13 ms·
Facebook Defends Getting Data From Logged-Out Users
- rwolf 15y agoI'd be interested to see how many competing social networks exhibit the same behavior. Specifically, Twitter and Google+ has similar social buttons. Imagine I wanted to do this but not be get caught. What would you improve? Clearly the cookies will need to look different pre and post logout, but how different?
- elehack 15y agoI would remain suspicious if there was any identifying or unique information in cookies after logout. Ideally, logout should delete all cookies.
- rwolf 15y agoI already pointed out that HN leaves a cookie behind in another comment, so here's a different tack: is there a site on the first page of http://www.alexa.com/topsites http://www.alexa.com/topsites that actually leaves no cookies behind when you logout? A major faux pas like leaving your uid in the clear in the cookie after logout certainly seems to bother us, but I don't think users (even savvy users) care about leaving some cookies behind. For the record, I've installed various opt-out browser extensions in the past (only to switch computers/browsers and forget to bring them along)--I don't think my views are pro-cookie or even moderate.
- wnight 15y ago> I don't think users (even savvy users) care about leaving some cookies behind. In most contexts, that is true. A Slashdot cookie is just a line in a text file until you visit Slashdot. But a Facebook cookie is sent home every time you visit a page with any FB spam on it. The mysql.com malware is trivial. Hitting Facebook would get most everyone, users and not.
- pyrmont 15y agoWhy do the cookies need to exist? If I log out from your service, why do you need to keep a cookie on my computer?
- rwolf 15y agoHell, HackerNews leaves a cookie on your computer after you log out with some opaque blob holding who-knows-what. Users like to complain about cookies when you bring them up, but generally can't seem to bother. Including the two of us.
- ltamake 15y agoHacker News doesn't have like buttons or other widgets all over the Internet...
- tedunangst 15y agoAs stated in the article, so when you login again from the same computer, they don't have to do the whole two factor "I've never seen this computer before" text message handshake with you.
- lpolovets 15y agoBejar said Facebook is looking at ways to avoid sending the data altogether but that it will “take a while.” Maybe I'm naive, but why would turning off the gathering of information take a while? This reminds me of unsubscribing to email newsletters, where the final goodbye says something like "you should stop receiving our emails within 6-8 weeks."
- jurjenh 15y agoI wonder if that involves something like collecting the data and storing it locally on your computer, then only sending the data once you log into facebook...
- rwolf 15y agoNot how cookies work. Visit any page with loads the facebook like widget iframe/img/script -> make a request to facebook with your cookie.
- jurjenh 15y agoI was thinking more along the lines of a local store, but then you'd need a little script embedded into every page to handle the storage. Essentially, instead of FB like widget -> request to facebook I would think FB like widget -> add to local datastore. Then FB could do an optimised/aggragated query on the local database. The only thing would be that it would introduce large latency in the resulting data if its sent back only on FB login.
- pork 15y agoThat's a micro/premature optimization at facebook's scale.
- mnutt 15y agoAny code changes take a non-trivial amount of time. It sounds like the solution is to delete more of the cookies on logout, but there may be other Facebook services that use them and need to be transitioned away.
- polemic 15y agoThe company says the data is sent because of the way the “Like” button system is set up; any cookies that are associated with Facebook.com will automatically get sent when you view a “Like” button. They have a point. This is going to be the same for any site that has static content served elsewhere with cookies attached to the domain. Hot link to an image on my blog you commented on? OFFLINE DATA GATHERING ZOMG.
- tripzilch 15y agothe difference is, that's not linked to your FB accounts and friends network / social graph. not that third-party cookies aren't a big privacy issue, but this goes one step further.
- bandushrew 15y agothey dont really have a point, cookies are nailed to a specific domain or sub domain. If they really wanted to they could easily associate the like button with a subdomain of facebook if the user isn't logged in, such that the cookies associated with the user login don't get sent. They don't really want to.
- nbm 15y agoHow would whatever system that does this discover that the user is or is not logged into Facebook? The javascript portion doesn't have access to cross-domain cookies, so that won't work. Anything else requires connecting to a domain such that cookies are passed on so that it could discover whether the user is logged in or out before passing it to a subdomain. (I work at Facebook, but not on this.)
- bandushrew 15y agohmm? without pretty specific knowledge of the problem set facebook is trying to solve with its current set of code I am clearly unable to offer a solution that will resolve them all. However, if one of the problems that they wanted to solve was 'we dont want to track user data unless they are logged in', they would have solved it by now. The fact that they haven't means either (a) they just haven't thought about it or (b) they have thought about it, but do not want to solve it.
- tripzilch 15y agoTheir defence doesn't hold much water. But then, I can't imagine any excuse that would satisfy me. They say “The onus is on us is to take all the data and scrub it,” said Arturo Bejar, a Facebook director of engineering. “What really matters is what we say as a company and back it up.”, except their track record on that matter isn't exactly stellar. We know they don't actually delete messages or things you delete on FB, they just mark them "deleted". With that attitude to "deleting" things, what does it even matter? And I don't care if they promise the data is not used for targeting ads, that is just one of the many ways this type of data can be abused. The argument they use it to prevent "spam and phishing attacks" also seems dubious to me. How does that work? And the cookie that's kept contains just your facebook ID, so wouldn't that be trivial for spammers and phishers to work around? And the most important thing is, they might act all innocent about it now, that they did it with the best intentions and not to continue tracking people after they log out. Let's believe that and lets assume this behaviour doesn't involve any other privacy implications: Facebook is by now well known for their feature-creep, if we hadn't caught them red-handed now, what's to say they wouldn't be using this data in a few months from now? Sorry but it's all bullshit. Facebook doesn't care one bit about their user's privacy, they've made that perfectly clear by now, and them pretending to do otherwise in this article is absolutely laughable.
- mikeryan 15y agoWe know they don't actually delete messages or things you delete on FB, they just mark them "deleted". With that attitude to "deleting" things, what does it even matter? I've never written a web app that actually deletes data. The argument they use it to prevent "spam and phishing attacks" also seems dubious to me. How does that work? And the cookie that's kept contains just your facebook ID, so wouldn't that be trivial for spammers and phishers to work around? Actually its an attempt to make life easier on users. When you log in from another machine they sometimes use enhanced measures to confirm your identity. By keeping the cookie they get more confirmation that you are you. I'm not justifying it. There's ways to prevent this that weren't taken. But I can see what they're trying to do.
- rhizome 15y ago
- andrewpi 15y agoAnother good reason to run something like ShareMeNot [1] - it blocks Facebook from receiving anything unless you specifically click on a 'Like' button. [1] http://sharemenot.cs.washington.edu/ http://sharemenot.cs.washington.edu/
- iamleppert 15y agoWow, has anyone here ever set multiple cookies? People are blowing this up bigtime. Facebook sets multiple cookies, one for an active user session and another token that serves to authenticate a user has previously logged into facebook, so they don't need to enter extra security questions. Who else does this? Major banks, forum software, etc. It's a common technique. All that matters is what Facebook actually does with the data, and their privacy policy, just like the Engineer stated. If you're paranoid, either don't use Facebook or clear your cookies after you log out. Don't you just love simple solutions?
- spot 15y agoit's different because banks don't have "like" buttons that track your browsing across the web.
- FuzzyDunlop 15y agoThe cookies are somewhat a red-herring when you consider how insignificant they are compared to other methods of tracking. They don't need a cookie in place to receive the IP of whoever loads a page with a Facebook 'like' button on it. They're a big enough company with smart enough people to develop algorithms that can associate an IP address to a user account to at least a 95% confidence interval. They've got all that stuff you type in your profile and all the things you've shared to aid that, and the more you use your account the better they can predict. To that end I'd be surprised if they don't continue to track 'deactivated' Facebook accounts. Not in anticipation of you going back to it, of course.
- suking 15y agoTracking by IP is pretty useless with so many people on phones, aol, etc. Plus, multiple accounts per workplace, just doesn't work...
- alastairpat 15y agoTracking by IP is a ridiculous idea. My mobile phone provider uses transparent proxying for its mobile Internet - I must share the same external IP as thousands of other people when I browse the web via my phone. Not to mention that households using NAT will have three plus accounts from the one IP, let alone businesses with hundreds. Internet-facing IP simply isn't unique enough for these purposes.
- DougWebb 15y agoMy inclination is to agree with you; the IP is hardly a unique identifier. But they don't need perfection. Think about it: most people, most of the time, will send requests to FB from just a few IPs and maybe one ISP proxy network (which FB can recognize as a proxy.) They know that your account is associated with these IPs based on tracking cookies. So, when they see a request from one of these IPs without the cookie, they can do a reverse lookup to get a list of possible accounts. That narrows the field. Next they can do a semantic analysis of the page that had the Like button which sent the request, and compare that to pages previously associated with the possible accounts. If one of them stands out as a likely match, they can be pretty sure who sent the request. The more data they gather, and the more relationships they can record between you, your friends, and the pages you visit, the better they will get at tracking you without the cookies.
- thoradam 15y agoHow about if browsers implemented this cookie system: Each time a cookie is set, you could have the ability to mandate when that cookie is sent out. For example with a Facebook cookie you could tell the browser to only send that cookie when your address bar reads facebook.com. Problem solved?
- executive 15y agoThey do.. it's called disable third party cookies.
- thoradam 15y agoNo that's for setting cookies, so that website A can't set cookies on your machine while you're visiting website B. What I'm talking about is the ability to limit when cookies as sent out with requests. Privacy wary users could perhaps have their browser set so that for example Facebook cookies are not sent to Facebook just because you're visiting a website that has code from Facebook on it, but only when you're actually browsing Facebook.
- jstanderfer 15y agoThis is a great example of the inherent conflict of interest when your users are not your customers, in fact they're your product. http://johnstanderfer.com/2011/09/26/facebooks-most-important-product-you/ http://johnstanderfer.com/2011/09/26/facebooks-most-importan...
- pork 15y agoPlease don't take this personally, but the whole "you're the product" meme, while it has a shred of truth in it, has been so re-hashed on the net that it's no longer pithy or informative. Just google for "you're the product" and you'll see what I mean.
- jstanderfer 15y agoI don't take it personally at all. The meme is common among people familiar with the internal workings of consumer web business models. My concern is that its not well understood outside that group. I also think it's an interesting way to view the rollout of Facebook's new features and public reaction to them.
- RexRollman 15y agoHow anyone from Facebook could make those statements with a straight face is beyond me. In my opinion, Facebook has a serious credibility problem.
- rblion 15y ago"And earlier this year, Facebook discontinued the practice of obtaining browsing data about Internet users who had never visited Facebook.com, after it was disclosed by Dutch researcher Arnold Roosendaal." I'm going to trust my gut on this one. I just get an uneasy feeling from their track record of 'mishaps' and the excuses that follow. There is a lot of stories that don't get enough attention or make enough people think... Facebook might be called BigBrotherBlue when people look back one day. BigBrotherBlue is always watching.
- deleted 15y ago[deleted]
- rumcajz 15y agoIsn't there a way to run specific web applications, like Facebook, in a virtual sandbox? I.e. storing its cookies separately from other apps, launching new unrelated browser instance if you browse facebook from/to some other site etc.?
- 0x12 15y agoThe real winner here is Google. Facebook makes Google look good. And that's pretty sad. When your users are logged out you have zero business tracking them or trying to do so.
- amnigos 15y agoIf you want to stop pushing tracking data to Facaebook from your machine then just add a local redirect in your hosts file for facebook.com to map to 127.0.0.1 and just comment it when you want to use Facebook site :)