Who is Facebook's mysterious “Lan Tim 2”?
shkspr.mobi
shkspr.mobi
When there are $billions$ of dollars at stake for this type of information, you can guarantee there will be many companies attacking this problem.
Therefore, not to be a pessimist, but if you think that 1) using a fake cell number on Facebook is going to help or that 2) there aren't services like Google doing this already, potentially with just as good match rates as Facebook, or 3) that using Firefox + adblock is all you need, then you're going to be constantly plugging holes in a leaking boat.
If they’re deducted $0.15 from income, paid to you, on spot each time they query that information, or if it adds 0.015% to probability of their stock crashing in that quarter quantifiably, then I’d expect it’ll be gone forever before any of their C-class stands up for some coffee next time. The reality is roughly reverse of that.
What I am describing is a destructive change to revenue streams for ad companies. That is as nonsense as reversing direction of couple major rivers and I know obvious open question will be how in the world.
My mobile phone company has no idea who I am. It was trivially easy to purchase an iphone, at the Apple store, with cash and then purchase a Verizon MVNO SIM from US Mobile (which I prefer over StraightTalk because they allow tethering).
Neither Apple nor my MVNO nor Verizon knows who I am.
I, personally, am not a customer of any mobile provider.
Certainly my mobile provider could find out if they dug deeply enough - specifically, they could (somehow) check the Visa card I use for payment and see the corporation that that Visa card was issued to and then look up the corporate records and then ... they would know that somebody at X Corp is their customer. Possibly me.
Remember: neither Visa nor Mastercard verifies purchaser name. Only AMEX does this. You can purchase online with your personal or corp Visa/MC and put in "Mickey Mouse" as the name - it will always work unless they are a very, very rare merchant (usually European) that has put the "Verified by Visa" component into their workflow.
1. sample the HSS (HLR in old-money) every night to find which phones are camping in which location areas (LAC)s;
2. this given them a phone → area location for every phone in the country, where area is about 200 cells (a few km²);
3. then they could draw out the call detail_record (CDR) of very outgoing call, SMS, and even data session to get the cell identity;
4. this gets the phone → area mapping down to a few hundred m²;
5. then if they are motivated, they will use the location services in the Mobile Application Part (MAP) to silently move every unknown phone into dedicated mode and repeatedly determine its location to within 10m - 50m;
6. if the phone has control plane, GPS, they just ask it that. Many, many phones do;
7. this information is collected all the time and passed to in-house and 'external' GIS teams to cross-reference against all sorts of wonderful data;
8. they know who you are.
The good news is they don't care. They just want you to spend more. ARPU is everything.
Source: I built this stuff for a living.
My threat model is "telco or ISP employee decides to see if John is a customer and, if so, just what John does with his phone". They will not find me in their customer database and they'd have to dig fairly deeply, and possibly involve banks and/or LEAs which are not my threat model.
Also, just as a coincidence, and not by design, my place of residence has zero bars of mobile service ... I lose it about two miles from where I live ...
I'm sure that you've done better.
Also, I wouldn't be surprised if in the near future, KYC is required to buy any SIM that connects to the network. It isn't here yet but is coming.
Correct, but to clarify - they know your SIM cards location. In my case this correlates to a corp name and no actual personal name (mine or otherwise).
"Also, I wouldn't be surprised if in the near future, KYC is required to buy any SIM that connects to the network."
I suspect you are correct and I think this is already de facto practice for a consumer purchasing mobile phone service in the United States. I suspect, however, that an EIN and a corp name will continue to allow SIM provisioning without associated PII.
Something to consider: we are promised many, many more 5G SIM cards on the network than there are people on the planet. Most of those SIMs will be provisioned by corporate entities and, therefore, the ability to procure and deploy SIMs with no PII will persist ...
Remember, this isn't even new for many countries.
You may be able to do this in the US for the time being. However, in many countries already – a list that is steadily increasing – you cannot purchase a SIM card without showing ID, a copy of which is made and forwarded to state authorities. In other countries – I know of at least Chile – you may have to register the IMEI of the phone as well.
Are you paying with a pre-paid card? If not, your number is tied to your card which is tied to your identity.
Please correct me if I am wrong.
You can hide content, except where the sender is mirroring it. You can hide your DNS lookup by using a DNS aggregator (are you?), unless you are using 1.1.1.1 or something, where the business model is harvesting. But unless you route everything through a foreign VPN, the phone company knows what site you asked for a connection to.
And who owns that VPN, and what is their real business model? The bigger they are, the more their customer list is worth.
Unavoidably if you aren't using Tor the network can see the IP address, which would pin down that this is say, Facebook or Wikimedia, or Porn Hub. On its own you can't be sure this is Wiktionary not Wikipedia, or which type of porn.
In almost all cases the HTTPS traffic uses SNI (Server Name Indication) which deliberately carries the name of the server (the news.ycombinator.com in the URL you're looking at right now) in plain text. This enables Virtual Hosting - otherwise how would a bulk hosting company give you the certificate for bumsex.tinyblog.example rather than cats-in-boxes.example which are run by entirely different customers but hosted on the same cheap Apache server in a rack in Ohio? So that's enough to know it's the English language Wikipedia not Wiktionary or whatever.
But yes, it's only the site and so they won't know (at least just from this) if you looked up Bowel Cancer or Elizabeth Warren; if you are watching a Youtube video about Minecraft or Venezuela; and so on.
Medium term the plan is to deploy two technologies that mean the site's name isn't available, improving privacy. DPRIVE (encrypted DNS, often via DNS over HTTPS) and eSNI (Encrypted Server Name Indication) but while DPRIVE is complete and being rolled out (controversially as you may have seen right here on HN) eSNI isn't finished and is tricky to get right, it may be some years before you get much benefit. We need both for (hopefully) obvious reasons although DPRIVE already makes a lot of cheap censorship options impossible, and making censorship expensive makes it de facto unpopular in democratic countries where voters don't want to pay lots of money for something that seems mostly to inconvenience them. See also: popularity of the American TSA.
Even after all that work is done though, if the mere IP address you're connecting to is enough to be a problem you must use Tor today, and then, and likely forever.
Interestingly the Network described in Stephenson's "The Diamond Age" actually works exactly like Tor all the time, with (apparently) no way to directly send things to an address whatsoever. But this will always be more expensive to do with technologies we know about today, and so it is unlikely that we're destined to replace the Internet with a network that always behaves like Tor.
True, but the ad industry isn't like a boat. They don't want to track everything or build a complete profile about everyone. They just want to track most things and build a fairly complete profile about most people.
That means every privacy step you make has some incremental gains. Just because a private detective could use the collected data to build a complete profile of you, doesn't mean the ad company will - they'll collect data from the easiest sources, and if you make it too hard for them to get data about you, they'll simply collect data about other people.
Citation needed
Marketing to you doesn’t make them money. Marketing to many, many people roughly like you makes them money.
You yourself are only a tiny and statistically irrelevant piece.
Perhaps, but they engage in so much effort to spy on me and defeat my protection against them that this distinction doesn't actually matter.
It's also important to understand that these data aren't just used for shotgun marketing campaigns, they're also used in highly targeted applications. For example, if you give a company a small amount of information about yourself, for example through a insurance or financial services "estimate" page, that company has very good reasons for wanting as much (and as accurate) data about you as possible. The two biggest reasons are:
1. If they're smart, they're running models to associate those and other things with purchasing behavior. Notwithstanding the fact that they need to stay on top of the model's accuracy, having information about you that is too incomplete or too inaccurate can really fuck up their shit.
2. In domains where customers are extremely profitable (again, e.g. insurance and financial services), it can likewise be extremely expensive to acquire the data needed for robust modeling, even dirty data.
In both of these cases, they do very much care "about having data about 'you' in particular".
The bigger agencies are building their own databases, but they haven't been able to link ad spend and customer purchases effectively, so that's the main focus at present. In particular they need to know ROI to effectively budget ad spend. Obviously, they have estimates of these numbers, but not an accurate per-ad-buy prediction. Google/Facebook are full of clickbots and there seems to be minimal incentive on their part to remove the bots. They've made some efforts with pay-per-conversion but it seems like marketing theater rather than a business model shift.
So until the fraud problem is solved, I don't think they care about microtargeting too much, except for its anti-fraud properties (attractive ad profiles are hard to fake).
I strongly disagree, and with all respect, this is a naive view.
This might be true when you're looking at the mapping of individual company to individual person (ex: "You to Facebook" or "You to Google.") But the ecosystem approach to building a profile on you is more comprehensive than you think.
Example: you might get very very good at removing your phone and TV/Movie interests from Facebook, or never having it on there to begin with. But then Media Conglomerate X owns a cell/wireless provider, internet provider, and hell maybe even a cable company. There's a high probability that you pay for >= 1 service from this company, that can be matched back to your Google profile and/or Facebook profile - via a DMP (data management platform) or something similar.
Oh and remember when you used your real phone number to make a reservation at a restaurant? AND they needed a credit card on file, just in case you don't show up? Well those are uploaded and grouped in the same data pools.
And then when enough stores / restaurants / ecommerce sites pool this information, they can build a pretty reasonable shopping profile for you, make (very good) estimates on your demographics, etc. Almost like it's crowd-sourced!
Therefore the "you" that is supposedly a "small, statistically irrelevant piece" is actually part of a group that has an ecosystem of companies and DMPs pooling data to make that group smaller and smaller.
So what in your opinion can people do, that are reasonable, actionable steps to take, to avoid being an unwilling part of this ecosystem?
Even if you Adblock and never give away personal info, like op said, your cable, bank, insurance, dmv, internet, and phone provider will still collect and sell your data.
Yes you can make their ad targetting somewhat less accurate in some circumstances.
Which is why we need really tough legislation to put a stop to this abuse. The GDPR and CCPA are good starts, but both of those are much too weak. Here's hoping that such legislation will get better, and more pervasive, over time.
I guess it is a mixed blessing.
Missing something like “exclude recent purchasers” was easy to forget, but easier to not even have time to set up. (It might take 10-30 minutes to set that up)
Knowing you browsed a product is as simple as firing a tracking image on the product page from the adtech platform. Knowing you actually bought it means having a connection from the ecommerce system back to your email then back to the id that used used in the adtech and then setup as an exclusion filter in all of the campaigns.
It's also usually not worth it since conversions are low and ads are cheap so better to keep advertising and get net new sales then worry about the people who already bought seeing the same ad.
I also do things like look up something on Google for someone else, then see ads about it for months. While I understand the simple way of this technology works, they might want to rethink the idea that I need to see ads endlessly for everything I did one search for.
Also, your Smart TV may simply be spying on you and sending that data back to the manufacturer[1] either by sending a hash of portions of your screen, or in Samsung's case, straight-up sending screenshots.
It generally takes years for a big company to completely ingest the data of a company that they acquire, and even then everything is siloed in 20 different ways. People only wish that company X buying company Y meant that the two merged all of their databases synergistically. The world definitely does not work this way
You literally upload any offline data (phone numbers, names, address, whatever you have) and they match it to online profiles. They take the data you give them and use it in their cross-device graph, which is the exact thing you said doesn’t exist. Any business can go license or use that cross device graph in a variety of ways. $RAMP, 2.2B market cap.
Same service is provided by oracle with their cdp and dmp, and a few other companies. If you want to do more research the terms to look for are identity graph, cross device graph, offline matching, and other variants of those. Fb, google, LinkedIn, etc all offer some version of this in their walled garden. In the blog post they talk more about offline conversions, but it’s the same idea.
If I'm wrong, sign up with Liveramp and use my phone number to tell me what restaurants I've booked reservations at in the last month. Is that how it works?
Liveramp is b2b and definitely won't support anything you want to do with them, but there are some comically bad tools (haven't been updated and are purposefully inaccurate) that let you check what data pools you're currently in.
If you're going to be bad, at least don't try to pretend that you're good.
Example: https://digitaladvertisingalliance.org/license-pricon
If that were the specific claim they made, I wouldn't call them lying. But I was talking about Liveramp specifically, and they're making claims well beyond that -- they're claiming that they're actually defenders of privacy. That's a straight-up lie.
I keep a close eye on the adtech/martech world ("know your enemy"), and it's clear that on the whole they've managed to reframe the issue in their own minds in a way that is favorable to them (mostly by doing what Facebook is doing: considering themselves as "pro-privacy" by defending the data they collect against outside attackers and abuse rather than considering their own collection and data use).
I don't think they're lying when they do this, I think they've managed to delude themselves in the way that salespeople often do: by convincing themselves that the lie is actually true. It's not lying, after all, if you believe it.
But Liveramp has elevated this to a level that I believe is intentionally deceptive.
If FB thinks you're a 72 yr old retired dentist from OK, and you buy nothing but feminine hygiene products and 3 wheel wheel barrels, you're pretty worthless as a consumer.
The future of ad block is disinformation. Makes the entire ecosystem worthless
I suspect it's much harder to do this successfully in real life than it is in a novel where it's just an excuse as to why otherwise resourceful intelligence agencies don't know who the central character Rabbit is (Vinge says he's not sure either, to me it seems obvious Rabbit is an AI, surely the whole point of all Vinge novels is that there's a Singularitarian Apocalypse, and in Rainbows End the humans think they've averted that apocalypse but actually the thing that just saved them is the Apocalypse and they ought to be terrified)
It's on in the Firefox extensions site:
https://addons.mozilla.org/en-US/firefox/addon/adnauseam/
But not on the Google Chrome site:
https://www.theregister.co.uk/2017/01/05/adnauseam_expelled_...
Crikey. Just downloaded all the data and having a browse. 22k line location file (about 3k locations) stored too. I don't have the app installed on any device i own. I presumed the mobile page wouldn't have permission. Checking the data it does seem to stop when I changed phone (samsung preinstall fb app)
$ date -d @1495296127
Sat 20 May 17:02:07 BST 2017
$ date -d @1573424412
Sun 10 Nov 22:20:12 GMT 2019
What are they doing with ancient location data?Also have every deliveroo purchase I've made in there they have an entry for every deliveroo purchase i've made
{
"name": "Deliveroo",
"events": [
{
"id": 4538632xxxx,
"type": "SUBMIT_APPLICATION",
"timestamp": 1583216215
},
{
"id": 33897312xxxx,
"type": "PURCHASE",
"timestamp": 1583146135
},
{
"id": 3389731270xxxxxx,
"type": "PURCHASE",
"timestamp": 1582371142
},And no, GDPR will not stop them. The privacy guys here in Europe only go after small businesses, sadly.
The only thing I did was logging in to Facebook via the browser on my phone.
Wait... I logged in to Tinder with Facebook on my phone. That how the Facebook SDK probably found out.
Basically these Apps are betraying me and sending Data to Facebook without my consent.
> ratm.com
perhaps not quite living up to their name there...
Do I read this correctly that a restaurant will just dump its complete visitor log to FB and then let FB "sort it out".
Meaning that FB gets to vacuum the info on everyone including those without FB accounts?
businesses want to see if their ads are working. by uploading their visitor records, they can get reports of how many people who saw their ads visited the restaurant.
What does this mean?
You go into a bar, you order the IPA you liked someplace else, you see they've got a heap of cans... the bartender reaches under the bar and hands you... an open can.
No right? You don't want that one. Why the hell is it open?
OpenTable sounds like it would be open-source, but it appears that it isn't
I think the parent comment to yours made a sarcastic take using a variation of the popular ambiguity Free as in Beer [1] that usually differentiates between free as 0 cost and free as freedom as a reaction to the OpenTable software being free to use rather than open-source
Really what is happening here is that companies that advertise on Facebook push conversions to Facebook to “close the loop”.
Unless a company is advertising a service on Facebook, there is nothing to push to them for this purpose. Are there Yelp and OpenTable ads on Facebook targeting users booking reservations? Have you pulled your results and see those?
"It's just offline conversion events being uploaded so you'd stop getting these ads, or so they can market to you again in the future. You purchased this product, gave them a phone number.. Not sure where the issue lies? You agreed to the terms on Spreadshirt which is probably where you opted for marketing."
This is the basic approach. You give it to us. You agree to whatever we put in legalese and now we can do whatever we want. What?
It is disheartening, but I agree with the rest of the posts on HN that it is not at all surprising.
I just don't know how to approach it.
For VISA to sell transaction data, that's one thing. But a business that uses it to run their marketing, using transactions with their business? That seems less clear.
To further muddy the waters, if I can tell the business how they can use transaction data, shouldn't they also be able to tell me how I can/cannot use it? That seems like it would infringe upon bad reviews/etc., but it feels more consistent.
In my case, it always seems to be some sort of invisible line that I can't quite articulate. For lack of a better term, it feels like transgression. For example, I give the business my credit card information, but I don't give them permission to use that card on anything other than that one transaction ( or more if recurring ). If I give them my phone, it is for the express purpose of handling my business. That phone is not there to be sold to the highest bidder.
For the record, I am agreeing with you. The waters are definitely muddy, but we need some sort of enforceable and enforced ground rules.
And I am saying all this, because there is a reason for business to gather this information. I am willing to entertain an argument for keeping some of that data for efficient processing of my business. I am less charitable with hoarding data for no other reason than selling me more stuff and or outright selling that information to 3rd party to that in some other way.
So yeah. Neither. But there is a line. I just don't know where it should be.
It's about informed consent. The businesses should at least warn their customers that they're doing this, and who they're ratting us out to. That way we can each make an informed decision about whether or not to use that business.
If I know a business I’m thinking of purchasing with is going to send my purchase info to Facebook, I’m picking a different business.
It would be a kind of General Data Protection Regulation. All joking aside, and as much as I've grumbled about implementing it at the company where I work, I really wish this was a thing world wide.
Because we have yet to tell them they can't do whatever they want with it. That's the purpose of regulating it.
> I have never used FaceBook [sic] login for anything
> Facebook doesn't even have my phone number, only my name and my business email address.
People, if any company has A-N-Y-thing that can be associated with you, online or offline, you have no privacy. None. It is gone forever.
There is billions of dollars at stake for companies to build as complete a picture as possible of you and every detail of your life. And billions more remains on the table. That is plenty motivation to fuel a highly-lucrative market for accurate, meaningful profiling for years.
Sure, there's a long list of actions you could take to begin minimizing your exposure, the practicality of each varying widely. But frankly, most of them would only serve to make going about daily life inconvenient. (And the correlation between effectiveness and convenience isn't 1:1...)
The best case scenario is your data becoming stale, such that its values diminishes to a degree that makes it effectively background noise.
There is simply no means of unembedding yourself. But also, more discouragingly, for most people there is no practical means to avoid being ingested.
edit: grammar
Do you mean that purely in the sense of marketing and advertising? i.e. they want to market to me as effectively as possible, so that's why they're going to these great lengths?
Every data point gathered builds towards a more comprehensive knowledge they have on you. It hardly matters if you never log in to a third-party site using credentials from Facebook/Google/etc., that's just icing on the icing on the icing for them. They'll know if you logged in regardless, as long as their widgets or services are in place on a site.
While cookies are certainly the most common means of following you around the internet, there's other means of fingerprinting that, while perhaps not as laser precise, certainly provide more data than most people realize.
Why do you think ISPs are so ardently against people's ability to use them as dumb pipes? And why has the smart TV platform landscape grown like gangbusters (spoiler alert: Roku's CEO has outright said why https://www.theverge.com/2018/7/20/17595384/roku-ceo-anthony...)?
edit: clarifying grammar
I like to think none of it applies to me because I don't consume, but that's another story :)
> I have never used FaceBook [sic] login for anything
That was in response to someone saying you could avoid this by not using Facebook login. Maybe before calling out others' naïveté you should work on your reading comprehension.
I'm actually quite (pleasantly) surprised that Facebook provides this information, and somewhat curious why the author is angry at them rather than "Lan Tim 2".
The problem is, they don't give me any meaningful data other than a code name and an incorrect date. If they'd said "This is from Company X on or around date Y regarding action Z" that would be more transparent, and more useful.
I use Firefox to avoid being tracked by Facebook, and never login with Facebook. But it looks like I slipped up in signing up for email receipts!
Even if I didn't have a Facebook account, Facebook would still be building a profile on me using my email address /phone number in anticipation of the day I made an account.
If you order via kiosk in Taco Bell, you have your receipt ONLY by text message or email. Yep. No print out option.
HOWEVER, if you order via cashier, you CAN print it out.
It's easier for you, and instead of fighting expenses abuse and having a bunch of workers to check the expenses paperwork the business just has an understandable cost when it sends people to do their jobs.
It's fine that OP bought a t-shirt, not fine that that is somehow reported to Facebook.
It would be nice if it were, or that they promised that they wouldn't just hand it out to everyone.
> If it bothers you, though, it does really work to a) periodically reset your IDFA/AdID on your mobile device, and b) delete cookies on your browsers.
How does this help in this case?
True, but that's not the expectation in play here. I think there is a general expectation that when you're doing business in a brick-and-mortar store, that store is not going to be reporting your business to the likes of Facebook, Google, etc.
"Some chat apps (like Viber and others) have Facebook SDK integrated in them, without any direct Facebook functionality people would use. Discovered after using NetgGuard, and seeing who is calling home, and not only home. (Why viber is making requests to graph.facebook.com anyway?)
Duolingo is a nice app for learning new languages, yet it might be using the same sdk, since it likes to call facebook.com domain.
Netflix is a good streaming service, but it has some option somewhere, which allows them to share data with others, and enabled by default. And yes, it's present in fb activity.
The list can go on...
There are developers who integrate dozens of SDKs, without any specific purpose for users, and not knowing what is happening. We need something like PrivacyBadger/ublockorigin for phones/laptops/routers/homes/cars. It's getting more than creepy.
And why would Facebook allow third-parties/businesses upload into FB info they have on their customers...
PS: analysis of how a simple menstrual tracking app is leaking data about the owner https://media.ccc.de/v/36c3-10693-no_body_s_business_but_min... "
For one app I worked on, we made a decision not to include Facebook or Google login and only support email/password login, specifically to avoid leaking information.
A subset of users was not pleased at all -- and they sure let us know about it. Maybe around a third of our support requests were asking for third-party sign-in. People often made privacy arguments in support of it: they'd say "why do I have to give you my email address to create an account?" (though usually much less politely). And they kind of had a point. You may trust yourself more than you trust Facebook, but most people are going to trust Facebook more than they trust [random developer].
Anyway, it takes a lot of effort to deal with these support requests, it sucks getting yelled at (even in text). Some of these users probably went on to give the app a 1-star rating, and just a small percentage of those will really drag down your overall score. Dealing with this was not fun. It would have been much easier to just add FB or Google login.
Sure I can. And I do. Developers are making these choices, after all. I understand the economic drive behind them, but that doesn't get the devs off the hook.
I have seen apps sending requests to facebook graph without using the login, or they don't have facebook login at all..
I haven't rated any apps based on this, though.
Edit: How they matched it up though is a mystery to me, as I use another e-mail address for FB than for the rest of the online world.
Firefox's Container system is a powerful solution to this general problem, but normally you need to do curation work proportional to the effort being taken to track you. Their Facebook Container though comes with that curation done.
If you use Login with Facebook (you want Privacy, but you choose to Login with Facebook? Maybe reconsider your life choices) the Container puts everything you logged into this way inside the Container too, so that dissolves your privacy but you chose to have it happen.
Yet some mobile apps still use heavy analytics which is sent to some domains, again, you need something like netguard, vpns, to filter your mobile traffic. Privacy becomes a pain https://media.ccc.de/v/35c3chaoswest-32-toll-of-personal-pri...
That's just great. So I guess the gift that marketing agencies have given us is that we can't trust anybody. The only thing left to do is go entirely cash-only and never give any personal details to any business whatsoever.
The marketing industry has become so toxic that it is now poisoning everything.
This data can be sold or leaked. And is readily accessible to governments.
You just killed my aunt.
Not using fb can't protect you from fb independently creating shadow profiles with triangulation.
Then use a restaurant details blocker? Celebrities have been doing this since the beginning of time. Use an alias. The notion that physical places of business are collecting our data for their own purpose is not really a new one.
Yes, this is what I was calling out in my original comment. We need to remember to treat physical establishments as attackers.
>"Suppose I go to a restaurant, and I booked using my name and phone number. The restaurant sends that data to Facebook to say "Terence Eden ate at this restaurant on this day." Facebook can then tell if I saw an advert which led me to make a purchase."
An ad blocker and not having FB isn't going to stop a restaurant from participating in this FB program. And if you follow the short URL of the Twitter user the author quotes, it links to a Privacy International report that states:
Facebook routinely tracks users, non-users and logged-out users outside its platform through Facebook Business Tools. App developers share data with Facebook through the Facebook Software Development Kit (SDK)"[1]
So the combination of some random app on someones phone built with FB's SDK and a brick and mortar retail establishment using Facebook Business Tools seems like it is enough to thwart even a fairly ardent privacy advocate. I'm not seeing how an ad blocker would help against the combination of these two things. It's also well known that FB maintains shadow profiles and buys offline data.
[1] https://privacyinternational.org/report/2647/how-apps-androi...
The next step someone would probably say is that other sites you transact on might also be selling your info to FB, but again how is that valuable if they can't know who you are until you either login or enter your payment details? Generally speaking, your profile info is only valuable for advertising (people want to get you to their property to buy things - once you're already there your profile value is a lot lower). If you effectively shut down the advertising funnel entirely what's the issue here. Yes, it's bad from a general privacy standpoint, but what else?
Shadow profiles are valuable to FB as it provides data on the interests of a FB user's real life friends. I don't doubt there's categories along the lines of "has 2 or more friends who regularly frequent wine bars in West London" or something similar.
No, it doesn't. This issue is unrelated to using the web or Facebook.
> Transaction data like restaurant purchases is only useful in this scenario if it’s linkable to other online tracking data on you.
It's also useful if it's linkable to to other offline tracking. But that's beside the point -- the point is that I don't want this data to be sent to these companies without my consent. Whether or not it's actually useful to those companies is a completely separate issue.
Whether or not anyone has this information is totally irrelevant to me, and I'd imagine this is true of upwards of 95% of the population. And hey, if it leads to restaurants bringing in more people, it'll lead to more restaurants I like staying open instead of going under...
No, I haven't. I wasn't commenting on what most people care about. I was commenting on what I, and people who think similarly to me, care about.
There is a reason why EU made the GDPR. Its not like it was a law meant to solve a purely theoretical problem
http://jacek.zlydach.pl/blog/2019-07-31-ads-as-cancer.html Advertising is a cancer on society (last update: 2019-10-02)
Good luck! Lots of brick&mortar stores are going to debit/credit only...
Not bad!
All of the activity I had was from games that I casually installed and then deleted in the past month. These are games that I signed into with Google Play, which displayed advertisements primarily for Facebook.
Speaking of which, some of Facebook's advertisements are absurd.
https://i.redd.it/czyfotsak2l41.jpg
"Start Reacting Today".
They're all owned by the same handful of companies. You gotta get rid of em all.
Moreover my facebook account is just a dummy one which only has the bare minimum of information to own my business page, which I don't even post to (I have dedicated social media people who do that).
Facebook doesn't even have my phone number, only my name and my business email address.
Very creepy.
Lan Tim 2 is likely a contract manufacturer. Spreadshirt outsources the production of their t-shirts to Lan Tim 2. Likely, many companies do this as well. Lan Tim 2 probably does more than just t-shirts.
It's like with most craft beer sold in cans. The individual breweries cannot supply the demand for their product, so they have another company that specializes in mass production do it according to their recipe.
The contract manufacturer is likely the one giving data to FB, not the spreadshirt.
Perhaps they do other whitelabel manufacturing, but I just looked through my emails a week around the date and I don't see anything it could be.
Also keep in mind the only thing tied to my FB account is my work email (and my name I suppose), which I definitely didn't order anything with.
You can say that the systems that you're building are not being used in a dystopic fashion, but in doing so you're ignoring the fact that you're still building scaffolding for the rest of the industry.
(Not looking for any special techniques or trade secrets, just trying to understand where the data comes from and how is it tied to a pseudonymous browser fingerprint so I can make an opinion on whether I think it’s ethical and how can I defend against it.)
I swear I'm not trying to be overly confrontational, but... what you're saying makes me think that you're just a bad guy who uses naive mental gymnastics to rationalize their dystopic contributions to the world. Please prove me wrong. I want to give you the benefit of the doubt, but... you're not making it easy.
Edit: If you're not a moral compass (ie, you haven't put any thought about whether you're actively causing harm in the world), then you should at least try to say that on the onset.
I cannot possibly believe that deleting your fb account removes all the info about you in their identity graph. It would just convert your active profile to a shadow one.
http://theconversation.com/shadow-profiles-facebook-knows-ab...
Also deleting profiles excludes them from tons of data model recalculations since they cannot deliver impressions, it is a waste. Sorry I thought that was clear.
So they still can tie back impressions to your account in the exact same way.
Facebook started off as a very white shade of gray and has slowly turned to the dark side, getting darker and darker shades of gray until the present day, when they are nearly black, gamma channel 1/255.
When an advertising platform has to pay fartsniffers to follow you around to offer marginally better ctr than email spam, maybe just don't run ads?
Work manually on growing networks of users, actually walk up to them and chat, talk in relevant business forums and you won't spend thousands of dollars you don't have casting a net in hopes of finding people who more likely than not just don't want to be associated with your practices.
Then you could also do something on a case by case basis where you can click to say “I don’t want Facebook to have this offline conversion.”
The data from "LAN TIM 2" was sent to Facebook on the 5th of March 2020, yesterday that is.
The only stores I've shopped at lately were ALDI and EDEKA, and yesterday I bought a Webhosting offer directly at the hoster's site, no third party involved.
I have never bought a custom shirt.
What I do have is a Motorola G7 Plus, which is filled with uninstallable background services from Facebook. Two days ago I upgraded it to Android 10 and now all those background services, like "Facebook App Manager" or "Facebook Installer", "Facebook Services", all names which truly frighten me, are activated again. I had deactivated them months ago on Android 9 as soon as I got this phone. I really am wondering about the data this phone is pushing to Facebook without my consent.
I really wonder what caused those two entries, I never give any consent to any company to share my data.
God I hate Facebook, they are the cancer of the internet.
There's no specific reason to believe this isn't the real name of the manufacturer. I tried to find more information about Lan Tim to see if that's likely the case, but I couldn't, but that's not very conclusive.
https://www.facebook.com/off_facebook_activity/future_activi...
But raises a more important question: If you are reading this and don't like it - why do you still have a FB account?
That said, I'm doing a social media fast for Lent. It's entirely possible that when Easter comes I might not go back to either Twitter or Facebook.
Most of my socializing has been and continues to be done in person, over text, or over email. I do miss out on updates from distant family and friends, but the interaction on Facebook was always shallow anyway, so I don't feel like I'm missing much.
"Hey friend, I'm getting off Facebook, What's a Slack workspace you're in? I'll send you messages that way .."
...you delete your facebook and never talk to this friend ever again.
It's not that there aren't alternatives. It's that people don't use them. It's not like back when everyone had AIM, Yahoo and MSN and you could add people on all three and group them together in Audium/Pidgin/Trillian. Facebook has literally bought most of the competitors (Instagram, WhatsApp, etc.)
They do if they value the relationship. I left Facebook almost 10 years ago, and the people on Facebook that I had actual, valuable relationships with had no problem continuing to communicate with me though alternate means.
Google Chromecast shares activity with facebook!
It wouldn't be beyond Facebook to immediately connect that telemetry to your user profile, making these apps show up in your profile.
You are the product in both of these companies, why wouldn't they work together? Ethics, sure, but that won't stop them.
https://about.fb.com/news/2019/09/understanding-updates-to-y...
For example, if you try to login from an unknown computer, you'll get an email asking if it was you - that usually contains a rough location based on IP.
Twilio has no idea who I am. They have a corporate name and a corporate Visa card.
The sharing with Facebook seems presumptively illegal. But I'm guessing the author isn't in Europe.
You might get away with being somewhat vague about who needs it, e.g. maybe you can say "Our delivery contractors need to know your address" and not spell out which companies you've contracted with for delivery. But it's on you, the outfit the user gave their personal information to, to enforce that e.g. "This phone number is for calling our recipient about the delivery, you can't keep it after the delivery is successful and you can't give it to anybody else" through contractual arrangements or whatever other reasonable legal steps.
I am in Europe (though it's England, so eventually no longer subject to EU regulations sadly but it does have a Data Protection law anyway) and I see this "Lan Tim 2" crap in my Facebook as well. If I have bought anything from Spreadshirt it was months (maybe years?) before the supposed "Off-Facebook interaction" listed by Lan Tim 2.
I actually wouldn't be astonished if this comes down to:
* There's an incentive (maybe not by Facebook) to create tremendous numbers of "Interactions".
* It is possible to create fake Interactions by generating garbage, e.g. lists of randomly chosen phone numbers or email addresses and sending them to Facebook.
* So somebody creates accounts maybe initially with real business names "South China Air Freight Inc." and then they get lazy "So Lee" ... "Lan Tim" ... "Lan Tim 2" and they upload random garbage to harvest the incentive.
* This publicity drives Facebook to eliminate the incentive or make it too hard to upload garbage so that the incentive isn't worth it, and the "problem" goes away.
I already use anonymous single-use email addresses for a lot of services (anonaddy.com is good for this), and I think in the future I'm going to just decline to use anything that demands a phone number of me. Far, far too much of it is being sold to third parties as soon as it's obtained by these companies.
https://techcrunch.com/2018/09/27/yes-facebook-is-using-your...
If I'm remembering right, they had two methods they'd switch between:
A. By emphasizing how much more secure it would make my account.
B. By telling me how many of my friends have provided theirs, which is a blatant attempt at manipulation via peer-pressure.
https://www.forbes.com/sites/johnbbrandon/2019/12/19/267-mil...
Either it's a bizdev scam that they're all trying to get in on, or they're clueless. I lean toward the latter but expect it to be the former. Surely they can raise ad rates with the extra PII, I'm guessing?
The bitchy thing is, even an Android app like MX Player or Maps.ME was sending events to Facebook, but FB's JSON just said "custom event"...
Best you can do is withhold information at time of purchase. Use cash, don't give your email, phone number, etc.
Some businesses are clever and dangle a carrot with the request for PII such as emailing you the receipt or texting you status updates. You will have to learn to be "that guy" and politely refuse, or give bogus information.
Also since it is related to Spreadshirt, many Vietnamese are working in t-shirt making MMO, which make it even more suspicious to me.
I just checked my own off-facebook activity and I am blown away at just how much information is available on me. They have a fairly concise list of all the websites that I have visited in the past month, none of which I used facebook for logging in.
I think this may be by correlating the Android advertising ID?
Then, when you use another service, and don't even create an account or log in, and simply provide that service with your phone number (e.g. OpenTable, Deliveroo, AirBnb, others), and then that service provides a complete log of all of their transactions to Facebook with phone numbers and email addresses, now Facebook can associate your purchase history with your name, email address, and phone number provided to them by your contacts. It's called a Shadow Profile.
It has nothing to do with "us[ing] Facebook as your ticket to all the other services". They track you even if you don't have a Facebook account at all, and don't create accounts on other sites, simply through your telephone number or email address. I wouldn't be surprised if they're also storing credit card numbers (or one-way hashes thereof) to cross-link purchases, too.
I mean, what did you think happens when you sign up via facebook?
Signal users have a "profile" which is encrypted, and their device can give the keys to other people. By default it'll give keys to Contacts you message on Signal, and this encrypted profile has more keys and tokens inside it that people can use to send you stuff. So when you send a Signal message to your friend Alice, what Signal sees is that somebody sent this encrypted message, which comes with a token proving Alice authorised somebody to send her a message.
Alice's device decrypts the message, and in doing so it decrypts a MAC which it can then examine to prove that this is a message from zeveb (or Alice has faked a message to herself but like, why?). Signal never learns who you were in this process.
So, if you use Signal to communicate with strangers and they haven't overridden the defaults (you can say you love strangers and don't mind spam, in which case this Sealed Sender technology works for anybody sending you messages) they would if they wanted to be able to figure out this relationship, and then monetize it. They explicitly promise not to, but I guess if you want to you could believe that Signal is the problem and we shouldn't worry about Facebook.
I definitely have a bridge for sale you should enquire about, also that big iron tower in France? I can get you a good deal on the scrap.
Why not? They know which device sent the message (because Signal were sent it) and they know which device received it (because Signal sent it). I know that they have some really clever ways to forget the sender information and still route the messages, but we really don't know that they actually do forget it.
> They explicitly promise not to, but I guess if you want to you could believe that Signal is the problem and we shouldn't worry about Facebook.
I think Facebook is a far greater problem, but I also worry that Signal is a problem too. It's not either/or but both/and.
"Which device" here meaning they have an origin IP address for the traffic? Is that what you think most people mean by "sender" ?
Like, who sent this postcard "A pillar box in Westminster, London" ?
If your quibble was that this isn't technically completely anonymous I'm down with that. But the original claim was that Signal can tie this to a phone number, and "We could tell the IP address of the sending device" isn't that at all.
If you are worried about IP addresses then just as with literally everything else the only effective way to hide your IP is Tor. But then why bring Signal into this?
Strange.
I also have access to an account for a fictitious member of an old web comedy group I was part of. They don't have anything from Lan Tim 2, but Lê Linh did register some "Off-Facebook Activity". Which is impressive for a person who doesn't even exist. Good quality data, obviously, from both Lan Tim 2 and Lê Linh.
I don't get the benefit of GDPR or CCPA since I live in Quebec, Canada rather than the EU or California. But, I wonder if there's a way for me to send a request based on Canadian or Quebec privacy law, since they do have an office and plenty of users here in Quebec? Or have they effectively firewalled that stuff off from whatever entity controls or processes the data?
You can't. It's part of the perversity that is Facebook -- in order to be able to see (and delete-ish) the data they have about you, you need to sign up for an account and give them more data about you.
Other situations where Facebook processes data sent by third parties to show relevant ads for said third party and not use the data to match for other ads is also legal under GDPR, since Facebook only acts as a data processor to act on behalf of said third party.
When ordering from Spreadshirt, you may be ordering from a partner that uses Facebook for Business and their privacy policy apply to you. This is also stated in Spreadshirt's privacy policy.
GDPR is not an umbrella protection for all type of tracking, even though it usually is brought up as such. It only makes sure you have insight in what is getting shared, a way to export, modify and delete said information. In shop/partner situations, you have to contact the partner to request deletion as the shop is not responsible after your approval.
I may be completely wrong, but this is my general understanding.
every single advertising company already sell advertisements by "household" where they clump together all accounts assumed to be from one user and their family/roommates, effectively going back to aggregate IP targeting, but not saying its using IPs because that tarnish things with GDPR et al.
also, even if not using household, they sell by "people targeting" vs the old "device targeting", which again breaks all account separation people here assume.
I strongly suggest people minimally interested in privacy or advertising to create an account with any advertising network, or at the very least look up youtube videos on how marketers create and target campaigns.