9 ms·
No boundaries for Facebook data: third-party trackers abuse Facebook Login
- IBM 8y agoI can't wait for PWAs to be the future of apps. /s Apple should take the new Firefox Facebook extension and apply it by default to Safari. But also do Google and every other major ad-tech company. Not sure if this can be done without breaking the web though. Also not sure how different Firefox's extension is from Safari's Intelligent Tracking Prevention. It's possible they already do this.
- 908087 8y ago> Not sure if this can be done without breaking the web though. If that's the case, the web is already broken.
- Spearchucker 8y agoThey have a place but PWAs are no panacea. There are still things I want physical control of, like anything I need client-side encryption for. Fighting one extreme with another has been human nature, but isn't prudent.
- underwater 8y agoPWAs will do nothing to address this problem.
- IBM 8y agoI was being sarcastic but I realize now that I was probably getting upvotes from both camps.
- stareatgoats 8y agoSarcasm never works with a substantial number of people. And on the internet it escapes even more people, even if using emojis ;-P
- nozzlegear 8y ago> I can't wait for PWAs to be the future of apps. /s Genuine question, I don't do much mobile development: aren't native apps able to collect just as much information as a web app/site? Except with a mobile app you can't just open a Dev console and see what requests are being made? Again not trying to troll, I just don't know if I'm missing something here.
- cpeterso 8y agoThe difference, as I understand it, is that third-party code would not be able to snoop on user data in Facebook's native app. In this paper, the third-party JS is able to get itself loaded on the same page as the Facebook user data.
- chatmasta 8y agoTrue, but a native app can read (and inject scripts into) the DOM of any website in a WebView component within the app. The app can also read all cookies that are created from within the WebView (not cookies from Safari). Think how many apps use native "in app" webviews, e.g. reddit, facebook, etc. Now think about login pages, oauth flows, etc... There are lots of opportunities to slurp data from a native app.
- K0nserv 8y agoNo but if an app uses a Facebook login flow with the native Facebook SDK any third party analytics that the app developer has integrated should be able to do the same thing, at least in the case of Objective-C where powerful runtime meta programming exists. I'm not sure about Android, but maybe Java reflections could achieve it too?
- IBM 8y agoA native app could leak/abuse information like a web app, but in general the surface area is way smaller for that to happen on iOS (which is what I'm most familiar with). Everything is sandboxed and Apple strictly controls how apps behave in iOS with the types of APIs that are available and the design of those APIs (there's a reason why Google is desperate to have you sign-in when you use their apps on iOS). And when something is being abused Apple can do something about it [1]. You could put some third party "analytics" framework in your app that happens to be a bad actor (or compromised) that sucks up data in some way, but at least Apple can remove misbehaving apps because they control the App Store. So there might be technical reasons why native apps are more privacy preserving than web apps, but I think that pales in comparison to having an actor that actually follows the principles of Privacy By Design running the platform [2]. If the platform owner doesn't actually want to vet what goes in their stores beyond "machine learning" [3], had a useless permission model until recently, or does dark pattern bullshit [4], I doubt there's much of a difference between native vs web apps. At the end of the day the only thing that matters is incentives, and that informs how these actors will behave. [1] https://www.theverge.com/2013/3/21/4133288/apple-to-finally-stop-accepting-apps-that-use-outdated-udid-device-identifier-may-1st https://www.theverge.com/2013/3/21/4133288/apple-to-finally-... [2] https://en.wikipedia.org/wiki/Privacy_by_design https://en.wikipedia.org/wiki/Privacy_by_design [3] https://gizmodo.com/google-boots-fake-ad-blockers-from-chrome-web-store-1825362470 https://gizmodo.com/google-boots-fake-ad-blockers-from-chrom... [4] https://qz.com/1131515/google-collects-android-users-locations-even-when-location-services-are-disabled/ https://qz.com/1131515/google-collects-android-users-locatio...
- pornel 8y agoNative apps have the same problem. There are "SDKs" for analytics, social sharing, and "monetization" that are native equivalents of putting <script> in your app.
- the_snooze 8y agoAre there any usable solutions for end-users besides wholesale blocking of ad/analytics/tracker services? With all this, it seems pretty reasonable to assume all third-party elements on the web are hostile.
- kevin_thibedeau 8y agoNoScript + self destructing cookies.
- the8472 8y agoAll solutions break things to some extent by design. So "usable" would be quite subjective.
- ve55 8y agoThose sound like the perfect usable solutions. Do not run code on your machine (Javascript) unless you want it to be ran. The only good way to do that if you use a modern browser is using extensions to help you do it. It's definitely true that most third-party Javascript is not good for you, and just tracks you in malicious ways, slowing down your browser and putting your data at risk.
- watsocd 8y agoNever use the "Login with Facebook" or any other 3rd party login method. Create a separate account on the site if you need to log in.
- underwater 8y agoIf a script running on the page wants to scrape your data then creating a new account isn’t going to protect you. In fact it’s probably worse, because the malicious script can sniff your login details.
- albemuth 8y agoThere's a few sites I continue to log in with facebook, I just make sure to use an incognito window and close it when I'm done.
- cortesi 8y agoI have a project that's relevant here - netograph.io captures low-level data on website behaviour, then indexes the data in various ways for querying. Right now, it ingests a sizeable fraction of links on social media live. Here's my data for the api.behavioraldata.com domain, which is the first tracker they mention: https://netograph.io/datasets/social/domain/api.behavioralengine.com https://netograph.io/datasets/social/domain/api.behavioralen... It's interesting that Netograph has seen this exclusively on .pl domains, and that it hasn't cropped up again in the last month. You can do similar digging through the dataset for all the other trackers they list.
- dstjean 8y agoQuite interesting! It would be great if we could filter the lists (eg. I just want to see html and js)
- underwater 8y agoThe underlying issue is executing arbitrary third-party JavaScript on your website. It’s unfortunate that browsers and standards organisations haven’t done more to promote safer methods of third party integration. The state of the art is still injecting script tags into the document. Given that the web is powered by embeds, ads, and analytics, there should be better sandboxing tools.
- politician 8y ago> The underlying issue is executing arbitrary third-party JavaScript on your website's visitors' browsers. Fixed that for you, but I agree with the sentiment: it's a real problem that browser vendors are disincentivized to address.
- jopsen 8y agoHow is Mozilla discentivized from fixing that? Sure, you can't break everything tomorrow...
- lllr_finger 8y agoAMP achieved this, for better or worse - the only script allowed on the page is AMP common library and approved plugins. I wonder if the Google CDN was removed from the equation if it would have been more embraced.
- JoshMnem 8y agoAMP causes many other problems, so it isn't really a solution. uMatrix is one way to block third-party scripts, but it requires some knowledge to use.
- underwater 8y agoIt hasn’t solved it at all. Google have whitelisted a set of first and third party scripts. They routinely add more through a non scalable process that seems to rely on a preexisting relationship with the company. The analytics tag allows for arbitrary logging endpoints to be used, but that solves one very specific use case. I believe that they’re going to allow worker scripts in the future, but again, that I don’t believe that will solve every case, and will be AMP specific.
- samkone 8y agoDuh ... hasn't this been going on for years now. Tealium cited in the article uses this as one of their pain source of data collection
- lllr_finger 8y agoI consider Tealium doubly in the wrong here since the appeal to some orgs is that their tag manager allows BizDev/AdOps types to include scripts on sites without answering to product owners and developers.
- tylerhou 8y agoThe title might make it sound like JavaScript trackers have collected data which allow them to login to your Facebook account; maybe "'Login with Facebook' data hijacked by JavaScript trackers"?
- MentallyRetired 8y agoAgreed. That's what I thought it was, as well.
- btown 8y agoThe linked article https://freedom-to-tinker.com/2018/04/18/no-boundaries-for-facebook-data-third-party-trackers-abuse-facebook-login/ https://freedom-to-tinker.com/2018/04/18/no-boundaries-for-f... provides much more detail and links to source code, such as https://gist.github.com/englehardt/db3ecea255ccd6aa2b0cb73ca76257d6#file-be-init-js-L1229 https://gist.github.com/englehardt/db3ecea255ccd6aa2b0cb73ca... It's important to recognize that this is not an exploit or high-tech exfiltration: it's extremely well-documented in https://developers.facebook.com/docs/reference/javascript/FB.getLoginStatus https://developers.facebook.com/docs/reference/javascript/FB... and https://developers.facebook.com/docs/javascript/reference/FB.api https://developers.facebook.com/docs/javascript/reference/FB... - the Facebook library even assumes that potentially multiple scripts may be checking repeatedly, and caches accordingly. Facebook is incentivized to make it as easy as possible to integrate their login across the internet, and that entails removing any requirements such as server-side processing that would discourage every tag from including this code. Seeing this and being surprised is like watching a teen movie where the gossiper invites the entire school to listen in on the phone line while the protagonist is (unwisely) sharing a secret with them, and thinking as you watch, "that's totally out of character for the gossiper - even though they want to collect people's information themselves, there's no way they would invite other people to listen in as they're in the process of receiving that information."
- Semirhage 8y agoSeeing this and being surprised is like watching a teen movie where the gossiper invites the entire school to listen in on the phone line while the protagonist is (unwisely) sharing a secret with them, and thinking as you watch, "that's totally out of character for the gossiper - even though they want to collect people's information themselves, there's no way they would invite other people to listen in as they're in the process of receiving that information." Doesn’t that depend on who’s surprised? My parents would be shocked by this, people working in the software industry should be less shocked. I bet that a poll of 100 randomly selected people asking, “What does documentation mean in the context of software?” would discover that few knew the answer. Never mind actually reading the docs, or understanding their implications. Facebook goes to some trouble to ensure that only a small minority of people grasp the implications of how they’re monetizing their users.
- AznHisoka 8y agoPeople aren't even aware that there are browser extensions that track every single website, keystroke, and click already. The companies that do this then sell your data for thousands a month. I'm talking about big players like SimilarWeb and JumpShot. Clickstream companies.
- nathancahill 8y agoIsn't this the revenue model of eBates too?
- arciini 8y agoAs far as I know, eBates doesn't directly sell the websites you visit. Instead, it makes money from the fees paid by "affiliates". For example, eBates is an affiliate of Macy's. That means when you buy something on Macy's with eBates installed, Macy's assumes that eBates is helping to get the user onto eBates. Macy's pays eBates, and eBates pays a part of it to yourself. As far as I know, it only sends URLs of your visits to its affiliates, but not for other sites
- ensignro2340 8y agoThis so much! As I've been watching people freak out over FB, I've been wondering - if people didn't even bother to read the pop-up, bulleted lists of information they were sharing with the apps they were connecting to FB, then how are they gonna feel about the similar, bulleted lists of information they're sharing with browser extensions? I mean, I assume they don't read those either. [for the record, I know there are other issues w/ FB, but A LOT of the fallout seems to be related to the apps users were connecting to their profiles.]
- tomaskafka 8y agoAnd let's talk about antivirus companies that sell clickstream data while claiming 'tracking protection'. One of many: https://www.businesswire.com/news/home/20150527005372/en/Marketing-Analytics-Firm-Jumpshot-Receives-22M-Series https://www.businesswire.com/news/home/20150527005372/en/Mar...
- EGreg 8y agoHere is the only real solution: Have a browser which intercepts requests and encrypts all of them with your public keys, which can only be used to decrypt stuff on the client side. Wesites would have to start indicating that they understand this new contract and that their servers won’t understand ANYTHING. It could be a new protocol like https but called something else such as shttp:// http:// or encrypted:// All apps would be client side and in Javascript. Yes, servers will be relegated to dumb boxes like in SAFE network. The business model can no longer be about capturing your data unless you share the data with another participant in what is essentially your web based VPN. Any encrypted:// site can only load other encrypted:// resources so it can’t send any info to the server via postMessage etc. There would be no cookies. Sessions would be kept on the client side, as they should be. Using sessionStorage. Business logic done on servers now would be pushed to the edges, or could be further secured by validators that you allow into your VPNs and group activities. People would share keys to group activities. I am talking about somethig that breaks the current Web. No more cookies. No more AJAX the way you know it. Files are loaded from static bundles loaded ahead of time, before the website can learn custom information about your user agent.
- ta457482468 8y agoWhen the net/web was first rolling out (or my first exposure to it), I recall thinking, "This is it, universal communication, no more politics/propaganda/dark-ages-of-information-is-over etc". Then we got Google, Facebook and the cadre of TLA's and criminal orgs turning it into a panopticon and a tool to manipulate people. I think no matter what technology or tool we create, it'll be abused because that's the society we've created - one that encourages and rewards this behaviour when performed by a small group of very greedy, very misanthropic people.
- JumpCrisscross 8y agoUnder GDPR, would the sites that used this insecure Log-in Button from Facebook be liable for losing their data? (I assume they could then sue Facebook to re-imburse them for their fines, et cetera.)
- lerie82 8y agoso people are all like, "some third party website has my information and its all facebooks fault". get fucking real people.
- pizzaknife 8y agoReading a sentence or 2 about the abstract concept of exposing yourself to arguably unknown agents is hilariously so specific in terms of the breadth of information you're agreeing to divulge... its not appreciated? Maybe my tinfoil hat truly fits perfectly but if you read the grant dialogue, its extremely clear insofar as "sign in with FB to take this super rad personality quiz! and all we need is everything" really meant it? Im jaded i guess
- textmode 8y agoAccording to a recent article[1], once an advertiser/attacker has collected a large quantity of email addresses, she can "import [them] as contacts" on Facebook, thereby revealing which Facebook profiles they are associated with, if any. The article was written by a gentleman who wrote some early code for Facebook to do this which was later the subject of a Microsoft patent. Would it be fair to say that once a user submits an email address to a website, that website can locate the users Facebook profile, if one exists. No "Facebook Login" required. 1. https://www.washingtonpost.com/opinions/your-facebook-data-is-still-vulnerable-i-know-because-i-made-it-that-way/2018/04/13/1cf5c794-3e7d-11e8-a7d1-e4efec6389f0_story.html https://www.washingtonpost.com/opinions/your-facebook-data-i... Also, the curious reader may find these interesting, regarding the ease with which an attacker/website could learn a Facebook user's private friends list: https://www.telegraph.co.uk/technology/2018/04/17/facebook-quietly-stopped-apps-harvesting-users-private-data/amp/ https://www.telegraph.co.uk/technology/2018/04/17/facebook-q... https://gizmodo.com/how-facebook-figures-out-everyone-youve-ever-met-1819822691 https://gizmodo.com/how-facebook-figures-out-everyone-youve-... https://nakedsecurity.sophos.com/2013/06/23/facebook-issues-data-breach-notification-may-have-leaked-your-email-and-phone-number/ https://nakedsecurity.sophos.com/2013/06/23/facebook-issues-... https://www.facebook.com/notes/facebook-security/important-message-from-facebooks-white-hat-program/10151437074840766 https://www.facebook.com/notes/facebook-security/important-m... Finally, I have read that a major dating website has now removed Facebook Login.
- drpancake 8y agoIs this not the same as integrating 'Login with Facebook' and sharing my user's profile data with a third party service using server-side API requests? A practice that I'm sure is rife. The third party JS scripts simply cut out the middleman, but as a side effect the sharing is detectable.
- known 8y agoFB should comply with https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard#Requirements https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Sec...
- spullara 8y agoWhat is hilarious about all this is that Facebook sharing any of this data with anyone is against their interests.
- geocar 8y agontvk1 is nativka http://nativka.ru http://nativka.ru , now http://natimatica.com/ http://natimatica.com/
- EGreg 8y agoOur Qbix Platform has a solution to this using the existing modern web: https://encrypted.google.com/patents/US20120110469 https://encrypted.google.com/patents/US20120110469 We did not continue the patent application process to the end, so you’re free to use it.
- ivanhoe 8y agoIf I remember correctly you can't request access to any non-public user info without submitting your app first for manual approval by Facebook's staff. So, if there are FB apps out there tracking extra user info, Facebook must have reviewed and approved them, so they are obviously OK with such usage. So it's not an exploit of the platform, it's FB's core business...
- 1sttimeposter 8y agoWhy do we not assume that the site owner has the responsibility to protect how data is intercepted on their site? If said site owner allows their web page user to type their email into a form, a malicious script on the page can still intercept that data. FB assures the transportation of the data to the web page and once the transmission is triggered, up to its delivery, then the onus is on a site owner to govern the data. Furthermore, as an end user you have to be diligent in what you do online. If you come across a site that asks you to type information or log in with FB, you have to determine whether you trust the site enough and that you feel comfortable taking the risk of exchanging your information for the service at hand. Let’s not lose site of reality and remove emotional bias from this conversation.
- daveheq 8y agoI don't use Facebook to login with anything, so I guess I have nothing to worry about.
- hackbinary 8y agoI have never trusted Facebook login. It just always seemed 'wrong' to me. It always gave me a creepy feeling.
- Ajedi32 8y agoHow much of this is intentional on the part of the first-party site? The article says: > The following could indicate the first party’s awareness of the Facebook data access: > 1) third-party initiates the Facebook login process instead of passively waiting for the login to happen; 2) third-party includes the unique App ID of the website it is embedded on. The seven scripts listed above neither initiate the login process, nor contain the app ID of the websites. > Still, it is very hard to be certain about the exact relationship between the first parties and third parties. But I can certainly imagine a situation where a site owner would inject a third-party analytics script into their site and have no problem with it including information from Facebook logins as part of the analytics data it collects. After all, as a site owner why wouldn't I want my analytics dashboard (provided by a third-party) to include information like "percentage of visitors between the age of 18-25"? That seems like a useful thing to know, and the users who granted my site access to that info did so explicitly via a Facebook permissions prompt, so what's the issue? The issue, of course, being that my site's user's data is now being handled by a third party. But I obviously had no problem with that when I decided to use a third-party analytics company in the first place; why would that change now?