Facebook has always sold data to advertisers, and it probably always will
nytimes.com
nytimes.com
If you asked an average person what "selling data" means, they would describe a much more straightforward exchange: you pay me, and I tell you the names of woman interested in skiing.
Consider a real world comparison. You run a ski class for woman. I pay you $100 to distribute vouchers for a range of ski equipment at my store. If a customer shows up with a voucher then I know that they're taking your lessons. I can infer their skill level and that they can afford to pay for private lessons. Was that an instance of you selling your customer's data?
Can anyone clarify if there still exists a way for 3rd parties to get data out of Facebook for users that haven't clicked on the 3rd party ad?
I used to work at one of these firms and AFAIK, I worked in sales, Facebook didn't exchange any data with us.
I believe with FBX was implemented using tokens but this changed with custom audiences.
What we could do was match email addresses from our clients, think newsletter list, and get custom audience segment to advertise towards on Facebook.
I seem to recall that we needed at least 1000 emails and we could see how many of them matched a Facebook user.
A possible covert channel of confidentiality breach could be that you feed it 999 bogus emails and one target email to find out if a particular email matched a Facebook user.
But then I don't think you would've been able to target ads to that small of an audience.
If there is a possibility to get data, my guess is that it would be through inference using this kind of covert channel.
Except that I'm not sure I do, now that computers are involved and can pick up every scrap of maybe-data and correlate sets of maybes into probable identities. Twenty years ago walking into a shop with a voucher wasn't an identifying action, now it may be. Twenty years ago what the shop owner got from the voucher distributor wasn't a list of names, now it may be.
If the shop owner gets a list of names at the end of the day, then arguably that list is what Facebook sold. Maybe Facebook sold it with plausible deniability, maybe Facebook would prefer not to sell it, but the shop owner paid money and got something in return.
In the case of tech, most people have no idea how to even articulate what crossing those lines would mean in terms of the data they give up. If someone has a medical procedure, most of us assume that sharing that information is a line that shouldn't be crossed. We have laws that even prevent directly sharing the directly acquired information, and those laws make sense to people.
But when you say that the same information can be obtained in other, more roundabout ways, it's hard for them to conceptualize the risk. Companies can't back down because they have no compelling reason to argue against making that next dollar other than "it feels immoral."
That's why we need strong regulations. Strong regulations actually protect the honorable businesses by giving compelling reasons to not cross those lines.
Google literally does this with adsense. It is definitely possible.
This is quite a spin! The leakage is unavoidable because it is an essential part of the sale.
>Was that an instance of you selling your customer's data?
Yes. The reason you distribute targeted vouchers is to use the data to help identify qualifying customers.
This seems equivalent to arguing that poachers don't actually "kill" elephants, it's just an unintended side effect of shooting them and ripping their tusks out.
So, if leaking data isn't their primary intent, it's cool if it happens — even if Facebook knows there's a causal relationship between their advertising model and data leakage? Why should a company not be liable for known externalities of their business?
The key difference is that, while a website may know from your ad click that you were targeted by a campaign looking for college-aged men or whatever, it doesn't necessarily know who you are. That's the difference between personally identifiable information and simply targeted information.
There needs to be safeguards to avoid abuse. For example, if the targeting dimensions of an ad campaign are so narrow that the few people fall into it, it shouldn't be targeted (a good example would be geographic targeting of devices that are inside of your house -- too granular).
But, I don't care if a website knows that I am likely male or my coarse age or whatever, because i don't have to tell the website who I am in the real world if I don't want to. "Selling your data" is commonly understood by the public to mean something like this -- people suspect that facebook just gives lists of their users to third parties and asks them who they want to send ads to, which is the accusation that Facebook is denying.
If I end up making a purchase w/ a website, then sure, they'll know some things about me from the FB ad click referral and the underlying ad campaign they ran. I feel fine with that, I'm entering a relationship with the business where they know quite a bit about me anyway -- like my name, my address, what I'm buying, etc. I don't buy things from places if I can't trust them.
But they see some usefulness too and/or don't want to be out of the loop, so they're not ready to totally walk away. So they remain in a situation they don't like, and there's been a lot of simmering frustration.
Then this data collection thing came along, and it became a way of venting some of that frustration. So it became a myth that a lot of people believe in. A myth because, while Facebook definitely isn't perfect, people believe it is doing certain bad things it really isn't.
To me this suggests that, like a couple who has a big argument over some trivial non-issue, there is probably some other real issue that needs to be sorted out.
Just because a person ends up on an advertiser's site after clicking on an add targeted to [whatever] doesn't mean the advertiser has the data. It doesn't know the identity of the person that clicked on the ad.
&woman=1&age=24&location=Seattle&sexor=bi&interested=[cars,skiing,succulents]&relstatus=single&...Still, "Facebook tells you which ad someone clicked on, and that can give you some demographic information, and if you can at some later point determine that person's identity you can connect the two" is a very different thing from "Facebook sells your data."
But it doesn't tell you who this information is about. You'd have to trick the user to reveal their identity on the attacker website.
I guess this could happen if the victim had previously visited the attacker website and identified themselves using say their email. Store a cookie of this user. Then when the click the information leaking ad they identify themselves on the attacking website with this cookie. Now you can link the information leaking targeting with the user and potentially leak data.
It's misleading to say that Facebook is selling data to advertisers. Rather they might leak personal data through covert channels.
See https://panopticlick.eff.org/ for one conceptual demo.
As an innocuous example, have you ever noticed that Maps seems to show the right neighborhood when you connect a non-GPS laptop to a friend's wifi?
Isn't that just matching the IP to the correct town? Using a database like maxmind's.
Retailers buy and sell customer data as part of "data cleanup" efforts, that data can be correlated with geo-IP and third-party cookies, etc.
The NYTimes does admittedly worst than Facebook on that front (the key aspects for me: I can’t see the targeting for their ads before clicking on it, refuse some ads on their website, I can’t access, edit or delete what their partners know about me; I can do all that on Facebook). That makes the claims of that editor seem very disingenuous.
Should we judge him based on that? Or is he a user of NYTimes and a victim of their disputable privacy practice, like he is a user of Facebook and an avowed victim of the Mark & Boz’s decisions?
It boils down to: if you own an algorithm f: H->R^n and show m number of (k, v) pairings such that f(k) = v, does it follow that you have revealed all or part of the algorithm? (Where user data is folded into f.)
This would necessarily have to do with how big m is and whether it is enough to infer a f with reasonable accuracy. Not sure what are good metrics for "reasonable accuracy" though.
>Please disable your ad blocker
>
>Advertising helps fund Times journalism.
No I don't think so - uBlock Origin all the way.Internet advertising fuels the Facebook problem.
The smaller we can make internet advertising, the smaller the Facebook problem becomes.
IMO the NY Times simply isn't good enough or original enough to be worth paying for though, so I choose not to subscribe to it.
Also, I'm not very interested in being informed about the endless news cycle of daily events. It distracts focus and in the long run is mainly noise. Its main purpose seems to be to create jobs in the media for the oversupply of liberal arts graduates.
In fairness, maybe that's because journalism isn't cheap?
I don't know? I'd need data from inside of NYTimes, or AFP, or Al Jazeera, or whatever to know for sure. But I suspect stuff like that costs a great deal of money. Subscriptions that would fully fund something like NYTimes, or WSJ, or Le Monde, or what have you would likely be unaffordable for the majority of information consumers. (Again, that's just my guess. I don't know?)