6 ms·
Facebook leaks user's IP addresses
- rdj 16y agoNot speculation. I just tried this with a few folks, and it works as advertised.
- hugh3 16y agobut not when a wife is trying to hide from an abusive husband and assumes Facebook is the best form of communication Is this the best scenario they could come up with where this is a problem?
- mcantelon 16y agoThis might have been a reference to a similar scenario regarding a Google privacy leak: http://bit.ly/bCrVll http://bit.ly/bCrVll
- hachiya 16y agoYep. Confirmed. Command line example: Take the Base64 string from this line in the headers: X-Facebook: from zuckmail ([OTguMTgzLjI0Ny4yMTg=]) $ ruby -rbase64 -e "puts Base64::decode64('NzQuMTI1Ljk1LjEwNA==')" 74.125.95.104
- bobbyi 16y agoThat confirms that it's a IP address, not that it's his.
- deleted 16y ago[deleted]
- rm-rf 16y agoOr - that confirms that it's 32 bit number that when represented as a dotted quad appears to be an IP address.
- spc476 16y agoI did the same for two Facebook notifications, from different friends, and both tagged their city (Tuscaloosa, AL didn't surprise me, but Blountstown, FL? That's fairly targetted).
- harshpotatoes 16y agoNote: I havent experimented with this yet. Are we sure this is the ip address of the user and not just the ip address of one of facebook's servers? If it is a user's address... is that a problem? This seems like very easy to obtain online information... for example, by sending an email to the person im trying to talk with via facebook...
- rdj 16y agoIt's the user (I tested with 2 friends to verify). Here's a scenario we talked about in my house: Once potential problem: friends-of-friends. A friend-of-friend comments on something your mutual friend put out, you then comment, the first friend (whom you don't know) can use this trick to ballpark your location.
- harshpotatoes 16y agoRight. But you're all talking to each other. It seems to me this same info would still be available to everyone if you were emailing each other. I don't really see this one as a huge security risk...
- natrius 16y agoDid you test the problem you described? If it works, this is the only potential flaw I see. Including IP addresses with messages still doesn't seem like a bad thing regardless.
- jsz0 16y agoIt allows some basic location tracking. The real world impact is minimal and easily obtained through other methods. If your friends or family want to track your location it's time to reconsider your relationships with them in my opinion.
- dmn001 16y agoPerl 1-liner: http://bit.ly/cNHkzQ http://bit.ly/cNHkzQ Every other day I see facebook and privacy in the same sentence..
- jacquesm 16y agoUsually with a negative in the sentence somewhere.
- natrius 16y ago"Every other day I see facebook and privacy in the same sentence.." That's because Facebook-bashing has become fashionable. There is absolutely nothing wrong with the behavior described in the article. It's how email is supposed to work. There is no way to accidentally include the IP address in an email header. They (presumably) do it on purpose.
- wildmXranat 16y agoCan someone write a GUI in Visual Basic to track these IPs please?
- jasonlbaptiste 16y agowill do after i finish my logowriter script LEFT 90 UP 90 move turtle move!
- iamdave 16y agoI'm assuming you got downvoted because no one saw that episode of Criminal Minds. Heh.
- shrikant 16y agoLink for down-voters: http://www.youtube.com/watch?v=hkDD03yeLnU http://www.youtube.com/watch?v=hkDD03yeLnU
- MikeCapone 16y agoDoes anyone know of a site that tracks all of these privacy problems (and potential problems) with Facebook? Following up and keeping track is the best way to keep FB accountable, and I'm sure a lot of media people would use such a site.
- there 16y agothere might be a facebook group for it...
- davidmurphy 16y agoI just did this on an email about a comment on my wall post by someone at a nonprofit. Sure enough, it came up with not just an IP, but a subdomain listing that nonprofit's domain name. Yes, it works.
- deleted 16y ago[deleted]
- yaroslavvb 16y agoSomeone commented on that page that leaking user's IP address is a common spam-prevention practice. I just checked gmail and Yahoo Mail, and they both include my IP address in the header of outgoing messages For instance, Yahoo Mail puts my IP address in a line like this Received: from [xxx.xxx.xxx.xxx]
- rm-rf 16y agoCorrect - Yahoo and others put the IP address of the client that sent the mail in the SMTP headers. Example: Received: from [x.x.x.x] by web113916.mail.gq1.yahoo.com via HTTP; Fri, 07 May 2010 18:59:00 PDT In this test case, x.x.x.x is my current IP address, not Yahoo!'s. The HTTP indicates that I used a browser, not POP/IMAP. They've been doing that for years. It's handy as heck when you need to track an e-mail - you don't have to bother Yahoo with a subpoena - you can go right to the client's ISP. There is no reason Facebook shouldn't do the same thing. Edit: Comcast does: X-Originating-IP: [x.x.x.x] Google is weird: Received: by 10.216.27.139 with HTTP; Fri, 7 May 2010 19:34:21 -0700 (PDT) I'm not on a 10.x address. Hmmm....
- known 16y agoHeaders of http://groups.google.com/ http://groups.google.com/ posts reveal IP address
- mikexstudios 16y agoI thought Gmail doesn't include the sender's IP address in their outgoing mail: http://mail.google.com/support/bin/answer.py?hl=en&answer=26903 http://mail.google.com/support/bin/answer.py?hl=en&answe....
- alexyim 16y ago"IP addresses can be considered sensitive information. As such, Gmail may hide sender IP address information from outgoing mail headers in some circumstances." They only said they may hide it.
- danieldon 16y ago
- devinj 16y agoWhy does this matter? I get others IPs and send my IP all the time (e.g. IRC). If I was worried about my IP, I would use something like tor when doing everything. But worrying about IPs seems... silly An IP is just so uninformative, unless somebody subpoenas my ISP or something.
- rm-rf 16y ago"unless somebody subpoenas my ISP or something" And in addition to your secure wireless SSID, you have an open SSID at your house that you maintain just for that reason, right? Mine's named Free_Porn.
- petercooper 16y agoIt must suck for the one user who has had all their IP address's leaked.
- patio11 16y agoI'm just... not concerned? Anything you do online leaks your IP address. If a friend embeds a photo from Flickr into their feed, and you load it, consider your IP leaked. etc, etc, etc
- alanh 16y agoLeaked to Flickr, not to a Flickr user, unless I am missing something.
- u48998 16y agoSeems Facebook users are born in 2009 or after wards. Every email service sends your IP address with the email. The exception is Google.
- jrockway 16y agoEvery? My mail appears to originate from mail.jrock.us, my MX, regardless of whether or not its actually composed on that machine.
- sounddust 16y ago1) Someone tagged me in a photo and it leaked their IP address. 2) Someone who is not even my friend commented on someone's status, and I got a notification because I made a comment before her. It leaked her IP address to me. These situations are not comparable to e-mail, and I seriously doubt these people reasonably expected their IP address to be sent to me based on these actions.
- robryan 16y agoI'd be surprised if someone really wanted my IP they couldn't get it just by getting me to visit something off facebook.
- stcredzero 16y ago"Leaks IP address" as a dramatic headline is an indicator that the poster is not-so savvy about networks and security. Seriously, this is the level of knowledge I observed in the typical high school student 3 years ago or so.
- rdj 16y agoThey changed it. The new header is: X-Facebook: from zuckmail ([MTI3LjAuMC4x]) (127.0.0.1) So I guess, nothing else to see here. Move along.
- oomkiller 16y agoAnd so does every popular webmail provider. I remember learning about this when I was 12.
- jarin 16y agoYour computer may be broadcasting an IP address!!
- jseifer 16y agoYour computer is broadcast an IP address!
- chronomex 16y agoThis is not new at all. Here's a segment of an email header from 2006: X-Facebook: from zuckmail ([128.208.54.23]) by washington.facebook.com with HTTP (ZuckMail); Date: Sun, 10 Dec 2006 12:31:27 -0800