5 ms·
As an FB Marketing API developer, this has been available for several years . The way it works, advertisers can send their phone list to FB for ad targeting. Ho
by boraturant 8y ago
As an FB Marketing API developer, this has been available for several years . The way it works, advertisers can send their phone list to FB for ad targeting. However, phone hashes are sent, not clear ones.
Personally, as long as the user has an opt-out and opt-in options, I don’t think ad targeting is necessarily an unethical pattern, the blurring lines of ads and recommendations would be actually a pattern that users might like. Would you rather use Netflix or Spotify without recommendation engine?
- oneeyedpigeon 8y agoSpeaking as someone who hasn't used facebook in years, I think it's awkward trying to compare it with netflix/spotify. The latter are narrowly-focussed, with a clear target for recommendvertising - i.e. I am viewing a film or listening to music, the case for suggesting another is pretty good, and useful. That's very different from, for example, recommending a product to me when I'm viewing my friends' photos.
- FabHK 8y agoAlso, one pays for Netflix, and there are no ads. They try to give you, the user/customer, a better experience, so that more users/customers sign up and pay. Needless to say, Facebook's goals and incentives are very different.
- whoknowsnobody 8y agoAnd you use Netflix to watch videos and Spotify to listen to Music, no problem in being offered other, personalised, videos and music. But on Facebook people go for socialising, and not to get personalised ads.
- hjek 8y agoI disagree. Blurring the lines between ads and recommendations is super creepy[0]. Anyway, I still upvoted your comment, because it's interesting to read what someone working at FB has to say on this. [0]: https://readwrite.com/2012/12/11/why-are-dead-people-liking-stuff-on-facebook/ https://readwrite.com/2012/12/11/why-are-dead-people-liking-... EDIT: Images seem to be missing from the original link, so here is an archived version: https://web.archive.org/web/https://readwrite.com/2012/12/11/why-are-dead-people-liking-stuff-on-facebook/ https://web.archive.org/web/https://readwrite.com/2012/12/11...
- jstanley 8y ago> However, phone hashes are sent, not clear ones. The space of phone numbers is small enough that this is not a significant consideration.
- Fri21Sep 8y ago"No worries we hashed IP adresses"
- pjc50 8y agoAdvertising destroys reccomendations. Suddenly it's not based on any genuine attempt to work out what the user might like but only what benefits the margins of the advertiser. This is why Google's adverts are in a separate box at the top, un-mingled with the search results.
- pmlnr 8y ago> Would you rather use Netflix or Spotify without recommendation engine? Hell yes. Related artists per track, that would be more, than enough.
- mattlondon 8y agoThanks for the info - didn't think of this angle (i.e. advertising sending a list of numbers to target, and facebook tying that to their cookie ID they have on you). There I was wondering how this works in a browser since browsers don't know your phones number (right?). > Would you rather use Netflix or Spotify without recommendation engine? 100% yes. Personally for me the term "personalisation" is becoming a dirty word and I am becoming uneasy when I hear it mentioned in design docs and product launches etc. I dont want to see what some algorithm thinks I want to see. Instead I would prefer to see the real, unfiltered, unfettered data. I think the whole Fake News outcry started me thinking about it in a more deep way. Imagine if you went into a fancy restaurant for some special occasion and the waiter took a look at you as you walked in and brought you a "special" menu based on some decision they made silently in their own head about what they think you want. Rightly you'd want to see the full menu and not just what they think you want to see. Sure I'd welcome them pointing out some highlights on the menu, but I'd apprecaite seeing the whole thing before making up my own mind. As a result now I use DuckDuckGo exclusively and have Firefox set up with Google Container[1] to keep the Google cookies separate from everything else (I dont use facebook at all so their cookies are entirely blocked as 3rd party) as well as the usual uBlock Origin, privacy badger et al. I am even toying with the idea of moving away from my gmail that I've been using since 2004/05. 1 - https://addons.mozilla.org/en-US/firefox/addon/google-container/ https://addons.mozilla.org/en-US/firefox/addon/google-contai...
- 394549 8y ago> Personally for me the term "personalisation" is becoming a dirty word and I am becoming uneasy when I hear it mentioned in design docs and product launches etc. I dont want to see what some algorithm thinks I want to see. Instead I would prefer to see the real, unfiltered, unfettered data. I think the whole Fake News outcry started me thinking about it in a more deep way. That's also a corruption of the meaning of "personalisation." Personalisation is about me making choices to adapt a product to my preferences, it's not about the product making choices about how to interact with me. Real personalisation would be having the (sticky) option to shut the algorithm off and "see the real, unfiltered, unfettered data."
- fivre 8y ago> However, phone hashes are sent, not clear ones. Somehow, the knowledge that the efforts to tie every trace of my existence together to help marketers target ads to me are done in a cryptographically secure fashion is not entirely comforting. In general, I have been unimpressed with recommendation engines of any sort. Spotify can't suggest music I'd like worth a damn, and it's working within a relatively specific domain. Whatever fractional gains in ad relevance are currently obtained from this aren't worth the privacy invasions needed to obtain them.
- ric2b 8y ago> are done in a cryptographically secure fashion is not entirely comforting. It's not even cryptographically secure, a phone number is like a 10 digit number that isn't even completely random because of area codes, trivially brute-forceable.
- aaaaaaaaaab 8y ago>However, phone hashes are sent, not clear ones. Lol! Phone numbers have less than 40 bits of entropy, it's trivial to break those hashes.
- dredmorbius 8y agoSalt them.
- bob_roboto 8y agoHow would that work in this setup?
- dredmorbius 8y agoIf Facebook were required to hash and salt phone numbers, then the correct 2FA value might still work (it would match the salt and has), but an arbitrary list of submitted values would be expensive to match to the hashed set. Facebook would be unable to contact the user via SMS, they would have to issue a token via WWW or app and have the user text that to a specific address from the corresponding phone number to achieve phone-based 2FA. This might even be a third-party service to deny FB any direct access to the phone number. The verification channel might become a phishing target via spoofed FB pages or apps, though that would be moderately expensive and of limited use. An attacker might request FB login credentials (the actual verification would not), might acquire a phone number (generally, though not always, a non-critical datapoint), and would still be denied account access via 2FA without further compromises, say, social-engineering the phone account (a proven risk, though expensive at scale). Tildes.net uses a similar mechanism for recovery email addresses.
- deleted 8y ago[deleted]
- stordoff 8y ago> Would you rather use Netflix or Spotify without recommendation engine? I'd rather it didn't have a recommendation engine. I'm fed up with it trying to get me to watch something else - I'd rather it just stay out of my way.
- ric2b 8y ago> However, phone hashes are sent, not clear ones. A 10-digit number is only 10 billion possibilities, much less if you consider that they aren't completely random and have area codes, etc. You can probably brute-force a hash of a phone number in seconds to minutes _on a CPU_.