9 ms·
PSA for any devs out there implementing FB Pixels: – Facebook's pixel will, by default, attach click listeners to the page and send back associated metadata. T
by cosmie 6y ago
PSA for any devs out there implementing FB Pixels:
– Facebook's pixel will, by default, attach click listeners to the page and send back associated metadata. This simplifies implementation needs, but can create unintentional information leaks in privileged contexts. To disable this behavior, there's a flag[1] you can use. After which, you can manually trigger FB Pixel hits and control both when they're fired and what information is included in them.
– There's a feature for the FB Pixel called Advanced Matching[2] that allows you to send hashed PII as parameters with your FB events. "Automatic Advanced Matching" can be enabled at any time via a toggle in the FB interface. I believe that setting autoConfig to false as mentioned above will similarly prevent Automatic Advanced Matching from working (since it disables the auto-creation of all those listeners to begin with). When manually triggering pixel calls like above, you can use this functionality via "Manual Advanced Matching"[3].
As a general rule, I'd strongly encourage anyone implementing a Facebook pixel to also include the autoConfig = false flag. This makes it work like most other pixels, where the base tag just instantiates an object. After which, hits only occur when explicitly defined in the site code, and include specifically what details you include in it. That way you're fully aware of the scope of data disclosure happening and any need from marketing to include sensitive (or potentially sensitive) information in these calls has to be explicitly requested (and theoretically vetted) as part of the standard dev process.
[1] https://developers.facebook.com/docs/facebook-pixel/advanced#automatic-configuration https://developers.facebook.com/docs/facebook-pixel/advanced...
[2] https://www.facebook.com/business/help/611774685654668 https://www.facebook.com/business/help/611774685654668
[3] https://developers.facebook.com/docs/facebook-pixel/advanced/advanced-matching https://developers.facebook.com/docs/facebook-pixel/advanced...
- miked85 6y agoThis is good info, but Backblaze shouldn't even be using FB pixels to begin with.
- KingOfCoders 6y agoExactly. When the most important thing for a backup provider is the trust people put in you, don't do anything that risks that trust.
- gigatexal 6y agoEdit: my biases against Facebook keep me from making cogent points.
- mvzvm 6y agoThis feels like an almost intentional misunderstanding.
- gigatexal 6y agoPixel tracking on an internal customer page... scanning and uploading metadata about users backups? How much am I misunderstanding?
- mvzvm 6y ago> I guess they can’t afford to cover costs given current prices so they sell customer metadata to Facebook This sentence, your thesis, is absurd. Where does it say they make money from selling data? Furthermore, "I guess they can’t afford to cover costs given current prices" is a really strange foundation to leap from. Do you have any facts? Or are you just speculating on BackBlaze and making wild assumptions? > now that other like-minded crazies can find each other faster than ever You are right, there is nowhere else online where "crazies" gather - not 4chan, not reddit, not voat, not twitter, just Facebook?
- gigatexal 6y agoThe last point I’ll admit exposes my bias against Facebook. But the previous two points make no difference on why tracking is baked into an internal portal so I speculated as to the reasoning as anyone would do — it’s not a stretch to think that data owners could sell customer data to an aggregator like Facebook for an additional line item of revenue.
- manigandham 6y agoFacebook does not, and never will, pay for data like this.
- cosmie 6y agoI don't necessarily disagree with you, and whether a pixel should be there at all is definitely a discussion in itself. But for those who are implementing FB Pixels, I wanted to put out some potentially useful information that can help protect against unintended data disclosure, after mentioning the auto-listener behavior in a reply to another comment and being met with surprise[1]. [1] https://news.ycombinator.com/item?id=26537078 https://news.ycombinator.com/item?id=26537078
- nerdponx 6y agoSeems like it's designed to make it easy to accidentally send more of your users'/customers' data back to FB than intended. Oopsie!
- azernik 6y agoGiven their (paying) customer base, which skews more towards content producers, I suspect it's more likely intended to ease setup for less-technically-savvy users. ie they don't really want your truly-security-critical customer data. But if they can boost their conversion rate with sites like dogfoodreviews.com by 5%, and the price is sending backblaze.com's fantastically-sensitive paid customer data into an unsecured data path, they will absolutely do it. Comparable to the absolute havoc that Zoom wreaked on browser security to save one click on starting a call.
- cosmie 6y ago> I suspect it's more likely intended to ease setup for less-technically-savvy users. > ie they don't really want your truly-security-critical customer data. It's both. It eases implementation with a one-and-done snippet, and then slaps a user-friendly GUI on the other side for marketers to sort through the firehose and use what they want. While making it also trivially easy for marketers to toggle a button that OKs the turbo-boost mode that siphons up (hashed) sensitive customer information, which can then be used to claim credit for additional conversions by cross-referencing the (hashed) PII siphoned up against what Facebook has for those exposed to your ads.
- 6y ago
- mvzvm 6y agoWhy is that? Perhaps they get business value out of it?
- bschwindHN 6y agoWon't somebody please think of the business value???
- manigandham 6y agoThat's how businesses make decisions.
- bschwindHN 6y ago> Backblaze shouldn't even be using FB pixels to begin with. > Why is that? Perhaps they get business value out of it? Oh, they get value out of invading my privacy? Carry on then!
- manigandham 6y agoRunning and measuring ads is one of many things that delivers value to a business, yes. The privacy issue in this case is clearly an implementation mistake and seems to have been resolved. Ignoring the situation and context to make a comical statement doesn't really add anything to the discussion.
- ksec 6y agoThe overwhelmingly mentality on HN is that All Ads are bad. And all targeting Ads is bad. Because by their definition, All ads are tracking ads. This mentality also fits the current Internet and Twitter narrative. Especially true when it is from Facebook. Which happens to be pure evil on HN, twitter sphere and MainStream Media.
- Nextgrid 6y ago
- manigandham 6y agoWhy? Using ads to increase business is completely valid. This issue is data leakage due to an implementation error and has nothing to do with using advertising services from Facebook or other companies.
- deleted 6y ago[deleted]
- Nextgrid 6y agoThere are ways to use ads without violating privacy nor breaking the law (remember that this practice is illegal under the GDPR). Either way, if you must do ad tracking, do so on your homepage. Once the user is logged in and has paid you money for a service there shouldn’t be any ads nor tracking.
- manigandham 6y ago> "without violating privacy" Yes, that's covered by this being a mistake in implementation as I said. > "there shouldn’t be any ads nor tracking" Again, based on what exactly? Finding new users that are similar to your existing customers is a completely valid strategy. Most people in this thread are making wild statements from the typical emotional/outrage driven pile-on when anything happens.
- Nextgrid 6y agoBased on respect, common sense and the GDPR? > Finding new users that are similar to your existing customers is a completely valid strategy. But this can be achieved with tracking in the homepage without embedding trackers in the actual product right next to sensitive data? > Most people in this thread are making wild statements from the typical emotional/outrage driven pile-on when anything happens. This doesn't make these statements any less valid though? Most people are indeed outraged that a paid professional product is ratting them out to Facebook which makes total sense as nobody would've expected that.
- 6y ago
- Corrado 6y agoThe thing that concerns me about the FB Pixel (and GTM) is that the host is completely free to do anything and everything to the page. Even if they don't do anything "evil" today, tomorrow is a different story completely. This scares the pants off of me and makes me want to rip out any "tracking" that I've ever installed on any site anywhere. Actually, that's probably not a bad idea. Are there no browser level protections for this type of thing? I thought CORS was supposed to prevent these activities from happening.
- cosmie 6y agoVirtually all tracking boils down to 1x1 sized images getting embedded on the page, with various metadata being attached in that image call. The javascript libraries may include other functionality (like additional fingerprinting and such), but are primarily just convenient abstractions that generate and embed the the tracking images for you. Most provide the details needed[1] to build your own generator function, which would allow you to integrate the tracking you want while reducing your security exposure to third party code. As for GTM – a deployed container is self-contained. If you don't want to expose your site to third party code, but want to use GTM as a convenient control plane for configuration of tags and tagging rules, you can do that. Instead of using the standard snippet that loads the container from Google, you can just grab the generated javascript file for the container after a new deploy and self-host it. It gives you the convenience of GTM (central control plane for tagging-related stuff, versioning and commenting, etc) but without the security exposure of embedding externally hosted scripts. [1] https://developers.facebook.com/docs/facebook-pixel/advanced#installing-the-pixel-using-an-img-tag https://developers.facebook.com/docs/facebook-pixel/advanced...
- tga 6y agoThe actual 1x1 pixel is a leftover from the previous generation tracking tools, and even the page you liked to recommends _against_ using that method because it can’t spy on users enough. Here we are talking about a tracking _script_ embedded in the page and sending to Facebook everything the user does (“standard or custom events triggered by UI interactions”). Using only a pixel to track how users move around the app wouldn’t have landed Backblaze in as much hot water. Instead, it looks like the Facebook _tracking script_ (automatically) exfiltrated sensitive data like file names, and that crosses a limit.
- Lukas_Skywalker 6y agoAs a protection for the users, addons like Facebook Container for Firefox [0] can isolate all Facebook tracking and prevent the scripts from running on pages that are not facebook.com. [0] https://addons.mozilla.org/en-US/firefox/addon/facebook-container/?src=external-www.mozilla.org-facebookcontainer&utm_source=www.mozilla.org-facebookcontainer&utm_medium=referral https://addons.mozilla.org/en-US/firefox/addon/facebook-cont...
- rciorba 6y agoEven just using an ad-blocker will prevent this: https://github.com/gorhill/uBlock https://github.com/gorhill/uBlock
- corobo 6y agoAnd if that doesn't tick your creepy boxes lets try the financials. If a user hits your tracking pixel they (and those like them) will more likely see ads similar to yours, meaning potential customers will be more expensive to obtain now. Don't give data to Facebook lmao.
- hertzrat 6y agoI have a question about tracking scripts: can they read what we type into browser addons? Eg, your master password when unlocking a password manager?