Facebook is embedding tracking data inside the photos you download
twitter.com
twitter.com
So maybe people who agree to do such things are a result of a (long) selection process.
[1]: https://www.theguardian.com/technology/2019/may/17/facebook-...
And there are many well-paid positions in hi-tech not involving working in surveillance part of Facebook or in Facebook at all.
> how do you approach that morally? I really want to know the opinion of someone actually working there.
> See what gross inconsistency is tolerated. I have heard some of my townsmen say, “I should like to have them order me out to help put down an insurrection of the slaves, or to march to Mexico;—see if I would go”; and yet these very men have each, directly by their allegiance, and so indirectly, at least, by their money, furnished a substitute. The soldier is applauded who refuses to serve in an unjust war by those who do not refuse to sustain the unjust government which makes the war; is applauded by those whose own act and authority he disregards and sets at naught; as if the state were penitent to that degree that it differed one to scourge it while it sinned, but not to that degree that it left off sinning for a moment. Thus, under the name of Order and Civil Government, we are all made at last to pay homage to and support our own meanness. After the first blush of sin comes its indifference; and from immoral it becomes, as it were, unmoral, and not quite unnecessary to that life which we have made.
-- Henry David Thoreau
Employers can’t (yet) do the same. I’m under no obligation to them to do what I morally disagree with because I can always quit playing their game.
All I can do to quit my country is uproot from everything I’ve ever known, including my family, to another country that I agree with more that will also let me in.
They’re completely different situations and I’m pretty sure we all recognize that, but I’ll add my own personal anecdotes:
Employer
I don’t like the idea of software patents or generic business patents that can be summed up with “... do it on a computer”. I created some really awesome things for an employer many moons ago that were essentially revolutionizing how people in this very particular niche could more efficiently do their jobs. What did I really do though? I put together some open source tools completely foreign to this niche, glued them together with some nifty ideas and code that I wrote, put a decent unified UI on it, and packaged it up as a virtual machine appliance for our people in the field. My company wanted me to sign the invention away so they could patent it, and were going to put in 5 different applications. It was sign on the dotted line or walk, I walked at significant financial penalty.
Government
My dad’s from Libya. I lived there for a while growing up, and all my dad’s family is still in Tripoli. They all hated Gadaffi, and with the Arab spring uprising- things were getting bad. I joined in some protests across the US asking for intervention. Welp, we got what we asked for but not what we wanted. Turns out governments and geopolitics are tricky.
>What makes you think this was designed as tracking system rather than anti-abuse feature?
Which goes to the crux of the problem: the way "online abuse" is defined presently, it enables platforms to introduce virtually any measures in the name of preventing abuse[1], and people gobble that up, heck, even cheer for it. "Think of the children" got an internet-era make-over, and it seems to be working.
--
[1] off of the top of my head: requiring real names & verifying them via governmental ID; automatic take-downs upon automated requests from 3rd party; automated limiting of posts' reach based on language analysis; requiring posting under your own login; pervasive tracking that jeopardizes people under repressive governmetns.
There's speculation that FB could infer relationships with this. If you've ever shared memes, you'll know this this is unlikely to be effective.
At the end of the day, in an age of reverse image search and public profiles and commodity facial recognition, what is actually the threat model here? That someone is able to tie an unattributed photo back to the URL it was downloaded from? That if someone downloads your photo without permission (why did you upload it in the first place?) and they share it but don't say where they got it, someone else can potentially find out where it came from?
It's unclear whether this ID even uniquely identifies the uploader or downloader publicly. If it's a random UUID, then what? Facebook doesn't reasonably need it to track you (they could use the hash, face recognition, your session, etc). I honestly can't think of a case that would make this valuable to a malicious third party. Beyond content moderation (and maybe saving some CPU time), I can't see much of a use case for Facebook either.
Also, statistics how many images are downloaded and then later found online again by Facebook at other places.
https://www.sno.phy.queensu.ca/~phil/exiftool/
Looks like Facebook is adding IPTC field Original Transmission Reference, which you can view with:
exiftool -IPTC:OriginalTransmissionReference image.jpg
It seems different for each picture.
exiftool -IPTC:SpecialInstructions
(it will be a string starting with FBMD.)And while it’s obviously (can be used for) for tracking, it’s just a exif tag, “Special instructions” is a text for humans, not machine instructions.
So s/Structural abnormality IPTC special instruction/a standard exif tag/ for less click-bait.
Does anyone know existing, working solutions for this? Is IPTC purged as well by CMS systems, similarly to XMP or EXIF?
It's also not clear what the data contains. Is it info about the original account? The account downloading the picture
I would not be surprised if this was being used to prevent fake accounts being created with pictures taken from legitimate accounts.
Examples: Image to be used one time only, non-exclusive in English-language-edition magazine as inside image, no larger than a full page in color. Additional third-party rights to be negotiated with Julie Doe / XYZ Agency in advance. All rights not specifically granted are reserved. See delivery memo for specific license.
For consideration only; no reproduction in any form without prior, written permission."
quote from https://www.photometadata.org/META-Resources-Field-Guide-to-...
https://mobile.twitter.com/17haval/status/114997853789964288...
I ask what is the legal situation for a copyright holder, given users likely are not aware of this data being added to a file; what the data exactly is, where or if this data is kept by them independently of the file itself, what is it used for, GDPR implications, etc.
So if the images is converted to digital form, then compressed then decompressed, then printed out then usually it would be considered the same image.
What does this mean here?
This is akin to asking who gives Facebook the permission to badly compress pictures? The answer's same.
If all of us pushed our behavior to the legal limit, society would likely fall apart. Orderly society only happens because the vast majority of people respect the rights of others.
How is it any more powerful in that regard than just hashing the photo?
I made a LaTeX equation rendering script that embedded the source LaTeX in EXIF data, the idea being that you could edit the equation after the fact without having to save the source. But practically every tool I used would strip the EXIF data - so I moved to storing the source in the least significant few bits of the pixel values. This worked much better with the places I was uploading the images to (google docs mostly). Obviously fragile to image format conversion though.
For anyone interested, storing information/messages inside another file is called steganography (https://en.wikipedia.org/wiki/Steganography)
(If you've found a robust, patent-unencumbered phash, please share, I'd love to use it for PhotoStructure!)
From the twitter thread, whatsapp isn't currently doing it though. But this can be used to find the origin of images.
https://thenextweb.com/security/2019/06/18/india-is-still-ho...
You can say it is not a slippery slope but our rights are eroded when we compromise.
If you need tracking you put the dots on your own print outs. There is no need to have dots on everyone else’s print outs.
I can't see how you can adopt a stance, which places accountability above blanket surveillance by condoning behaviour, which makes an assumption that a crime has been committed by default.
https://www.eff.org/deeplinks/2017/06/printer-tracking-dots-...
https://www.eff.org/pages/list-printers-which-do-or-do-not-d...
These practices are going to take an even more twisted turn with deep-nudes/fakes, GPT2 etc. and related trends. If we are to learn from our experiences, it is now important to fight and push back, rather than just roll-over and pretend to be dead or to accept current practices and seek a (non-existent) compromise, as you suggest.
If it was just for recognizing re-uploads, they could have just stored the sha-256 hash serverside..
Edit: I just saw it's not a normal EXIF tag, this is something else. I'm not sure how this is handled, might be interesting to do some empirical testing!
My facebook usuage has gone from every second to maybe once a day. There is a rot happening and this will become a dangerous time for anyone who used facebook as facebook will slowly sell them out and in the end exort them. Want to keep these photos private you uploaded 10 years ago and deleted? Pay..
I had this problem when I was trying to use the meta data to get the orientation.
If you attach the file, it won't. If you drag the image into the body of the email, it will.
https://stackoverflow.com/questions/31120222/iptc-metadata-a...
It is not in a comment field, nor it reuses any EXIF guid equivalent
A much more grievous thing they may be doing is speculated to be them encoding tracking into photo's hue channel.
There was time when you was able to see a stripe of odd pixels in the right bottom side of some photos.
Later, I read a blog post saying that if you upload a solid grey picture, you will see weird subtle colour banding patterns on it if you download it back.
I tried myself now, and it did not work for me.
EDIT: with passive updates.
I recently created myself a Pixelfed (a federated instagram, basically) and was pleasantly surprised how my profile has a plain, old RSS feed, so that anyone can "track" me without ever visiting a website (which is something that ActivityPub itself also allows, but AP still forces you to be a part of the "system", so to say).
I'd much prefer that kind of Federated world, but I don't see how we can get there in any other way than spreading awareness about it and basically nagging our friends (at the risk of isolating ourselves) – “I wish I could follow your adventures and thoughts, but I don't want a facebook account”. This of course requires a critical mass for basically each person, and probably a way of automatically updating the locked-in platforms (for each post you push to pixelfed/blog it updates your instagram/facebook) so that the ones who take a step out don't need to leave their locked-in friends behind.
Of all the people who listen to podcasts through some kind of an app, how many of them have created an account anywhere?
On a serious note, all the tools from before Facebook existed still work. If you need Facebook/Twitter alternative consider Mastodon or Diaspora.
I don’t know how it will end, but I’m confident that I’ll keep in touch with the friends that are actually important. Not staying in semi-touch with people I don’t feel the urge to call, send a mail, or invite/travel to is something I look forward to :)
Forbid stalking, dark patterns, lies (aka fraud) and their overall lack of morals & ethics. Facebook will be welcome to adapt and behave like a well-meaning member of society.
There motto could have been to SERVE THE USER. Instead it became FOCUS on the user. They focus their product towards three dark patterns: extracting data from the user, manipulating the user, and addicting the user. For now it is towards the benefit of advertisers which is Relatively harmless in the future scheme of things.
A more benign use could have been connecting users across the world to each other and to other companies for healthy conversations. To be what FRIENDS were meant to always be.
Where did I go wrong? I lost a friend.
So essentially forbid everything that makes them the most amount of revenue from advertising? I don't see that likely to happen.
The problem with Facebook is not exclusive to Facebook Inc. It's a common symptom of advertising-based and similarly nefarious business models used by the richest modern corporations. Investors want their ROIs and optimizing for advertising delivers that easily when the business handles extraordinary amounts of personal information.
There are many ways of breaking out of this corrupt model. Creating new business models not dependent on advertising is a no-brainer, but so is creating tools that enable people to keep control over the data they share online. There's a lot of emphasis on distribution and cryptocurrencies recently, which is great, but we have a long ways to go to make the importance of these systems understandable by the general public, while also making them approachable and easy to use.
Make this about the people. Nobody likes being stalked, tricked nor lied to. Regulation against these behaviours would be welcomed by most people.
This is what I was talking about. I consider surveillance and tracking of any kind a dark pattern, though.
And the current legal debate and regulations about it are long overdue.
The world where regulations can prevent that would be so creepy dystopian, that it wouldn't even need humans anymore.
Is it dystopian to regulate that sites cannot host and distribute pedophile content for instance ? Regulations are needed, in the internet as much as anywhere else.
Yes, this is exactly dystopian.
You don't need to look to the future. We already have p2p solutions and encryption that if hacked together could serve as some sort of decentralised storage. The public doesn't use it.
Had. Torrent is mostly banned at ISP level.
> The public doesn't use it.
They will if there is no alternative. The public uses email because there was no WhatsApp in 1989.
The public doesn't use it because it hasn't been hacked together and that for all intents and purpose the experience has more friction than what is available today.
One of the first things we teach people is, that once a picture is on the net, it will never be deleted.
And, secondly, nowadays the web is a lot more crowded, all the less technically minded people go online with a very sparse understanding of the web. Early adopters had a different demographic than the current userbase.
The less tech minded usually do what the more tech minded tell them. The problem is we 've lulled people with "security", green lock icons. We all know that all security is temporary, but we also chose to appeal to people's natural need for safety. The point is even the best digital security measure is nowhere near good old physical security.
So, the school photographer comes. It's the usual think where they make pictures, and you can order some copies. This year they only made class photos. They send you some link where you can log in to see a watermarked version of the photo, you can then order a digital copy or a printed copy.
However, they also put a Facebook share link on the page where people can share the class photo with one click. I am sure there are a lot of parents who do not even think about the rights and wishes of other parents and just share the photo.
So, we are in a bad situation where we explicitly disallow people to upload photos of our daughter, but not can people upload pictures anyway against our wishes, companies are actively pushing people to do so.
All the tracking and unwanted uploads of personal information (though friends' address books), photos, etc. without any explicit permission is a disgrace. I hope that the EU keeps hitting these companies with the GDPR until they respect people's privacy. Sure, if you decide to share your life with Google, Facebook, and a countless tracking companies, that's up to you. But this unwanted slurping of every bit of information has to end.
It's not the internet, it's social media. I believe in time history will show it was one of the worst advances of mankind.
And that is not even enough given the fact that Facebook owns WhatsApp and Instagram, their presence grows ever more ominous given their ubiquity.
> ...Facebook. Stop using it.
Easier said than done, I guess.
Btw, yes it is easy. I have stopped using FB for so long that in order to log back in to delete my account they are asking me to be verified via "friends" (people I haven't worked with or talked to for years).