Automatically sync your streaming services!

Exact same issue here on Samsung Galaxy 24+ running Android 15. I’ve emailed support@trakt.tv, but the flow is identical to what’s been described…it takes the username, password, and two-factor hardware key, but then just resets and says it cant log in and asks for username again.

Oh, and the apple website works fine in my phone browser, i.e. the login works and doesn’t break.

I do have to agree. I don’t understand a lot about this so my take on this is much simpler than all your guys’ deep dive…
The login process itself already felt off to me as a casual internet user. It wasn’t going through the Amazon app or whatever but through a Weblink and I had to do a captcha thing in the end to get my login verified. Felt very weird.
Since Younify didn’t fetch any data hours later this is useless to me anyways and I changed my Amazon password after log out.
iCloud’s are getting hacked every day so I don’t see how this is safer in any way.
Also, someone said, that if I log into Netflix it is kinda the same process of verification but it’s not really. With Netflix I’m logging into the service I have an account for itself without going through a third party service. The third party service is the real problem here since I don’t really know what they actually do with my login data.

“since I don’t really know what they actually do with my login data”

I have to say, this comment is factually incorrect. Your login is entered directly into the service provider’s (amazon, Netflix, Hulu, and apple) website. Not through some 3rd party web page/domain/server.

Your streaming service credentials are 100 percent, without a doubt, not sent to, received by, or stored anywhere by any 3rd party. That part is empirically provable. What you are prompted with, when the Trakt app opens a window to connect to a service, is the provider’s own web login flow. Their own page, on their own website, on their own domain.

I understand this part may seem sketch to a laymen since it doesn’t open the native mobile app. But the actual login details are no less safe than if you had typed them into https://www.amazon.com on your phone’s native web browser. Short of the App store letting Trakt get away with publishing something with a key logger that could record your input as you type into that browser window, they are not going anywhere. Google Play has a less successful track record with reviewing malicious apps, but apple is fairly strict about that. And let’s be realistic here, that isn’t necessary for this kind of service and frankly not a desirable approach for almost any company. You also wouldn’t ever get prompts to reauthenticate if it was. There would be no need, as they’d have your password.

Whats being discussed is if that authenticated session, ever leaves your device or not. I’m of the opinion that it never does based on the evidence. But again, the credentials themselves are not at risk.

You’re welcome to believe that they are, If you wish. That’s your prerogative.

2 Likes

Thanks for clarifying that.
I still feel like this is not as safe as it sounds since the login session has to be held somewhere to fetch that data in weeks and months to come. Even with the services themselves you’d have to be online every now and then to verify you’re still a paying customer. This data being fetched offline on device itself seems unlikely to me.
Again I might be completely wrong here. But if even people like you have no guaranteed idea how this works why would I trust the process as someone who doesn’t know any of the programming of things?
And again, one has to be fairly cautious these days. Phishing is everywhere. We all get robo calls. I personally know people whose accounts have been hacked on multiple services and they are not idiots. Seeing these login captcha pages threw me off somehow. I like the idea of the service but I don’t like the way it’s asking for my data.
For all the people using this I sincerely hope I do not get proven right.

I have issues with Prime video syncing (I’m from Mexico) I hope you can resolve this :pensive:

I signed up for VIP a couple hours ago and connected all the services. No sync as of yet. Is the system down or something?

“I still feel like this is not as safe as it sounds”
We’re merely having a technical discussion of the attack surface for this implementation. As in what is exposed by using this feature and what isn’t. The criteria for “safe as it sounds” is subjective and no one is trying to convince you to do anything.

“since the login session has to be held somewhere to fetch that data”
Yes, in the browser client leveraged by the younify SDK, integrated into the trakt app, on your phone. That’s where, on your device. The session is local. Younify’s software on your phone, periodically scrapes the web page using that cached login session. A session which expires at the service’s (amazon, Netflix etc) own discretion. They might do it based on a lifetime value, device fingerprinting details changing, etc etc.

“This data being fetched offline on device itself seems unlikely to me.”
Not sure where you got that from. No one has ever claimed any part of this feature is done offline.

“why would I trust the process as someone who doesn’t know any of the programming of things?”

I really dont get why youre asking me this. Maybe you meant it rhetorically, but I dont work for trakt. I’m not trying to sell you on this feature. I dont care if you use it or not. We weren’t discussing that. I was trying to provide information and context on how I believe Younify’s service is implemented and the security implications of it.

Also, no one in the discussion so far has made claims of this being as secure as simply not using it. It’s inherently a compromise on data privacy. You have to trust that Younify is ethically handling your data once they are given access to it. But while security and privacy are related, they are not the same thing. And from a security standpoint, there have been some misconceptions about the technicals in this thread.

3 Likes

“mean that for every future sync Younify’s servers would have to contact your phone and ask it to do the processing”

No it wouldn’t. From an architectural standpoint, that isnt even remotely necessary in order to achieve background content capture. Your phone doesnt need to be listening for requests from younifys servers to kick off a sync.

“And even if it would work like this, wouldn’t it just be the same problem again? In order to be authorized to ask your phone to do the processing Younify’s server needs a password/token/cookie, which it stores either in memory or on disk…”

Again what is processed on their servers is almost certainly the content captured on device and sent to Younify. Rendered HTML. They can capture it locally using your cached login session and process it remotely. That doesnt require the session or credentials leaving your device. Just the content your device captured. A session, that can be maintained with persisted browser cache.

You can achieve the same thing with chromium drivers on node based applications and web scraping packages.

3 Likes

nope. ios has a variety background task apis that would allow registering periodic refreshes. Each with their own constraints and throttling rules. BGapprefresh task and BGprocessing task for instance. both of which can be executed every few hours with no guarantee of execution time but can be prioritized by the os based on network, power availability, charging state etc.

It was rhetorical, sorry for any confusion. I’m also not pointing fingers or anything. I’m just merely saying that for me as an end consumer the safety structure has not been made clear from official sites. So I’ll stay away from it.

Set Amazon Prime up on 5th @ 6pm. Sync’d this morning (8th) at 6am. So there is life.

Does this only work if watch on services via Apple or Android apps?

I watched on Netflix through TV app after setting up and nothing synced.

I was curious about this and the discussion that has been going on here, as this would mean the app would be doing the sync as a background task, which didn’t seem likely.

So I set up Netflix as a connection, then I uninstalled the app. Today my data synced from yesterday after the app was uninstalled. So how can the authentication possibly be held on my device if the app no longer exists on my device?

I’ve been hesitant about this from the beginning because Younify is owned by the same parent company that owns PlayOn, the software that breaks streaming service ToS and skirts the law when it comes to copyright.

I think between the people who run it, the testing around the validity of their claims and the discussion here, I’m going to hold off on this until there’s an API or equivalent for tracking watch history. It’s simply not worth running the risk of giving authentication tokens to anyone, let alone a company that seems deceptive about how they are being handled (and by that I do not mean Trakt, I mean Younify).

Personally I feel that associating with Younify is a bad move and will end poorly when inevitably something gets leaked or misused, but ultimately that’s up to you to decide. I think what you are trying to do is great but I think you’re taking a shortcut to get there and in doing so are working with a provider that plays fast and loose with security.

3 Likes

I set this up 4-5 days ago and nothing has been updating since. It did the initial sync but as I watch more shows nothing is updating.

3 Likes

I downloaded Trakt app on my secondary phone and tried to manage my Netflix account (from Trakt app) from the secondary phone and it doesn’t need to log in in order to see the profile.

I tried to change the profile photo in case it is cached on the server and the new profile photo was shown.

So can I said that the login credentials are not store on my local?

Cool! The title of this post and the name of the feature says “sync”, but from reading about it, it seems that Trakt just pulls in / mirrors data in the services.

Is this just a one-way copy, or is it a true (two-way) synchronization?

The functionality that I personally would value would be that my central source of truth (Trakt) has its watch status pushed out to all other services. (I currently have to rely on a finicky plugin to make that work with Plex.)

If I watch something that’s available on multiple services and log it in Trakt, I would love for that to then get pushed out to all the other services. (And indeed, I would rather that, precisely because of inconsistencies about how the timestamp of having watched a show is inconsistent across services, no services are able to write to Trakt at all; I only want a one-way push from Trakt to the other services!)

Could you share which plugin for Plex achieves that? I too find it timeconsuming to have to adjust the viewed status of something on my Plex server if I’ve watched something on a streaming server instead.

Happily!

You have to use WebTools (I have version 3.0.0) and install the Trakt Scrobbler through the UnsupportedAppStore, also described here.

While support has ended, and there are claims of incompatibility, this remains functional for me for now, so I’ll continue using it as is before playing around with a different solution.

That’s not correct. I set up Netflix sync on my Android phone two days ago, watched something on my TV yesterday, and it synced correctly when it hit the 24 hr mark (from the time I originally set it up to begin with). If this only synced with the phone it would be worthless to me; it just uses the “watched history” from the services themselves, regardless of device.

Same here after activating apple tv+, Netflix & Prime video no sync after 4days. I sent an email to the support let’s see :slight_smile:

1 Like