Facebook’s Instant Personalization Is the Real Privacy Problem
gigaom.com
gigaom.com
Google may have (deservedly) gotten a black eye for the Buzz debacle, but they have a lot of cultural DNA that values privacy (their CEO aside) and at least some systems in place to allow management of personal data (as well as data exodus).
Facebook on the other hand is clearly all business and will bend privacy concepts till their either break or users are conditioned to accept lack-thereof as the new standard (all in the name of "sharing").
Though if you use your loyalty card and then pay with a credit card I guess they could link back to the "real" you.
Instant personalization means that if you show up to the Internet radio site Pandora for the first time, it will now be able to look directly at your Facebook profile and use public information — name, profile picture, gender and connections, plus anything else you’ve made public — to give you a personalized experience.
Is this true? A simple enable or opt-in prompt in the frame on the first visit to a site would be the expected behavior here.
The opt-out prompt is in the form of a blue bar at the top of the page. Once you say "No thanks" they are required to remove any of your information and not connect you on future visits.
This was without prompt, as qhoxie states.
Wait a minute; Yelp? Isn't that the small business extortion site? What a weird outfit for anyone to want to associate themselves with.
It seems to have removed all Open Graph stuff from the web for me.
A greasemonkey script to always click 'No Thanks'.
It has lots of insightful and useful information about identifying and controlling Enterprise 2.0 apps (Facebook, Twitter, Skype, SharePoint, etc.)
As more sites adopt these, Facebook will be able to track every site you visit on the web. I don't know about you, but I'm not comfortable letting Facebook know which sites I visit.
Google adsense/doubleclick is fairly prevalent and has the same issue. You can opt out of it with Google though: http://www.google.com/privacypolicy.html -- the Facebook settings I have seen aren't clear about their data retention policies and what 'opting out' really means.
Moreover, any site can display your profile information. http://cnn.com even seems to combine it with what CNN stories they liked recently, which makes me wonder how much data they can read back. Has anyone taken a look at the Facebook social plugins to determine how much data, if any, you can get out of them?
Facebook uses their parent-child-parent iframe tricks to assign a first-party cookie for the host domain. This cookie contains the Facebook user id and the OAuth access token used to make requests to the Graph API.
Any javascript running on the page can snatch that cookie and send the data back up to its mothership, which can then impersonate the host domain to make API requests on behalf of the user. Fun stuff.
Facebook knows it could lead to some major backlash too, so they're being very conservative with the initial rollout. If you go to Yelp, it's actually hard to tell at first glance that any data sharing has occurred. Go to Pandora and it will know what bands you like, but who is going to get upset about that? And Docs.com doesn't appear to be open to the public yet.
As the program expands, though, there could be a pretty serious shitstorm. I don't think people understand what the 'Everyone' option means, and this could be the first time they realize what they signed up for during Facebook's privacy overhaul last December, when Everyone became the default.
"Please keep in mind that if you opt out, your friends may still share public Facebook information about you to personalize their experience on these partner sites unless you block the application."
For those who don't want to have to log in to find out:
"What your friends can share about you through applications and websites:
When your friend visits a Facebook-enhanced application or website, they may want to share certain information to make the experience more social. For example, a greeting card application may use your birthday information to prompt your friend to send a card
If your friend uses an application that you do not use, you can control what types of information the application can access. Please note that applications will always be able to access your publicly available information (Name, Profile Picture, Gender, Current City, Networks, Friend List, and Pages) and information that is visible to Everyone."
(I'm pretty sure at least current city wasn't on that list until fairly recently.)
Checkboxes for lots of other information follow.
This move by FB makes whatever mistakes Google made with Buzz look relatively innocent. They need to get burned hard over this.
This proved to be very unpopular with customers and they stopped doing it... they probably still use the caller ID but don't let you know that they are.
Last.fm always generated you radio stations based on your scrobbles or by tags you type and predates Pandora
Or to be more precise, please use proper English. If English is your second language, we are forgiving -- unless your first language is AOLspeak.