16 ms·
Facebook can track your browsing even after you've logged out, judge says
- femwarrior 9y agoSurely everybody on HN knew that already?
- libeclipse 9y agoI have a few questions. 1) “Facebook’s intrusion could have easily been blocked, but plaintiffs chose not to do so,” This seems like a dangerous precedent. So if we can block surveillance attempts and we don't try, then it's our fault? > “The fact that a user’s web browser automatically sends the same information to both parties does not establish that one party intercepted the user’s communication with the other,” This makes no sense. Nothing happens "automatically", someone wrote the code for that to happen, in this case, Facebook. But, at the end of the day it's just an embedded thing in a bunch of websites. I don't see anyone suing Google about AdSense. I mean I despise Facebook, but unless they're doing something more nefarious than getting a GET request on page load, then I'm not sure that I care enough. Get a blocker.
- saltedmd5 9y agoYou're not very good at questions.
- hellbanner 9y agoPlease phrase comments constructively. In this case you could provide a better example of a question they were trying to ask OR explain why their question didn't make sense.
- d8421l01vv4r 9y ago> This makes no sense. Nothing happens "automatically", someone wrote the code for that to happen, in this case, Facebook. The website you are visiting has to deploy Facebook's code though. So the website owner has to allow it (assuming the know the implications of what they are doing).
- type0 9y ago> So the website owner has to allow it (assuming the know the implications of what they are doing). You could assume it but it's not necessary the same people who designed the web page that add those facebok "features". From my impression, often than not you have some "social media marketing expert" that does this. And they do not give a rats ass about any nefarious tracking and will continue to be blissfully ignorant about the users privacy unless it becomes a corporate policy to care about those things.
- admax88q 9y agoThe website owner still has the ultimate responsibility for what is served on their site. If they employ some "social media marketing expert" who deploys tracking code, then that's still on them.
- pyre 9y agoOn the other hand, Facebook could design their social media widgets in a way that doesn't require the user to send a GET request to Facebook unless the user actively clicks to share.
- JetSpiegel 9y agoAlso know as a link. That's not Web 3.0 enough.
- pyre 9y agoMost of these sites don't want you to navigate away from their page. They would rather you can share without leaving their site (i.e. a dialog pops up that allows you to create your Facebook "share" post, and submit it).
- braythwayt 9y agoThe most interesting thing to me about "Facebook's intrusion could have easily been blocked, but plaintiffs chose not to do so," is that it implies that users have a right to block tracking code. If that isn't already enshrined in case law, hopefully it signals that we will not get laws passed requiring users to allow tracking, and the courts will hopefully invalidate terms and conditions requiring tracking. Having lived through the rise of DMCA, I live in fear of an emboldened industry getting laws passed that make the use and distribution of blocking software illegal.
- jacquesm 9y ago> Having lived through the rise of DMCA, I live in fear of an emboldened industry getting laws passed that make the use and distribution of blocking software illegal. The day that happens I'm joining the dark side.
- drdaeman 9y ago> Nothing happens "automatically" Actually, the problem is [add: after the website is created, and tracking code is put there by someone] that it all happens automatically. See, there is another perspective into this. Not exactly correct (I admit, there is some stretching and it's not all solid), but just the general idea... The semi-forgotten term for the browser is user agent. Point is, it really should act on behalf of the user. It's an automation that should be programmed to do what the user wants it to do (browsing the web, displaying the pages, etc), sparing user of mundane choices and gory technical details. If the agent is configured to willingly accept and execute arbitrary third-party instructions, and provide detailed information - and it can be configured differently - isn't the problem with the agent configuration? If you didn't want that GET request, why agent did it? And it's not that the agent was tricked (hacked) into doing so - all the APIs (cookies, XHR, etc) are well-documented. Sure, there is some shady stuff sometimes going on - like browser fingerprinting, but it's not the core issue. Maybe we should actually start blaming browser vendors for shipping badly pre-configured software with the defaults that consciously and willingly trade privacy for "not breaking" the web? Remove the automation and just imagine users themselves would somehow connect to the web, and the site would tell "hey, now go talk to Facebook server and do whatever they say" - and they do. (And this is what actually happens!) Surely, the tracking would be a non-issue.
- _jal 9y ago> Maybe we should actually start blaming browser vendors for shipping badly pre-configured software with the defaults that consciously and willingly trade privacy for "not breaking" the web? This. The writing was on the wall when the conversation became about "balancing" the interests of users and huge content factories. And now web-DRM is a standard. Fuck that; my computer, my rules. I had a funny conversation recently with someone who was arguing that I was breaking etiquette, or perhaps an implied contract (it wasn't clear) by messing with cookies. He realized the absurdity about the time I asked if I was ethically obligated to back up and restore the cookies in case of drive failure, but people have some really odd notions about their right to control state on my machine. In some ways I prefer the black-hat types; at least they're aware that they're working against my interests and don't become indignant when I point it out.
- 9y ago
- akerro 9y ago>This seems like a dangerous precedent. So if we can block surveillance attempts and we don't try, then it's our fault? If I can save your life, but choose not to, it's your fault.
- sametmax 9y agoYour confusing "letting somebody being harmed because he/she doesn't protect his/herself" and "taking advantage of the fact that somebody is being harmed because he/she doesn't protect his/herself".
- altern8tif 9y agoHow do the courts rationalise privacy concerns of the less tech-savvy? Do we assume everyone reasonably knows how to block surveillance attempts by Facebook/Google? Shouldn't privacy be a default right, and that users can opt-in (to be tracked) with their expressed consent instead?
- wodenokoto 9y agoThe opposite thinking is what lead to the EU cookie warnings. Users can easily block cookies themselves, but that is no excuse for the cookie intrusion, so every single website must display a pop-up warning that it uses cookies. Imagine that: every single website you visit shows a pop-over or an extra top bar that you have to close. Every website. That's the online life of the European netizen.
- closeparen 9y agoYes, actually! You have no expectation of privacy with a postcard or a conversation in a public place, therefore they can be legally intercepted. This precedent predates the internet by decades. Whether you take reasonable steps to make something private does influence the degree of legal protection it gets.
- federicoponzi 9y agoNot a surprise.
- r721 9y ago>Australian internet security blogger Nik Cubrilovic first discovered that Facebook was apparently tracking users’ web browsing after they logged off in 2011 After reading that (in 2011) I decided to block all third-party cookies.
- dvfjsdhgfv 9y agoThe other side is not stupid, there are far better ways to track users than cookies, and blocking them takes a lot of effort.
- roblabla 9y agoWhat better ways than cookies is there to track users ? AFAIK, it's the most unique fingerprint you can get of a user. Everything else is probably going to be a lot less precise.
- test1235 9y agoI think browser fingerprints are quite a reliable way of tracking. https://amiunique.org/fp https://amiunique.org/fp
- tinus_hn 9y agoSure, 'quite reliable' beats 'unique' every time!
- braythwayt 9y agoUnique becomes unreliable the moment users delete their cookies.
- tinus_hn 9y agoWhich they of course do much more often than change one of the finicky parameters that constitute these unique fingerprints (which in reality tend to not be unique to begin with)
- slitaz 9y agoProper English should have been: "Facebook may track your browsing even after...". The judge can rule about lawfulness, otherwise it looks like they are a investigative reporter that just found out about the technical capability to track users in such a way.
- fareesh 9y agoWas confused about the headline as well, made it seem like this was uncovered by the judge during the course of some trial.
- lucb1e 9y agoOh, thanks, now I finally understand the title. Should be "may" or "It's legal to..." indeed.
- alangpierce 9y agoInteresting. For me, it's normal and understandable to use "can" to mean "is allowed to". I certainly know and understand the word "may", and I've heard it's technically more correct, but it feels a little antiquated or overly-formal, so I tend to not use it in conversation but might use it in writing. One source that "can" is ok here: https://en.oxforddictionaries.com/usage/can-or-may https://en.oxforddictionaries.com/usage/can-or-may I didn't realize that this use of "can" is something that would cause confusion. Maybe there's a regional difference? I'm from the western United States.
- dang 9y agoI tried s/can/may/ above but it sounds archaic to my ear. It may be proper English but if it's fallen out of common usage, putting it up would be distracting too.
- curiousgal 9y agoMeh https://www.eff.org/privacybadger https://www.eff.org/privacybadger
- titzer 9y agoThat's not all. In NY state, they ruled that can artist can take pictures of you in your home through your windows: https://fstoppers.com/photojournalistic/supreme-court-rules-photographing-neighbors-through-windows-legal-67925 https://fstoppers.com/photojournalistic/supreme-court-rules-...
- donatj 9y agoAnd why not? It would forbid a lot of outdoor photography if I couldn't accidentally catch a photo of someone in their house. Google Street view would be gone.
- jgalt212 9y agonot necessarily, they would be forced anonymize faces.
- AlphaWeaver 9y agoLike Google Street View already does.
- cooper12 9y agoI don't think they were forced. Google is based in the U.S. where it is legal to photograph people in public, yet Google still blurs the faces of those on sidewalks. That and things like license plates seems to me to be them preemptively trying to appease privacy concerns so that support to censor them legally doesn't form.
- m_eiman 9y agoFirefox has a pretty neat feature I discovered recently: https://wiki.mozilla.org/Security/Contextual_Identity_Project/Containers https://wiki.mozilla.org/Security/Contextual_Identity_Projec... It lets you run multiple sessions in one window, where each tab belongs to a specific session with separated cookies and such. I've got a bunch of tabs where I'm logged in to Facebook, another set where I'm logged in to Google and the rest of them where I'm not logged in to either. Of course they can still use IP matching to track me, but at least it's something...
- brainfire 9y agoI use the Tor browser for just Facebook. Stymies IP tracking, and I expect it to do more of the right things to deal with fingerprinting too. Plus it's super slow, encouraging me to not spend too much time on Facebook...
- kerkeslager 9y agoWhy not just quit Facebook?
- zimpenfish 9y agoFor me, the reason is "Because there are people on Facebook that I want to communicate with".
- kerkeslager 9y agoThat's true for me, too. But I can communicate with those people via other means and have found no downside to doing so. I've been Facebook- free for years now.
- zdkl 9y agoPreaching to the choir, it's our friends who need convincing!
- necessity 9y agoFacebook is a company, a superfluous one even, no need is forcing you to use it and there is no need for it. Don't like the don't use it. Don't like tracking configure your browser accordingly and get a blocker. It's easy and free.
- icebraining 9y agoYou can't block if you don't know it happens (or that it even can happen), which is the case for most people. Very few people understand the concept of third-party tracking - nor should they have to.
- deleted 9y ago[deleted]
- GrumpyNl 9y agoNice, if i don't lock my door, its my fault they steal my things.
- falcolas 9y agoThat is the insurance industry's standard. Which makes bump keys a bit more dangerous, since they don't leave the usual marks indicating your lock was picked. And if you door wasn't locked, the insurance industry won't pay out for losses.
- akerro 9y ago> Nice, if i don't lock my door, its my fault they steal my things. In many, if not most European countries you can get a ticket for not protecting your vehicle. If you leave your car unlocked and someone steals it, it's your fault. Police if have to investigate it etc, but they also give you a ticket, because it not thoughtlessness, they wouldn't have to do it.
- thinkfurther 9y ago> If you leave your car unlocked and someone steals it, it's your fault. Getting a ticket for that does not mean the theft gets blamed solely on the owner so that the thief is not even considered committing a crime. It's just the owner may have violated a law, too. How about you a.) quote those laws, and even assuming you are correct in how you put it, show how b.) one instance of victim blaming would justify another. To me that's like drinking a second bottle of bleach because you already downed one. That runs so much counter my own intuition I'm kind of intrigued.
- jgalt212 9y agoSeems very similar to the original Facebook Beacon, which they were forced take down. https://en.wikipedia.org/wiki/Facebook_Beacon https://en.wikipedia.org/wiki/Facebook_Beacon
- haterswillhate 9y agoWhy are you using this CIA / NSA sponsored corporation product ? If you know the danger of this and you still use it.. why you cry about it ? People... sheeps they are.
- borne0 9y agoWhile on the topic of tracking, is there a plugin that lets you delete cookies using rules on a per domain basis? for example, cookies are useful for some sites, and others they are useful for certain periods of time, and thereafter it would be nice to get rid of them (and yet more sites shouldn't be able to leave cookies at all). I know there are some plugins that let you block all cookies, or manage them after the fact, but I want something rule based and automated
- JetSpiegel 9y agoSelf Destructing Cookies is basically this. You can whitelist domains to keep cookies.
- propogandist 9y agovanilla cookies in Chrome allows quick cookie clearing (one click) and you can customize rules to save specific cookies. Self Destructing Cookies on FF is fantastic also.
- tedd4u 9y agoI use this [1] -- it's great. I have it set to delete any cookies not on the whitelist 30 minutes after last set. That way I can log into a site that's not on the whitelist and do something and after I've stopped using for 30 mins I'm logged out and cookies deleted. However - it's not perfect. It doesn't delete local storage, local databases, or Flash™ storage. There is a nest of Chromium issues [2] needed to be resolved to make this work. It looks like the most recent related work was done Sep 2016 [3] so maybe there's some hope, even though the issues have been open for 5+ years. Of course I have the option of working on it myself but having looked at the 5-10 related issues I think it would take quite some time to develop an understanding of all the APIs. [1] https://chrome.google.com/webstore/detail/vanilla-cookie-manager/gieohaicffldbmiilohhggbidhephnjj https://chrome.google.com/webstore/detail/vanilla-cookie-man... [2] https://bugs.chromium.org/p/chromium/issues/detail?id=78093 https://bugs.chromium.org/p/chromium/issues/detail?id=78093 [3] https://bugs.chromium.org/p/chromium/issues/detail?id=589586#c38 https://bugs.chromium.org/p/chromium/issues/detail?id=589586...
- ryan-allen 9y agoI think EFF's privacy badger [0] can block this kind of tracking, depending on how sophsticated their tracking methods are. [0] https://www.eff.org/privacybadger https://www.eff.org/privacybadger
- 4684499 9y agoEff's approach often makes me feel they acquiesce that users should be the one hiding from those corporations. Why are we making shields instead of them putting guns down?
- etiam 9y agoIs it instead? Since Facebook and their ilk are surveilling us largely out of greed, surely making the work less profitable for them has some merit as a tool for counter? As is often the case, a true solution probably does need to be political, but a technical one is valuable as a band-aid until/unless that can be achieved.
- leereeves 9y agoIf the judge had ruled the other way, would that have been equivalent to ruling that all tracking is illegal?
- walterbell 9y agoIf you delete the Facebook cookie (i.e. are completely logged out including username), then click on a link in an email notification from Facebook, it will silently log you in again, restoring the cookie and web-wide tracking. This can be tested by pasting an email notification link to a new private browsing window.
- akerro 9y agoIf you use PrivacyBadger you don't have more facebook cookie on 3rd party websites, so they dont track you. https://addons.mozilla.org/en-us/firefox/addon/privacy-badger17/ https://addons.mozilla.org/en-us/firefox/addon/privacy-badge... https://chrome.google.com/webstore/detail/privacy-badger/pkehgijcmpdhfbdbbnkijodmdjhbjlgp https://chrome.google.com/webstore/detail/privacy-badger/pke...
- walterbell 9y agoHow do you login to Facebook when needed, if there is no cookie?
- akerro 9y agoEdited comment to explain it affects 3rd party websites. Facebook works as usually and all content it the same.
- walterbell 9y agoThanks for the pointer. Wish this worked on iOS, where the only option is to use a dedicated browser for accessing Facebook. Not sure how Brave deals with Facebook cookies on iOS.
- akerro 9y agoWhy can't you use firefox on iOS? All addons should work normally. https://www.mozilla.org/en-GB/firefox/ios/ https://www.mozilla.org/en-GB/firefox/ios/
- tagawa 9y agoThe article or the judge (not sure which) suggests using incognito mode. While this will keep browsing history private for a particular session, it's only effective locally. Tracking from the server is still possible either through being logged in or through browser fingerprinting, which is surprisingly accurate. Here's a good demo which uses fingerprinting to show how ineffective incognito mode is: http://www.nothingprivate.ml/ http://www.nothingprivate.ml/
- threecheese 9y agoHow does a user defend against this, without resorting to a nuclear option like Tor?
- propogandist 9y agohtml5 canvas blockers / browser fingerprinting blocker for the site linked your browser is leaking a lot of data, from the plugins you have installed to the fonts & you need to take initiative to patch the holes here's a website you may find useful: https://browserleaks.com/ https://browserleaks.com/
- theWatcher37 9y agoIt's past time for Firefox to include tor as it's private browsing mode. Maybe put it at a tier above private, "ghost" mode. This BS has gone on too long
- tagawa 9y agoThe Brave browser has an anti-fingerprinting feature in Preferences -> Shields. It's not enabled by default because of the likelihood of breaking some sites.
- nemoniac 9y agoClearly Facebook "can". The judge ruled that they "may".
- 3uh5weutwehow 9y agoMake today the day you delete you facebook account. Do it! Opt-out of this panopticon as best you can. Block as many ads as you can, in order the starve the best.
- supernumerary 9y agoadd facebook to your hosts file per: https://github.com/erwinbierens/Facebook-Hosts/blob/master/facebook-hosts.txt https://github.com/erwinbierens/Facebook-Hosts/blob/master/f...
- mungoid 9y agoWouldn't something like Pi-Hole be a good network-wide way to manage this tracking? I know plugins are convenient but they all have to intercept and modify css/etc coming in on the fly which can lead to slower page loads. Plus I'd imagine some of those plugins will allow certain domains through regardless? Or are the sneakier ways sites track users something that can get by the OOTB settings?
- leeoniya 9y agothat awkward moment when the article itself has Facebook sharing buttons
- olivermarks 9y agoDoes FB track by IP or cookie or both? I use different browsers for the more invasive tracking sites. For FB (which I use very sparingly these days to stay in touch with people I won't hear about in other circles) I currently use Safari. I log in and out and limit my use of that browser to FB and a handful of other sites. since Chrome is such a memory hog on macs my principal browsers are opera and brave, both of which work very well on my elderly macbook air. I have no idea if my somewhat paranoid tracking avoidance is effective against FB though. I see that when I go to the log in page in safari that FB knows how many 'posts' I have stacked up to consume (the little Pavlov's dog red circle with a number in it). I'm assuming I'm being tracked despite being logged out...
- f4rker 9y agoso? people act like they have all kinds of "civil rights" on the internet. like the right to not be tracked. no such thing exist. or the "right" to have the internet and web sites work how they imagine things should work if you dont like the internet dont use it.
- blackoil 9y agoHow is Facebook different from other advertising networks. All of them track you across the web, on any site that use them. Why is FB a special case?
- Pxtl 9y agoMy general fix for web tracking cookies: HTTP requests sent from my browser page when viewing Foo.com to Bar.com have no cookies. Javascript is available to create an explicit pop-up requesting permission to share your cookies with Bar.com. When I go to Foo.com, my relationship is with Foo.com. I'm okay with being tracked by Foo.com when I'm on Foo.com, but if bar.com is going to track me then I want to be asked. That said, Foo and Bar could still share information about me directly without going through my browser, but without the cookie feature it would be very hard for Foo and Bar's profiles on the person Pxtl are the same person.
- heisenbit 9y agoIt is interesting that the court was arguing that there are protection measures the plaintiff can take. Makes one wonder that the legal situation is for the folks that are circumventing the default browser protection mechanisms.
- makecheck 9y agoSometimes I think people need a little more "Black Mirror" to see how bad this is. One of the episodes has random people basically constantly looking at and filming a woman everywhere; certainly no less than what Facebook does every day, yet somehow it doesn't seem weird to anyone?
- Piccollo 9y agoI can already tell Season 4 is gonna be awesome
- rubicon33 9y agoI wish someone would build hardware that protected against this. A router for example that filtered all outbound traffic and blocked specific routes and packets destined for tracking. Yes, you could do that all on the computer itself, no need to run it on the router. I guess the benefit of having it all on a router is that it would be a plug and play solution for the privacy conscious but technically limited individual.
- bguillet 9y agoPi-hole (https://pi-hole.net/ https://pi-hole.net/) does something like this. It's not plug'n'play though.
- TheRealDunkirk 9y agoI usually stick with Safari as my browser, but Privacy Badger isn't available for it, so I use "Facebook Disconnect." Does anyone know how well it really works? (I don't have an account, and I don't want them tracking my activity for my old profile.) I'm surprised I haven't grep'ed anything about this extension in the discussion thus far, which makes me nervous.
- Lazy_Killer 9y ago>Davila said that plaintiffs could have taken steps to keep their browsing histories private, for example by using the Digital Advertising Alliance’s opt-out tool or using “incognito mode” I just used the WebChoices "opt-out". And my guess is that the judge has no idea how it works. 1. It tracks your browser, it "scans" your browser so it knows which browser not to track. A catch 22 that, im sure the judge was unaware of. 2. 1/2 of the opt-outs where unavailable, meaning that they did not receive my request. Meaning that they will continue to track me unless I keep coming back and trying to send them my information. 3. Of those company's that did not receive my request, one was facebook. Whose "opt-out" is "currently unavailable". My guess is that on appeal they will get a trial.
- Radio_Killer 9y agoAt least you can go without Facebook. You probably won't have much of a social life, but who needs that anyway. The problem is that you can't go without Internet service, and when the ISP starts doing these things, your only options to protect yourself will be to either not connect to the net or use a VPN. If you choose the latter, make sure its a non-US VPN. That's what I plan to do. The non-US VPN will not only stop the likes of AT&T and Comcast from mining surfing habits, but it will also piss off the intelligence community that is watching everyone without a warrant or probable cause.
- a_imho 9y agoI don't even know what their logout button does. It puts me on the login page with my profile pic, and it displays the number of notifications I've received while logged out. There is a 'remove account' X overlay placed on the top left corner. I usually click it and hope it does something.
- owly 9y agoQuitting facebook is not enough. I recommend blocking all via hosts file. https://github.com/jmdugan/blocklists/blob/master/corporations/facebook/all https://github.com/jmdugan/blocklists/blob/master/corporatio...
- Mikho 9y agoThat is why media struggles making money--it gives its audience for free to Facebook and Google with all that "free" share buttons and analytics. Why would an advertiser pay to a brand name media outlet money for displaying an ad if it could buy exactly this audience on Facebook or via Google much cheaper? Media did it to itself--it just gave away it's audience for free. No wonder it can't make enough money via advertising.