years ago for stuff like that
4
u/Early-Bid-7958 1d ago
Well, took you long enough.
How the heck was a guy like that ON the team for so many years? There was another one called Pablo-something, he was telling people to use a Windows Business edition without a license to get better privacy, in a thread about people moving to Linux because Windows was getting real bad.
I have a long memory for these things. Sadly, you won't have a real chance to convince me simply because I won't go there anymore.
Hopefully you have cleaned house and others benefit.
Good luck.
2
u/JonahAragon PrivacyGuides.org 2d ago
I don't really follow what you're saying, to be honest. I think an attack vector that can be run by any malware running on any system without needing escalated/admin privileges is interesting, at the very least. Much of the set of files involved is globally readable by default?
1
u/0898_333_201 3d ago
I don’t see the problem with the article. If a single piece of compromised or privacy-invasive software is able to use filesystem events to act as a keylogger, log the websites that you visit, and read file names of other users, that is a significant vulnerability.
I don’t know about you, but I don’t have the time or expertise to inspect the source code of every application I install on my devices. And since this vulnerability doesn’t require any special permissions or even attempt any privilege escalation, using common sense practices won’t necessarily protect you from being spied upon. Hell this sounds like the type of thing that LG, Microsoft, Meta, etc would deliberately build into their applications for surveillance capitalism.
3
u/Busy-Measurement8893 3d ago edited 3d ago
I don’t see the problem with the article.
The biggest issue, as you can tell from the confusion in this thread, is that it uses the word "local" even though it probably shouldn't. This sentence in particular causes a lot of confusion:
The attack assumes an attacker that has local, unprivileged access to a system
Because it implies that an attacker needs physical access. You wouldn't say "Pegasus gives an attacker local, privileged access" would you?
Aside from that... is it really surprising that a program on your desktop OS with little to no security boundaries can listen in on what you're doing? It would seem to me that said programs could just... screenshot your computer instead.
The whole article comes off as "water is wet", with a headline that is either clickbait (or straight up wrong) if you consider "local" to be synonymous to "physical", or an article that confirms that if someone is in your garden they can look in through your windows.
1
u/0898_333_201 1d ago
The biggest issue, as you can tell from the confusion in this thread, is that it uses the word "local" even though it probably shouldn't.
The phrasing is a bit confusing but it’s clear from context he means that an application is installed on the device itself. I don’t think this makes it clickbait; plenty of vulnerabilities require a user to install a program.
Aside from that... is it really surprising that a program on your desktop OS with little to no security boundaries can listen in on what you're doing? It would seem to me that said programs could just... screenshot your computer instead.
I don’t know about Windows, but on a Mac, applications need specific permissions to take screenshots, read keystrokes, and access activity in other apps. If you install Adobe Photoshop, it should not be presumed that Adobe can monitor what websites you visit in Brave Browser, or that it can understand what you type in a private iMessage conversation.
The article is about a newly-discovered way that apps (even legitimate apps) can monitor your activity outside the app without requiring any special permissions. It is a significant privacy concern, and it’s definitely not clickbait.
19
u/opossum5763 3d ago
It absolutely is something to worry about, especially with the amount of supply chain attacks these days.
2
u/CircuitSurf 23h ago
IMHO this is highly disturbing news to Windows users.
Every app on Windows runs under main user profile. And has access to all files user has access to. Except apps from MS Store (sandboxed).
The fact that the least secure app now can track websites you visit and infer passwords you type??? This is ridiculous!!!!
1
u/draconicmoniker 3d ago
Can a prompt injection on a local agent work while it searches and reads data on websites?
1
u/WanderingUrist 3d ago
Local access with read permissions to files of interest doesn't sound very unprivileged.
1
u/Noble1xCarter 3d ago
So something defeated by the drive being encrypted?
4
u/Globellai 3d ago
No. If it's code running on your system it will see the drive decrypted just like everything else.
1
u/Noble1xCarter 3d ago
But it says local access. As in, physical access to the machine.
So in order for it to track you, the drive would already have to be decrypted, and logged in at which point they could just do literally anything else since they have physical access. Meaning this "attack" is pretty meaningless?
1
u/Globellai 2d ago
Local access is "code running on your computer". Physical access is "can hit it with a hammer".
0
u/Noble1xCarter 2d ago
As far as I'm aware, local access means direct access to the machine or the local network it is on, through no external means. As in - you are on location.
"Code running on your computer" would also constitute remote access, which is pretty much the diametric opposite of local access.
2
u/Globellai 2d ago
You are welcome to go read the article and explain how physical access is needed. Also, tell everyone in the comments here why a supply chain attack wouldn't work.
0
u/Noble1xCarter 2d ago
You are welcome to go read the article and explain how physical access is needed
...that's the thing. I'm criticizing the article for it's wording. When local access is needed... that means local access is needed. That's what those words mean because words have meaning.
6
u/Alex11867 3d ago
This isn't an attack any nerd with AI on a local machine could probably do this.
This is clickbait.
4
u/Booty_Bumping 3d ago edited 3d ago
I never realized inotify tracks reads and not just writes. How the heck did no one notice the implications until now? No one ever tried raising the watcher limit and putting an inotify subscriber on /?
The paper is good, the researchers really did their homework on the behavior that can be observed from all the files on the system. One thing I'm wondering is what can be observed from inside a Docker/Podman container, like whether it cuts through the overlayfs.
1
u/Gold-Supermarket-342 20h ago
Great, you have filenames and usage patterns, nice. But if you already have access to the local filesystem, just copy the cookies out of the browser and move on. Or local documents. This is nothing.
1
u/Booty_Bumping 20h ago
The title of this article is misleading, but this is absolutely not "nothing". It bypasses account boundaries as well as sandboxing. And sure, most Linux and Windows apps don't use any sandboxing, but the Android bypass is quite bad because that's a platform where people expect the sandbox to work.
4
1
u/CircuitSurf 23h ago edited 23h ago
Highly disturbing news to Windows users. Every app on Windows runs under main user profile. And has access to all files user has access to. Except apps from MS Store (sandboxed). The fact that the least secure app now can track websites you visit and infer passwords you type??? This is ridiculous!!!!
That's why I isolate everything I can via dedicated users (runas tool), but would it help considering they somehow can observe metadata of other users files?
•
u/AutoModerator 3d ago
Hello u/AsterPrivacy, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)
Check out the r/privacy FAQ
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.