3 ms·
I'm not aware of the technical details of how the user is tracked. Is it possible to be tracked even if the user has logged out of the social network website (b
by archangel11235 11y ago
I'm not aware of the technical details of how the user is tracked. Is it possible to be tracked even if the user has logged out of the social network website (based on the browser or machine being used)?
- stanleydrew 11y agoThe technical details are simple. When you are "logged in" to Facebook, your browser stores a unique token in a cookie that can identify you. That unique token is sent with every request the browser sends to FB, even requests you don't initiate directly. These hidden requests happen all the time, like when a web developer embeds a FB like button on a page. The like button is actually generated and served by FB's servers (check your browser's dev console), and the request to show the button itself gets that cookie sent along with it regardless of whether you press it. The tricky bit is that "logging out" might not actually be enough. I don't use FB so can't say for sure, but it is certainly possible to implement "log out" such that you can't see restricted resources or pages, but still have an identifying cookie on your machine. In this case the cookie itself would store a flag marking you as "logged in" or "logged out", but the cookie would still identify you all the same.
- chjohasbrouck 11y agoGood explanation. I don't know if it'd be worthwhile to track logged-out users though. Lumping it in with the same data that came from the last logged-in user would make the data less valuable, because there's far less of a guarantee of which user the data was collected from (imagine people using Facebook on a library computer, then logging out and 20 more people using the computer before someone else logs in). I'm sure there'd be some use for the data though, so I'm sure Facebook will gather it if they don't already have plans to. They could just earmark it with the probability that it applies to the given user. Or just lump it all together as anonymous data, I'm sure there's value in that too.
- archangel11235 11y agoIs it also possible that the user be tracked or is being tracked based on the machine used to access the internet (maybe over time for one to one mapping of user to machine)? Just curious.
- sbov 11y agoI like to always use incognito browsing sessions when logging into Facebook. At some point I cleared all my cookies too. I remember a while back an article was posted about how to uniquely identify users without cookies though. I don't recall the exact method though, or if in this scenario it would require javascript and not just a link to a like button.
- kaybe 11y agoBasically you're using the specs the browser sends about the computer - OS, screen size, add-ons installed.. this gets pretty unique. I've been able to identify friends on a local site just by knowing them and their computers. Check yourself here: https://panopticlick.eff.org/ https://panopticlick.eff.org/
- sbov 11y agoWas able to find it. Actually it's using etags. They work even if you disable cookies. Perfect identification, similar to cookies. Sites were using it before it came to light: https://en.wikipedia.org/wiki/HTTP_ETag#Tracking_using_ETags https://en.wikipedia.org/wiki/HTTP_ETag#Tracking_using_ETags
- pdkl95 11y agoYou don't even need ETags - if the server sends out a unique (or mostly unique) "Last-Modified" header, the browser will return the cookie in "If-Modified-Since".
- jlarocco 11y agoI'm not sure incognito browsing actually helps much. User tracking isn't a 100% accurate science, and your browser name, browser version, operating system, OS version, IP address, screen resolution, etc. are still getting sent along and they don't change by going incognito. It's no big deal for Facebook to just assume it's still you if the only thing that's changed is that you're no longer sending the same session cookie.
- pdkl95 11y ago