Facebook fixes logout issue
nikcub.appspot.com
nikcub.appspot.com
And thanks to Nik for bringing this to the light.
PR speak. This seems much less like a bug to me, more like a poorly contemplated decision.
What seems more likely is that they were contemplating what they should do, and given the general direction Facebook is headed, they probably thought little of just leaving it in.
I love the facebook guys, but calling it a bug as opposed to a non-malicious decision is just PR speak
Just so we are clear: we don't cookieless "track users anyway".
I suppose you guys can line up to say I'm lying like you did to the other engineers who posted yesterday, and it is quite obviously impossible for me to prove otherwise. But suffice to say our policies are rather clear on the issue.
We need to enter into an awareness about how identifiable we are just browsing the internet. Average users need to know this. It's not like Facebook can force browsers to not send identifiable content and its refusing to--web browsing has been designed to allow third party content just like that. So we need to start exploring the ways in which this amount of trust to third party content isn't so implicit.
> I suppose you guys can line up to say I'm lying
I never sad you lied. I just sad what you explicitly state on your privacy policy:
"We receive data whenever you visit a game, application, or website that uses Facebook Platform or visit a site with a Facebook feature (such as a social plugin). This may include the date and time you visit the site; the web address, or URL, you're on; technical information about the IP address, browser and the operating system you use; and, if you are logged in to Facebook, your User ID."
http://www.facebook.com/about/privacy/your-info#inforeceived
If that's not "tracking" I don't know what is...
With the exception the the UserID for logged in users, all of this data is standard stuff that every browser sends to every server of any site on every request.
> If that's not "tracking" I don't know what is...
If basic http header stuff is "tracking" to you, then every site on the internet is tracking you.
> sends to every server of any site on every request.
Come on lbrandy, let's be honest. Are you telling me and to the HN audience that you don't use the data "that every browser sends to every server", analyze it, try to get unique users out of it, try to gather interest, browsing behavior, a lot of other stuff and sell it to advertisers? Because that would contradict what you state in your privacy policy.
>> If that's not "tracking" I don't know what is...
> I believe the word I'd use is "http".
http is the protocol you gather the data with. Once you got it, you gather your stats from it. And thus track users with it. And you state so explicitly in your privacy policy. And there is IMHO nothing wrong with it. I adblock it anyway.
That's pretty much the definition of "cookieless tracking", isn't it? Feel free to read my original post.
This is spelled out quite clearly here: https://www.facebook.com/help/?faq=186325668085084
Yes, it is.
"We will keep aggregated and anonymized data (not associated with specific users) [...]"
Ok. So you partially confirm my point. You DO track users. But you say you don't keep the information associated with "y0ghur7_xxx", but with user_id:389472984. At least on the FAQ. The privacy policy is not so clear.
It's really nothing to worry about though, unless Facebook is doing something to de-anonymize that (otherwise stateless) data. They could probably do that (by noting the IP and User-agent seen when logging out, for example), but they explicitly claim not to in a number of places, most recently by lbrandy in this thread.
> "tracking" is "web server log analysis," then nearly every
> web site you visit is tracking you.
Of course. The "problem" is that the FB widget is all over the web, giving them the the possibility to track users not only on a single page, but on (almost) the whole web. I put "problem" in quotes because it's only really a problem if users don't know that. And I think the vast majority of FB users don't know that FB knows almost every page they visit on the web. The same is true for google as well of course.
If you are really concerned about this why not use a browser extension that randomizes your HTTP headers?
That's the privacy-endangering activity that has resulted from your sheer size. Please don't pretend it doesn't exist.
That's no different from being tracked by Google(DoubleClick). If you don't approve, it's really a matter between you and the web sites you visit.
That's a simple fact that sometimes gets lost when people are discussing Facebook. Lots of third-parties do this sort of thing and most of the time, nobody notices or cares. It feels odd to hold Facebook to a different standard.
Deleted comment
"We use the information we receive about you in connection with the services and features we provide to you and other users like your friends, the advertisers that purchase ads on the site..."
https://www.facebook.com/help/?faq=186325668085084
In particular, information from social plug-ins are specifically not used to target ads to users.
> you guys can line up to say I'm lying
You say that as if people should be ashamed for presuming the modern American corporation is lying to them. I've been directly and obviously lied to by representatives of many companies and they've all played the victim like you are.
If this is official have Zuckerberg say something legally binding.
> it is quite obviously impossible for me to prove otherwise.
Not at all. As a corporation, allow independent auditors to monitor certain key filtering systems to make sure you couldn't be receiving data you say you don't intend to log.
As an engineer you could leak the policy memos. And I mean leak, not get permission to post some redacted version.
Does anyone know how this cookie is used to prevent CSRF?
This functionality is referenced in the security guide.
http://guides.rubyonrails.org/security.html#csrf-countermeas...
So as long as you log in to Facebook often enough (more often than you install new browser plugins or fonts or whatever), they can cookieless-track you perfectly when you're logged out, by remembering the browser fingerprint you had when you were logged in. And even if the fingerprint changes a little bit, they could use something like Levenshtein distance, combined with statistics of frequently visited sites, to have a good chance of identifying you anyway. In the hypothetical world where Facebook was an evil monster of surveillance, of course. I'm not talking about the real world here ;-)
So what can you do when faced by a hypothetical monster like that? Disabling third-party cookies is only the first step. Is there any reasonable way to anonymize your browser fingerprint?
Maybe not totally anonymize, but a lot of the data that gets used for browser fingerprinting relies on flash to work, so if you run without flash on by default (click to flash, or whatever) that should help.
That is a bit unsettling.
"Within our dataset of several million visitors, only one in 27,775 browsers have the same fingerprint as yours."
But turning on Javascript, but leaving FlashBlock on, produces the same message as yours. Interesting...
Your browser doesn't report the fonts on your computer in alphabetical order.
I would prefer they deleted all cookies, since the user/browser can still be uniquely identified
A. His lips are moving.
Yeah, right! Sure it was a bug.