4 ms·
„Swedish Radio News reporters have tested the tip-form on ECPAT's website and found that their name, email and telephone numbers were shared with Facebook.“ Ho
by lucakiebel 3y ago
„Swedish Radio News reporters have tested the tip-form on ECPAT's website and found that their name, email and telephone numbers were shared with Facebook.“
How the hell does this just happen? Have people forgotten how to build simple forms and just use Facebook?
- kevviiinn 3y agoCan't profiles be made private?
- mschuster91 3y agoThey probably embedded tracking pixels because PR teams wanted to have data on how many people viewed the page vs how many people actually filed a report.
- Ekaros 3y agoWhy do I get feeling time and time again that developers pick the easy solutions. Not the sensible ones. Some type of page download counter should not be impossible, and number of reports should also be easy metric. Why do they even think they need to get someone like Facebook involved...
- mschuster91 3y agoIn almost all organizations outside of IT, IT is at the bottom of the social ladder. They gotta do what management wants. And that won't change until enough large organizations get hit hard by fines that everyone else follows suit and hires actually capable CTOs with veto power over everyone else.
- JansjoFromIkea 3y agoPoor supervision over something like Google Tag Manager resulting in someone on the PR team adding extra stuff without being fully aware of the repercussions
- VoxPelli 3y ago100% this, the marketing team wants to have Google Tag Manager to inject random marketing scripts all across the page and management backs them up and then the development team has no insight to or no say in what actual scripts are run on a specific page. That said: This is a GDPR nightmare and so is Google Tag Manager
- somedude895 3y agoThe way I could imagine it happens is that they use GTM to trigger Facebook tags, for example to remarket people who have donated to ECPAT, since people who donate are likely to do so again after say a month or during Christmas so that's a perfect audience to have available for an ad campaign. But they have GTM fire FB on every single page out of convenience, since setting up rules in GTM on where to trigger it is work. The tip-off page is hosted on the same environment, so FB triggers by default.
- austinpena 3y agoSomething is off here. When PII data is shared with Facebook, it gets hashed before it gets sent. In fact, Facebook warns you if you are “leaking” PII in places like URL parameters that get picked up by their tracking pixel. If they discover pageview events with PII in them, they throw them out. I’m not justifying that hashed data is okay… but clear text data is not received or stored by Facebook via a Facebook Pixel, or their conversions API.
- throwaway173738 3y agoIf facebook had the clear or hashed data anywhere else you’re still leaking it just with extra steps. Hashes don’t by themselves anonymize. If you have access to the original data it’s trivial to recompute the hash and build your association that way. You could assume the data is salted but that’s not always a safe assumption.
- austinpena 3y agoI am not here to defend Meta, only clarify how data is transmitted. Data is not salted as far as I can tell, it's normalized and hashed via SHA256. They publish SDKs for serverside integrations so you can see how the code is set up. https://developers.facebook.com/docs/marketing-api/conversions-api/guides/business-sdk-features/ https://developers.facebook.com/docs/marketing-api/conversio...
- gcr 3y agoFacebook knows the nine billion most common human names. On my Mac, sha256() takes 288ns, so running nine billion of them to find the collision would take about 43 CPU-minutes.
- mkmk 3y agoThe whole point of sending the hash to FB is so that they can look it up against the hashes of people to whom they have served an ad.
- deleted 3y ago