6 ms·
Facebook caught sharing secret data with advertisers
- CoryOndrejka 16y agoArticle ARS references here: http://online.wsj.com/article/SB10001424052748704513104575256701215465596.html http://online.wsj.com/article/SB1000142405274870451310457525... Additional HN thread here: http://news.ycombinator.com/item?id=1366199 http://news.ycombinator.com/item?id=1366199
- waterlesscloud 16y ago"Not surprisingly, Facebook appears to have gone farther than the other sites when it comes to sharing data." This isn't really the expectation you want your users to have. Interesting to note that Google comes up in this though. This is leading to regulation. Hard and swift.
- eob 16y agoI think the answer to this lies in regulation, but I think we also need to start treating the thriving market for our personal data differently. Privacy and regulation is super important. But I think we, as "products" also need to become active, engaged participants in the economic market for our personal information. We should have profit sharing agreements with Facebook to resell our data, should we consent to data sharing. Only then, I think, will we really have a stake that is worth more than writing angry articles and blog posts. I wrote an expanded version of this comment as a blog post here for anyone who wants to read it and comment, here or there. http://edwardbenson.com/facebooks-product-is-you http://edwardbenson.com/facebooks-product-is-you
- whatwhatwhat 16y agoThat sounds like people being paid to exist
- _delirium 16y agoI don't think that's necessarily wrong, if some money is being made off a common resource. Every Alaskan citizen gets annual oil-fund checks, for example.
- eob 16y agoThis is exactly the sentiment I think we need to get rid of. I have it too. Why? Because it is depressing to think of ourselves as a product; we'd rather just dismiss that idea as "being of a culture we do not choose to belong to". But the problem is that's like an ostrich sticking its head in the ground. People are making money off your existence, off of every click you make online, off of your gender and your religion and what you read last weekend. Until we are able to accept that reality as active, willing participants, we won't be able to demand better legislation to give us agency is the issue. The ostrich never had any agency in the stampede rumbling by him.
- rudin 16y agoFollowing the general rule in economics that special interest groups are more powerful than the masses in passing legislation I think any regulation would make this worse i.e. "enforced real-id online to make us safer".
- deleted 16y ago[deleted]
- pbhjpbhj 16y ago>>"Not surprisingly, Facebook appears to have gone farther than the other sites when it comes to sharing data." >This isn't really the expectation you want your users to have. It kind of is - Facebook's raison d'etre is sharing information easily.
- vaspers 16y agoYes Facebook is evil. When I saw that Zuckerberg called users "dumb f*s" for trusting him with their data, and I mused on how criminals could exploit that data via phishing, pw guessing, and social engineering schemes, I joined the Perma-Delete revolution.
- jacquesm 16y agoReally could have just as easy been a silly joke that is now taken out of context. I wonder if any of us will ever make it to the level of Zuckerberg, but if you do, are you sure you never made an IM message or an email that might be used against you like this? I don't even recall most of them.
- jacquesm 16y agoIt never ends does it? FB has a real problem, I hear my totally clueless (when it comes to computer related things) family members discuss their facebook privacy and whether or not they should quit. I never expected to see that happen. And all that in the space of about 2 months.
- patio11 16y agoIt hit the news cycle, and now technical details which have existed unchanged for years and which no user actually cares about (HTTP referrers) provide new grist for the mill. And, of course, it is distorted beyond all recognition: "Anyone who runs a web page on the Internet -- including advertisers -- is passively informed of the page you were looking at when you clicked a link to their site. This is built into the Internet and is the way it has always worked" becomes, quote, "Facebook, along with MySpace, Digg, and a handful of other social-networking sites, have been sharing users' personal data with advertisers without users' knowledge or consent." I don't fell all that sorry for Facebook, but man, am I sure glad I have never had my business interests aligned against a media narrative.
- jacquesm 16y agoIt's like watching a snowball roll down a hill at this stage. Imagine what you could do if you could harness the power of that narrative in the other direction. It's interesting to see how people react to realizing what has been going on under the hood pretty much for as long as I remember. I think that when the doubleclick trouble hit people just couldn't make the mental connection and for the media it was much too dry. Facebook is very close to home and it ties in to everybody's lives at such a close-to-home level that they seem to feel threatened way out of proportion. Not sure if digg belongs in that list.
- ashot 16y ago"Imagine what you could do if you could harness the power of that narrative in the other direction." diaspora
- paul 16y agoNot a lot of details. Is this a story about the HTTP referrer header? (aka "Referer") But don't let facts get in the way of a good story...
- drusenko 16y agoYes, it looks like it. And it's unclear how Facebook somehow shares more than other sites...
- petewarden 16y agoHere's the paper giving details: http://www2.research.att.com/~bala/papers/wosn09.pdf http://www2.research.att.com/~bala/papers/wosn09.pdf There's three ways info leaks: 1 - Referer header, eg facebook.com/profile.php?id=1 2 - Request, eg analytics.google.com/script.js?page=facebook.com/profile.php?id=1 3 - Cookies, eg z.digg.com points to an omniture server, and so passes all digg cookies to them! 1 and 2 are easily exploitable by advertisers who wanted to, but 1 especially seems like a very standard way of building urls on most services. Definitely will get them hammered for good reason, but there's not necessarily any bad intent. 3 seems a lot worse. Are there legit reasons I'm missing for hosting ad servers on the same domain, and so puncturing the browser security model?
- matasar 16y agore: 1 - For user shared links, Facebook redirects to anonymize the referring profile. I suspect they forgot to do the same for ads, and it was an honest if frustrating mistake.
- X-Istence 16y agoThey didn't use to do this, the only reason they redirect now is so that if a link is deemed a virus of some sort they can easily stop it from spreading, and you can enable a setting so that before visiting every link you get an interstitial that tells you that you are leaving Facebook.
- kingsley_20 16y agoI've sometimes subdomained a few, select third party services on the same domain. For example, if a third party hosts your landing pages and you wish to own the urls to those, subdomaining is the best way to handle that. That said, you should practice decent subdomain level security with cookies. You can and SHOULD restrict cookies to subdomain levels. The only exception is for SSO related cookies (that are stored at the domain root) that still need at least a second, shared secret verification at the very minimum.
- derefr 16y ago> Are there legit reasons I'm missing for hosting ad servers on the same domain, and so puncturing the browser security model? Avoiding generic (not targeted to your site specifically) AdBlock URL filtering.
- seldo 16y ago"Caught" is a little strong. It's not like they were selling the information to advertisiers -- in fact, several of the advertisers who were receiving the information have said they were unaware it was even being sent, far less doing anything with it. They didn't write any code to "share" this data; they just failed to put safeguards in place to prevent it leaking via HTTP referrers. I'm willing to put this down to incompetence rather than malice, though of course incompetence is still not great.
- ahoyhere 16y agoOP's #3 above with the cookie pointing seems to tell the lie to, well, that lie. You can't put it past big co's (or even small co's, and individuals) to come up with the strategy: 1. We'll do this naughty thing 2. We'll make it look accidental 3. Then if anyone finds out, we'll pretend to be bumpkins It's a classic foil. Basically, it's a reverse pool shark hustle.
- msg 16y ago"Reverse pool shark hustle" I would call this pulling a W.
- seldo 16y agoThe cookie thing is definitely a different matter. I was referring to the portion that is making all the headlines, which is Facebook "giving advertisers names and ages of people who clicked ads" (see http://www.businessinsider.com/facebook-myspace-busted-for-telling-advertisers-which-specific-users-clicked-on-ads-2010-5 http://www.businessinsider.com/facebook-myspace-busted-for-t... ). They did no such thing.
- tseabrooks 16y agoHonestly, I think the vast majority of facebook's privacy guffaws have been due to incompetence and not malice. My concern, however, is that we get in the habit of excusing these failures because of this incompetence. Software can be made (more) secure and can be tested (better). The point then is when does it make financial sense for facebook to put the money and man power into tackling these issues on the front end... If users / consumers don't take note of the problems and move to another (currently nonexistent) platform facebook will never have a motivating reason to change. Perhaps, users have done this to themselves by demanding low cost (free) software with fast release schedules for new features.
- indigoviolet 16y agoThe spin people are putting on this is just unbelievably sensation-mongering. ReadWriteWeb of all places is calling them on it - http://www.readwriteweb.com/archives/unbelievable_wsj_calls_referring_urls_a_privacy_vi.php http://www.readwriteweb.com/archives/unbelievable_wsj_calls_.... It's so disappointing to see Hacker News be a part of this mob mentality.
- ajg1977 16y agoSorry, but RWW's subtext that this is nothing more than regular referral URLs is disingenuous. Providing advertisers with personally identifiable information, particularly information that can be used to both gather additional data and target you later, is a pretty significant privacy failing.
- izendejas 16y agoThis is the part that troubles me: " It wasn't until WSJ contacted them that changes were made." How do you interpret that? 1) Too busy to care enough to prioritize this? 2) Indeed there was intent? 3) To dumb to realize the consequences? Maybe I'm too biased now, but I can't think of a good way to put a positive spin on that.
- spoon16 16y agoThere is an interesting related thread on Quora. http://www.quora.com/How-did-Elliot-Schrage-not-know-that-Facebook-was-identifying-Facebook-users-to-advertisers-when-he-made-a-statement-in-The-New-York-Times http://www.quora.com/How-did-Elliot-Schrage-not-know-that-Fa... Here is what one of the Facebook guys says about the situation: The Wall Street Journal article is not exactly factually false, but the implication you're drawing from it is incorrect -- the actual issue is that in some cases (e.g., after performing some editing operations) the viewing user's ID is contained in the page URL. If the user happens to click on an ad on such a page, the browser will send a Referer header line that has the URL with the ID in it. On the other hand, if the user clicks away to a different page then clicks on an ad there, the ID will no longer be present. This by no stretch of the imagination represents Facebook "going out of its way" to pass user information to advertisers. In any event, the accusation makes little sense given the context. If Facebook wanted to leak user IDs to advertisers, surely it would be far more profitable to do it reliably, on every ad click, rather than doing it via a mechanism that (even according to the WSJ article) only discloses user IDs a small percentage of the time when the user happens to be viewing certain pages in certain ways.
- dpritchett 16y agoI'm curious but I can't see the Quora thread.
- DanielBMarkham 16y agoDisclaimer: I have always thought Facebook was the devil -- it uses a growth model that co-opts human behavior in a manner not in the best interests of the participants Having said that, the media coverage is starting to get the feeling of piling on. Reporters have decided the media narrative around FB is something like "Big company goes evil. Users revolt" I think we may have reached the point where the leaders of FB really want to do this correctly, but the momentum of the company and the overriding media narrative may continue to drive lots of stories like this. So. I'm going to be careful to double-check the "Facebook is killing your grandma!" types of stories. The media is famous for getting tech wrong. My guess is that most all of them will have a grain of truth. And most all of them will need some technical clarification before we can make heads or tails of it.
- whyenot 16y agoWe don’t share your information with advertisers. Our targeting is anonymous. We don’t identify or share names. Period. -- Elliot Schrage, vice president for public policy at Facebook. May 11, 2010. http://bits.blogs.nytimes.com/2010/05/11/facebook-executive-answers-reader-questions/ http://bits.blogs.nytimes.com/2010/05/11/facebook-executive-... ouch.