6 ms·
Clearly I need to step it up. I was (unsurprisingly) surprised at what I've observed they've managed to correlate. I run standard pi-hole, resist fingerprinting
by thegeekbin 7y ago
Clearly I need to step it up. I was (unsurprisingly) surprised at what I've observed they've managed to correlate. I run standard pi-hole, resist fingerprinting, and normally go through a VPN (mainly because I'm on public wifi half the time when travelling). I haven't logged into facebook in about four years, just did it for the first time today to see what's been correlated.
Aside the mountain of irrelevant notifications, here's what I've observed in this report that's concerning.
1. Albeit some data has been correlated properly (banking applications which is scary on it's own part it's sending data to facebook, imgur, Xbox, my telco provider, and a few misc blogs I've visited a handful of times per year), it's correlated a significant amount of data that may not belong to me (good thing, I suppose?)
2. Why the heck are banking applications sending data to Facebook as "CUSTOM", with no context? For example, RBC bank in Canada sends "CUSTOM" data (haven't been with them for over two years, but all interacts labelled CUSTOM) and Facebook will not give any more context on the exact data it received. Little scummy, Facebook.
Well, time to sweep this up and resist tracking more. Let's see how it works this time round.
- monkeynotes 7y agoWhen you say `interact[s]` you mean interactions right? Not interact transfers?
- xfalcox 7y agoYou will want to use Firefox containers in order to isolate the Facebook cookie into a container to limit this.
- ocdtrekkie 7y agoI use Facebook container and most of the sites reporting should've never even seen my Facebook account. However, many of these sites have my email address. I highly suspect they're correlating data without knowing my Facebook account itself.
- untog 7y agoThey definitely do for advertising, at least. You can click “why am I seeing this” it’ll tell you as much.
- untog 7y agoUnfortunately there are no good answers for this on mobile.
- propogandist 7y agoif you're using android you can get add-ons for firefox. Also, you can use a firewall app like Netguard [1] to prevent apps from calling FB (graph.facebook.com)... I see most apps attempting to do this, and it's often the first thing they do. There's similar setups on iOS, I am just not very familiar with the app names. [1] https://github.com/M66B/NetGuard https://github.com/M66B/NetGuard
- wtmt 7y agoAt the risk of a bit of inconvenience, you could use Firefox Focus. Browse (it's only one tab), erase at the end of browsing and repeat. It also has built-in blockers of different kinds.
- gpvos 7y agoHmm, I don't use pi-hole, just uBlock Origin and Firefox containers, and they've only tracked three minor things, probably when I had some problems with my phone and uBlock wasn't working right. So how were they able to track so much about you? Do you have the Facebook or Whatsapp app on your phone? Or is this just the difference that they track much more in the US than in Europe?
- TACIXAT 7y agoMy activity was largely from apps on my phone. I just uninstalled and reviewed every one of those that was unnecessary. Unfortunately I need to find a new financial aggregator, because mine was sharing data with FB. I've seen a few self hosted ones listed on hn.
- novok 7y agoI think you can't avoid links you click within facebook itself right?
- y-c-o-m-b 7y agoThey only had two small websites for me. Great success! I'll share my strategy. On desktop: Banking: Vivaldi Browser w/ privacy badger and ublock origin Email and Commerce: Chrome Browser w/ privacy badger and ublock origin News and other BS (like Hacker News): Firefox browser, always in private mode w/ privacy badger and ublock origin LinkedIn (in the rare case I use it): Internet Explorer Mobile: Facebook: Opera Commerce: Chrome Reddit: Naked Browser News and other BS: DuckDuckGo Browser EDIT: I also do not use my credit card on my phone unless in extreme rare events. Absolutely no banking on my phone. No fancy apps (I use the web version where possible) beyond the generic stuff like email and maps. I use Signal for texting.
- deadbunny 7y agoI also had only 2 sites/apps. One I used Facebook oauth, the other I'm not 100% sure what it was. My strategy (Desktop & Mobile): Firefox + Facebook Container & uBlock Origin & Privacy Badger & DDG as search.
- mnicky 7y agoFor me they have nothing (success! :) I use Firefox + FB container + uBlock Origin + Privacy Badger and recently started to use CanvasBlocker as well. I have Firefox configured to delete all cookies on closing (except for few sites to avoid the need to enter the 2FA code every time I log in). I've also set Firefox Enhanced Tracking Protection to "Custom mode" with "cross-site and social media trackers" blocked [1] and to use block list "level 2". I also have the "Do Not Track" option switched on. I don't have a proper smartphone (never owned one), just KaiOS-powered dumb-phone on which I use Facebook mobile (i.e. their web site) all the time. Also no Pi-Hole or similar stuff. I use a throwaway email account for Facebook. ______ [1] Just now I've found out that there seems to be a new option, to disable "all cookies from unvisited sites", which I'm going to try as it looks even better.
- sails 7y ago> I use a throwaway email account for Facebook I feel like this might be key, I use a random burner number and this seems to confuse the tracking.