Facebook Shadow Profiles [pdf]
cesifo.org
cesifo.org
No, not every app. There are still open source apps who usually do not do this and there are probably also some proprietary ones with ethics who have not given into it. But that this is the default and there is no big outcry is probably because allmost no one outside tech circles understands anything of it, or just throw their hands in the air.
To be pedantic, that was one part of a 225-million-Euro fine. But that practice was specifically broken out as one of the line items, with a dollar amount attached.
And to be more pedantic, the fine wasn't for the practice itself. It was for failing to provide notice to the users whose contact info was harvested. In theory, this practice is acceptable under GDPR if the app immediately informs the user whose contact issue was harvested, and gives them an opportunity to reject.
The 225-million-euro fine is still the second-largest fine issued under GDPR, after Amazon's. The 75-million-euro line item were an individual fine, it would be the fourth-largest after (one of) Google's.
* Friends that I went to graduate school with. Just based on our degrees (MLISes) and career titles, which are pretty public, and the fact that we keep in contact suggests certain types of hobbies we have in common.
* I grew up partially in some pretty rural areas, as did my sister. So which people my sister keeps in contact with from back then and what they're into is a pretty good indication of what she likes. Otherwise, why would they be in her contacts?
Basically, if your contacts have less scrupulous information practices than you regarding hobbies (e.g. your friend tells FB EVERYTHING) and they're in your phone, it's pretty easy with that info to peg you as 'Greg's friend from rock-climbing club who probably goes out with all of them for craft beer afterwards.'
Do you mean any app that has a “login with fb” button?
When I left my previous company, I gave a few coworkers my phone numbers. Within 24 hours they showed up as suggestions on FB.
This has nothing to do with it being a "surprise". That doesn't justify the action, the erosion of privacy. If your car gets broken into in a bad neighborhood, it not being a surprise doesn't justify the break-in.
I have long wondered whether they can match these two kinds of shadow profiles together. One profile with personally identifiable information. The other profile with detailed browsing history. That would raise a huge privacy concern especially since these are non-Facebook users and therefore people who have not opted into this at any level.
On the plus side, pedophiles working at Facebook will have a great time. /s
https://www.invenglobal.com/articles/16506/facebookmeta-exec...
For those who don't already know, it takes very few data points to deanonyimize someone's data.
With greater effort and efficiency you can have even less data points.
On one side it is weird, on the other side it makes sense. For example: Einstein is not an FB user. But if people upload photos and tag him it makes sense after a couple photos FB learns what is Einstein
Calling that "weird" is an understatement, considering what's going on there; Users are asked to identify friends and family for facial recognition, to train an algorithm that FB then monetizes for all kinds of advertisement and surveillance shittery.
The whole thing is imho way past "weird" and firmly in dystopian territory.
When you consider the level of surveillance that exists today with the mobile phone, smart tv's vehicle tracking, cctv, jobs on computers you can tell when someone is running late and you can probably even work out why. Even if you dont have a mobile and live in a rural location, as you walk around our bodies interfere with wifi signals, we block them, so you could use routers like a phased radar array detecting temporary signal weakness and other anomalies, plus any cctv that is installed can be used to pick you up as many might have seen with crime stories or Edward Snowden. I've had PTZ cctv hacked and I know of other companies with PTZ cctv have had their's hacked because they have spotted them moving around inside their office as they were not hidden behind darkened domes.
I dont think people realise just how much surveillance there is today and the US Military have largely driven this at arms length, just like state assets have been ipo'd to keep them at arms length from the state.
However when I have reported stuff to the police, its surprising how MS Windows suddenly doesnt work and makes it impossible to access your screen dumps, thats why you need a basic digital camera with no wifi or bluetooth to capture whats on screen because even cdr/dvdr's along with rw's will get wiped.
I've even had my home accessed and old hard drives used as last resort backups wiped from a locked suitcase when on holiday one time and I only found that out weeks later. But that might be because it had allegations of Jeb Bush & other people rigging the elections in Florida for Bush to get a 2nd term in office. I dont know.
I think that the purpose of this query param is to act as a substitute for cross site cookies: when you click on some link then the original url is further transfered as the http referrer header of the http request, if they can get hold of the logs of some affiliated site, then they can possibly track the flow of these fbclid attributes.
Interesting to observe, how every tiny detail is getting used for tracking purposes. I guess that browsers won't get rid of any specific query parameters when the url is passed as the referrer header, as that would be a violation of the protocol. However it may be possible to write a browser plug-in that does so.
I can only argue from running social campaigns in the past and while the charges to the credit card were real, the clicks from FB, Google, Twitter, etc did not relate to real world app downloads or website visits. Also there is research which at least to some extent backs up my opinion [1]
Just because someone talks about a vacation in Cancun that doesn't mean he/she wants or is able to go for a holiday in Cancun.
You are correct that TV ads are a shotgun approach to advertising. Yet, at least in my opinion, that made them more engaging in the past.
[1]https://www.techdirt.com/articles/20190530/10330742303/new-s...
This was never “OK” for people to be doing before the Internet/Facebook so why should it be “OK” now? Stalking is now stalking “with computers” so that makes it a novel concept?
P.S. That’s why you never give your phone number to ANY company, it’s too easy for them to connect a bunch of dots. And if a service one day decides to ask “for security”, interpret it as “for farming your data” and stop using them.
It’s definitely a gray area.
Or that’s how I understood it anyway, correct me if I’m wrong.
The real issue is that CCPA can only be enforced by the California Attorney General's office. This means that Facebook's violation of CCPA is, quite literally, as much of a political issue as a legal one. (CCPA's private right of action only applies to data breaches, not to other CCPA violations.)
If you and I are friends, is the knowledge of that friendship mine? Is it yours? Can I freely share that knowledge with someone else? The impact of this just became so absurdly large when we started saving those data points forever and mining them for all sorts of purposes they weren't originally intended for.
This seems to be an inherently flawed collection methodology. The users that one would expect to be involved with these "install this software, download this app and earn free money!!" schemes would also typically be associated with certain activities that would not necessarily reflect the overall population.
The experiment groups themselves are flawed, but then again, I also cannot think of an ethical/legal way to conduct this kind of research.
Bit something I learned in my college statistics courses is that with a large enough sample, self-selection bias stops becoming a problem.
It was a long time ago, so I can't explain the math here. But from what I remember, you need a surprisingly small sample size to actually achieve real representation.
Statistics as an area is full of gotchas, I never dismiss this sort of complain unless I have robust assumptions about the distribution being studied.
That reduces sampling error, not non-sampling error.
Which, to be fair, is literally Neilsen's entire product (for TV at least). I mean, I guess that everyone here understands selection bias at a deep level, but to think that people who sell representative data to big corporations (and have done for longer than many of us have been alive) don't have a similar level of understanding is just weird.
That doesn't actually deal with self-selection bias if self-selection correlates with the feature of interest within the demographic groups, which is probably the normal case.
What you might have learned is that small (random) samples might not represent the full population, but as you get bigger (random) samples they tend to get closer to the true values.
However, if you sample badly, errors will persist even when you sample more.
Example - estimating height in a population:
- If I get a perfect random sample of people then I can estimate population height really well, even with a smallish sample. The estimate gets better the more people I (randomly) sample.
- However if there's selection bias in my sampling and I only sample women, then no matter how many women I sample I'm going to be getting a bad estimate of height across the full population, because I'm excluding men who are taller.
Sample size can't overcome selection bias, you need to use other techniques to manage it.
That's...not true, until you are so close to the whole population that your maximum error from excluding part of the population is less than the error that would otherwise be introduced by bias.
With larger samples, sampling error of a random sample is reduced, but non-sampling error is (with the above caveat) not.
I would be curious about an update based on newer data. 6 years later, even more traffic is mobile where privacy protection is stronger and GDPR has companies more concerned about data sharing and trackers. I'm sure if you included mobile traffic, the trend over time is dropping (with a big dip when iOS 14 came out).
I can speak with complete sincerity and say that shadow profiles were not a thing, and were never a thing during or before my time (before, I can't be 100% certain, but I schlepped through the repos and never found examples of same).
What generally happens is that you pick a userid (maybe zero for arguments sake), and everyone who doesn't match to an FB userid gets that number. It didn't make it impossible to build an individual profile, but it made it much, much, much more difficult and I never saw anyone do it. I left in 2018, and would be massively surprised if anyone had built this since.
Now, it is entirely possible that not everyone was as rigorous as removing userid=0 (for example) and so some FB data probably counts them, and they may be in some of the clustering models but the notion that they have profiles indexed by browser/device id is completely false (for ads at least, some of the crap they did for PYMK was insane).
There is also "Your off-Facebook activity" (I guess depending on jurisdiction) which shows me online stores that uploaded my data to FB for ad targetting purposes, sadly I use the same "junk" email for online shops and Facebook, and FB's page showed me a lot of businesses who gave it my data!
I'm pretty sure that you could ask Mark about loads of existing ads products at FB and he would say the same thing, as he basically delegated all of ads to other people.
I really wish they were more specific about some of these claims.
Facebook's answer is likely illegal (Not a lawyer), get in touch with your local privacy defense group.
I remember his answer on whether users are tracked when logged off. I mean the answer can really be a very simple Yes. But instead we got this evasion (I lightly cleaned up):
WICKER: One other thing: There have been reports that Facebook can track a user's Internet browsing activity, even after that user has logged off of the Facebook platform. Can you confirm whether or not this is true?
ZUCKERBERG: Senator — I — I want to make sure I get this accurate, so it would probably be better to have my team follow up afterwards.
WICKER: You don't know?
ZUCKERBERG: I know that the — people use cookies on the Internet, and that you can probably correlate activity between — between sessions.
We do that for a number of reasons, including security, and including measuring ads to make sure that the ad experiences are the most effective, which, of course, people can opt out of. But I want to make sure that I'm precise in my answer, so let me ...
WICKER: When — well, when you get ...
ZUCKERBERG: ... follow up with you on that.
[1] https://www.washingtonpost.com/news/the-switch/wp/2018/04/10...
That said, I'm of the opinion Feinstein is largely senile at this point, and wish she'd retire.
I share your opinion that the NSA's surveilance is bad, and I'd assert it's unconstitutional, but the hypocrisy/contradiction you're trying to highlight still isn't necessarily there.
The government can kill me; Facebook cannot. The government can imprison me; Facebook cannot. The government can require I pay taxes; Facebook can not.
It shouldn't be surprising when similar disparities exist on surveillance. The NSA's program has yet to be deemed unconstitutional by the courts, which is what matters.
There are already several companies that build a credit history out of every major transaction I do. There's at least two companies that have parts of a full credit card transaction history on me. Almost every store I walk into has security cameras monitoring me. The level of surveillance I'm already living under is so high that if I had anxiety about that sort of thing I'd have run for the hills when I turned 21.
The ad surveillance networks are impressive in scope, but about on-par with their peers in finance.
Interesting opinion for somebody with nick called 'shadowgovt'. I get your point, but even as that its shouldn't be OK in any meaningful way. It can easily end up as a slippery slope that is extremely hard if not impossible to come back from, and the intrusion to ones privacy goes deeper and deeper till you have absolutely 0.
Nobody alive in this world has absolutely nothing to hide. Maybe ass warts or shape of sub-par penis, some rather unusual preferences or opinions on XYZ, body odor when sweating or locations of body hair, whatever.
We shouldn't have OK categories for intrusions to our most private parts of our lives, period. Terrorists, ad optimization, blahblah whatever, just nope. At least disabled by default and if one is brave enough just go ahead and enable it to get that 5$ discount. I feel very strongly that I don't want my children to live in a world like that, how can we fuckup with such a basic and important item.
Why does the stranger not have the right to let a third-party know you talked to them?
Improving the ad experience could mean they stick a probe up your rectum and see if your bowels move better or not, for all they care.
His public blabber on ai and automation are a great peek inside his mind.
The mindset is "That problem isn't solved because I haven't worked on it yet." There's no self awareness or humility involved, and he can afford the apparatus to maintain that for the rest of his life.
It's very difficult for those with ethical and moral standards to grasp that there are truly nasty people out there.
Users are absolutely tracked when logged off or on other sites through 3rd party cookies, aka the Facebook Pixel. If you go on a news site that has the Facebook Pixel, it will record that you went on their site. When you go back on FB, they will check that FB Pixel cookie and see what other sites with that same cookie you've visited. Through that, they can compile a profile of what interests to use to advertise to you.
Shadow profiles are a bit of a different story, since that would essentially be FB compiling a profile of someone that has gone to all these sites with FB Pixel, but doesn't have a FB account. That's entirely possible, and would make it so that if you do eventually make an account with a FB-owned product, they've already got all of that info on you to start targeting ads.
The most low hanging fruit and directly impactful way to prevent this as a user:
1. Use a browser or browser extension that blocks 3rd party cookies
2. Use an email alias service like Firefox relay. This allows you to generate a random email address for every site you make an account on, and all those email addresses forward emails to your actual email.
Using the same email everywhere is essentially the same as what FB Pixel does, it allows all these sites to share with data brokers that bob@gmail.com has made accounts at these other websites.
3. This is a bit harder/not as cheap to do, but the same applies for using the same phone number when signing up to sites, it allows data brokers/ad networks to connect accounts across dif sites to the same person. If it's not required, don't provide a phone number.
If it is required and the number will be used to send important info, try to use a disposable phone number service that forwards to your personal phone number. If it's required but the number won't be used for important communication, use a fake number like 123-456-7890
1. Everybody wants your phone number these days, especially those you don't want to give it to. From whatsapp and signal that use it as your main identify, whether you want to or not; to social sites like Facebook or Twitter that MAY let you sign up without phone, but "flag" you for security on first login and require phone; to other sites whether gmail or otherwise that require phone to sign in
2. More and more of them these days send a text to phone to verify it belongs to you
I'm therefore finding it harder and harder to not give my phone to everybody (of course, "not using the product" is always a possibility, so I still don't have a twitter account and by all accounts my life is better for it :)
What you want to avoid is using your phone number when doing things like online shopping, since that's when more personal details about you can be connected to your number, and therefore to the other social networks you used that number with.
It all tastes like chicken. The tracking mechanisms are identical. You are probably given some "Ad ID". And that Ad ID correlates with your facebook ID if you have a facebook account.
Calling it a "shadow profile" sounds sinister. But its just commonplace tactics that any ad network is going to deploy. Facebook just happens to have more information on you than others.
Well, short memory/attention span or straight out ignorance of the masses happened.When those ideas first circulated mainly by affected users noticing such practices(shadow-banning for example), those were the first to be burned at the stake.Then whistle blowers came and dropped some well intentioned crumbs first amongst circles of "techies", mainly anonymously.(it was much later on when 'actual proof' was given to the media outlets -- out of which the vast majority disregarded them --) Did not matter in the grand scheme though: employees were fired, media articles did damage control(>for< the company, most often than not; because a Company doing the damage control is partially admitting a degree of truth to the claim), and let's also mention the 'useful idiots' who believed the authoritative voices because 'history is written by the victors': which is now mostly a cyclic numbers game of how well one controls a narrative in the social network(/any other information channel).Considering the attacked entity is the social media platform itself, the discourse medium was inevitable advantageous and easily skewed for the platform to defend itself.The more principled either staid in the mud, fighting skeptics of the rumors, or moved platforms towards less censorious and/or anonymous places.Truth ultimately did not matter, the platform did the required divide & conquer to shift the attention.
It's really miniaturized politics, except it's actually worse: there's no democracy(well unless you're talking board of directors and such, but that almost never happens: such optics tank your stock).To quote the hypocritical statement of people who like authoritative voices and also 'like the free markets'[which by the way ideologically speaking is a contradiction, unlike you're by definition a fascist; Granted here we've substituted the authority from the state to the company itself]: "They're a private company, they can do whatever they want."; At the end of the day FB is already ~dead, and Zuck knows this.Some people (users who know the skeletons in the closet, the company, entities that use it to push their narratives) probably will continue to ride it out as long as the naivety of the vast majority continues.
Alas, fraud is Facebook's biz model. Effectively preventing inauthentic activity would reveal the lie. Better the bureaucratic kabuki, shielding Facebook (and others) with the respectable veneer of plausible denability.
How could it be otherwise?
How do people still disappear, or commit attacks like the Boston bombing and the authorities have to go on man hunts trying to figure out who they were?
Everyone's entire lifestream is archived. To leave no record, no trace, takes extraordinary effort and resources. Or to be completely off grid, living like a neolithic nomad; the same as not existing at all.
--
Even in 2000s, Seisent was being used to solve cold cases. Queries to identify suspects. Big data to reveal any one without an allibi.
It's like the 1,000s of rape kits, collected but unprocessed. Why? What possible reason can there be to not investigate? To not close those cases?
We can only guess. Perhaps the people responsible don't want to know.