Company
Date Published
Author
Konstantin Darutkin
Word count
722
Language
English
Hacker News points
None

Summary

This article introduces a technique for detecting an Apple ID region without user permissions through the use of Smart App Banners, which were introduced with iOS 6 to help developers promote their apps on the web. The Apple ID region, linked to a user's billing address, affects app availability, pricing, and access to services such as Apple Pay and Apple News. The article describes a method where attackers can perform a binary search over the 175 available regions in the App Store by using region-specific iOS applications and Smart App Banners, allowing them to pinpoint a user's exact country. This technique poses a privacy threat as it can contribute to fingerprinting, enabling third parties to track users across different platforms. The company, Fingerprint, clarifies that it does not employ this technique and advocates for open discussions to help browser providers address such vulnerabilities.