I think that's what GP is referring to.
Perhaps you object to the page impression being tracked even if you don’t like it? This seems unavoidable unless you mandate publishers host their own copy of the code behind these buttons and use a public API only to record the likes.
Yes, that's the consequence (well, it does't really have to be an API triggered from the server, it can send the user there). Or a pattern where a user has to click a locally hosted link/button which then loads the Facebook one, and/or records permission to load it with further page visits.
It's not really that much difference from an integration perspective if you include code in your page that loads a facebook iframe, or code that only does that after user interaction.
Yes, the default configuration has your page include javascript from facebook.net which the browser will request on every page view
https://developers.facebook.com/docs/plugins/like-button
In the case of this the theguardian.com page it looks like they've got a webbug as the last element of the body, which results in a request to https://www.facebook.com/tr?
Having facebook count views of your like button is probably considered a feature to publishers.
And they were tracking even non-Facebook users this way. There's zero consent here no matter how you cut it.
Worse yet, Facebook did this for years, and in the first years it swore it doesn't do that, and when they were caught doing it they said it was "just a bug"...twice.
Facebook has 0% credibility at this point. Just look how they're ruining people's trust in 2FA security, too, now (although if they end-up ruining the trust in SMS 2FA, that wouldn't be too bad of an outcome actually...).
This is a good article (although not complete, and only until 2014) on Facebook's awful, no-good, history of lying and tracking users without their consent:
https://www.propublica.org/article/its-complicated-facebooks...
Thats not true. You implicity consent to usage policy of that website which then gave permission to FB. Ofcourse GDPR makes it illegel but until May 25 its not.
If Facebook means no harm, they could make this the encouraged way to include the like button.
We can remind people that the internet is still a dangerous place, while also trying to discourage bad behaviour
But right now I can install any number of tools on Google's own browser that mitigate most common tracking/privacy concerns. I don't necessarily agree that we need to increase government regulation to address a concern that a Chrome extension is already serving.
This warrants a political solution and I'm glad that the EU is moving into the right direction.
Then your beef is not with FB but the website which _chose_ to embed FB like button. You should stop using that website if you are not ok.
The argument "just don't participate in society if you don't want people tracking every news report you read" doesn't really sit well with me.
Google analytics should not be allowed without me getting a prompt to allow it or not, FB button should be a simple static image without tracking unless I click on it. Also they track users that are not logged in or do not have accounts.
One way to go about it could be to force all these data collectors to show what they know about us, how much they shared and with whom, and allow us to delete that data on request. I'd really like to know everything FB tracks on those like buttons, it's probably an obscene amount of personal data.
Once people see how much data they retain, there would be a righteous outrage. These datasets have been provably used to manipulate elections, subvert democracy and target us with fake news. I'd like a report of what fake news and politically motivated ads I've been served by their recommenders. Maybe if they are forced to come out in the clear about what they do with our personal info, they would change their tactics. We need reverse surveillance on FB and the other tech giants and ad companies.
When you request a page like this guardian article, all they'd have access to would be:
* The url you requested, along with time and IP
* Any facebook.com/facebook.net cookies you have stored
* Any other headers your browser sends
* Metadata about the page itself that the publisher publishes via "og:" tags
Said og: tags look like this:
<meta property="og:title" content="Facebook ordered to stop collecting user data by Belgian court"/>How does that compare with what you meant by "obscene amount of personal data"?
Seems reasonable to call that obscene.
The users should have a choice, "Do you want this site to share your data with Fb,Google ?" If you do not accept you can't use it, but it is your choice not to use the website, the users will get informed because now I am sure most of the people don't even know about the tracking.
Just like on HN there is no page with 'favorite articles'.
Oh wait ;)