What’s Not Included in Facebook’s “Download Your Data”
wired.com
wired.com
- information Facebook collects about your browsing history;
- information Facebook collects about the apps you visit and your activity within those apps;
- the advertisers who uploaded your contact information to Facebook more than two months earlier;
- ads that you interacted with more than two months prior.
Download Your Data is particularly spotty when it comes to the information Facebook taps to display ads."
---
TL; DR When you get too close to their business model, Facebook clams up.
Mr. Zuckerberg and other Facebook staff assert: "We do not sell data."
Does Facebook acquire/purchase data about people from other sources, e.g., data brokers, and then combine it with (a) the highly personal data people voluntarily submit to Facebook and (b) the highly personal behavioural data people consent to allow Facebook to collect from their use of the Facebook website, Facebook app, and websites hosting Facebook anchors.
Is Facebook allowing users to download all the data Facebook has on them?
edit: tried it on chromium 66: doesn't work.
steps to reproduce:
1. open new (non-private) tab, go to http://httpbin.org/cookies/set?k1=v1&k2=v2
2. check http://httpbin.org/cookies/, the two cookies should be there, and if you check the dev console, the expiry date is 1970-01-01 - 1 second. firefox says it's "until end of session".
3. open new private tab, go to http://httpbin.org/cookies
4. cookies from above do not show up.
Here's what Google says about cookies in incognito mode: "If you use Chrome in incognito mode (or in guest mode on Chrome OS), it will not transmit any pre-existing cookies to sites that you visit. Sites may deposit new cookies on your system while you are in these modes; these cookies will only be temporarily stored and transmitted to sites while you remain in incognito / guest mode. They will be deleted when you close the browser, close all open incognito windows or exit guest mode." Source: https://www.google.com/chrome/browser/privacy/archive/201408...
I first noticed that FB might be able to detect sites you visit while in incognito mode when I noticed that I was personally being retargeted by sites I visited in incognito mode while on Facebook. Here's an interesting quora thread I found while looking into it: "Also the cookies act too important role here. Cookies during Incognito Mode are saved in temporary folder, and they get purged after session ends. But when browsing Facebook and Google in the same session, they both share same cookies folder and cookies help to send tailored ads to users." https://www.quora.com/Im-using-Incognito-mode-for-Google-sea...
Curious for your take.
To be clear, the claim I'm making is that normal windows can read cookies from incognito windows.
There are potential information leaks, such as the combination of IP address, user agent, screen size, and fonts available. And there may be bugs in 3rd party plugins like Flash that fail to respect private mode. But it doesn't seem to be anything as simple as cookies being shared.
* There's slightly more of a chance they'll actually delete my data
* If they don't, I'll be entitled to be a part of any class-action.
I had deleted (not deactivated) my account ~4 months ago and they were supposed to delete everything after 14 days but I have a feeling they didn't.
Most eu Nations don't have anything like a class action suit...
Currently I haven't done anything in response to it. I don't want my account but it's not clear what happens should I not accept. Does my account get deleted, or does it just get put in purgatory? Should I login and just delete after the 25th?
I am absolutely shocked to discover that Facebook doesn't have a class action waiver in their terms.
I don't know if it is the official term but your ghost is all the data Facebook has about you that doesn't come from you. For example, friends can talk about you and even tag you even if you never touched Facebook. It means that if you are the only one within your group of friends not using Facebook, they already know pretty much everything they need to know.
If you delete your account, unless all your friends do the same, your ghost won't disappear, and it can be easily reconnected if you create a new account.
It is not the official term, because Zuck is shocked—shocked!—at the term:
> Lujan: So these are called shadow profiles, is that what they’ve been referred to by some?
> Zuckerberg: Congressman, I’m not, I’m not familiar with that.
(https://techcrunch.com/2018/04/11/facebook-shadow-profiles-h...).
(OK, I realised just after posting that you said 'ghost profile', not 'shadow profile'. Anyway, my snarky point stands that there is no official term for this, because it doesn't officially exist.)
If you actually delete your account you won't be able to reactivate it. There is an option to deactivate it but then all of your personal data is preserved anyway.
> He later made a request under the European "right to access" provision for the company's records on him and received a CD containing over 1,200 pages of data, which he published at europe-v-facebook.org with personal information redacted.
Similarly with birthdays, although it's quite easy to work around that via their calendar link.
Also, IIRC, all the photos are resized smaller and recompressed, while the full-res versions are still accessible through the Facebook website. This also makes it harder to quit if 1) you don't have the original photos and 2) don't want to live with the unnecessary sacrifice of quality.
Facebook really ought to include the best versions it has of the data you've uploaded, even if it makes the archive size enormous. The option to shrink things should be a non-default option only, since the download might be a prelude to an irreversible account deletion.
Is it not one of their aims to make it always reversible?
Is it? Cases like this [0] make that seem unlikely.
Even without looking, the idea that a data broker would just willingly give us all the information it has is unbelievable. The scale is so large, how would you even know?
That is specifically not possible under GDPR. It doesn't matter where your company sits, if you store data from europeans (or people living in europe) you have to follow the GDPR with potential for severe punishment. There really is no loophole afaik.
Does that mean the company has to follow it even for non-European users?
And being FB, they really do not have a choice, since the EU do have leverage over them because they're doing business here.
Hope that simplifies things.
They can also file a case in the country that you do belong you to get you to pay your fines in the original country. This sometimes works.
This would be an enormously stupid move. It guarantees not only failure but an acidic backlash.
[1] https://www.reuters.com/article/us-facebook-privacy-eu-exclu...
This is an indication that they won't apply GDPR globally (for users in e.g. India or Brazil), but they don't have a choice for the EU users.
The discussion is here:
https://news.ycombinator.com/item?id=16872542
I don't see it in a quick scan, but I wonder if that means all the revenue from those countries will no longer be shielded from US taxes, which might indicate how seriously FB see the GDPR as a threat.
EDIT: pdkl95 mentions in another comment, they claim it doesn't.
They're also not allowed to infringe on the data rights of other users which is why the friends list export is so anemic, for example.
Since a fingerprint is like a hash, it is theoretically impossible for Facebook to determine if the data really belongs to you, or to someone else who happened to have the same browser fingerprint.
This means that if Facebook is legally obliged to offer a complete user data download, then the practice of fingerprinting is illegal.
* Can I use differential privacy? Can a user request a correction to such a dataset?
* If I train a ML model on some user data what responsibility do I have with acquisition or deletion?
* Can I anonymize my data-sets?
* How do I handle aggregate statistics?
I have always been paranoid about sharing information on social media. So, this section has only Facebook access information - 4G, Ipad etc. Couple of categories are even incorrect.
The best I could figure is that I temporarily enabled access to my camera roll so I could post a few photos (ordinarily I just copy/paste them to keep Facebook out of my photos), and either it scanned the photos' exif data during upload or directly from the roll once I enabled it.
I wasn't remotely surprised to find that particular piece of location data wasn't part of the data download.
Plus it only ever happened that once.
Geo IP location is possible but unlikely: the location was very precise and accurate, and I would assume Verizon (wasn't on wifi) wouldn't be handing out IPs with that level of specificity.
Plus it only ever happened that once.
Without this, FB's targeting abilities for ads just evaporates. It is going to be interesting to see how this pans out.
[1] https://ico.org.uk/for-organisations/guide-to-the-general-da...
Classic guilt-by-association propaganda technique.
> The leaks continued steadily from there, as the suit details. Guccifer 2.0 struck again on June 27, June 30, and July 6. On July 22, WikiLeaks took the wheel, releasing nearly 20,000 internal DNC emails. The following day, according to the suit, multiple DNC employees received an email that said: “I hope your children get raped and murdered. I hope your family knows nothing but suffering, torture, and death.”
All evidence suggests, as Wikileaks has maintained, that their emails came from a physical source, and not Guccifer 2.0.
I think there is a larger editorial bias at play at Wired.
[0] https://www.wired.com/story/dnc-lawsuit-reveals-key-details-...
It felt forced and awkward in the context of the article.
It'd be nice to download my data and import it into a competing social network.