Facebook detects if you are logged in Gmail
webapps.stackexchange.com
webapps.stackexchange.com
I don’t log into Facebook for any reason on my normal user account, and I don’t log into anything else on my Facebook account. They can still sniff certain things using browser fingerprinting and so on, but this seems like the best I can do for the moment on my desktop.
Snapshots are astoundingly, amazingly, beautifully fast.
I use it to separate my various different Google identities and logins (so I can stay logged in with distinct accounts).
(Google's multiple sign-in is rarely effective or convenient)
Not flash "cookies". You only have one flash plugin that runs in every browser, and has one "cookie" store.
(Not that I know if/whether FB abuses this, I don't even have an FB account. Just sayin'.)
Situations like yours always remind me of how people emotionally force each other to stay in a religion, by threatening a cut-off of communication if they leave.
Did you happen to read the answers? Two specifically mention that Facebook requests authentication access (OpenID, I believe) the first time. It appears this user authorized Facebook at some point in the past and forgot about it.
When I look at this page: https://accounts.google.com/b/0/IssuedAuthSubTokens I can see that at some point in the past, I allowed Facebook access to my Google Contacts (probably their "find friends" feature). Facebook could use that to check if you're logged in.
> Nope it's not that unfortunately. I tried it myself removing all linked accounts. The event above still happens.
"The OAuth tokens for Google are at https://accounts.google.com/b/0/IssuedAuthSubTokens (it's different from Linked Accounts).
When I tried it, Facebook created a popup with a OAuth prompt the first time and only briefly opened a blank popup on subsequent attempts. De-authorizing facebook makes the prompts appear again."
Unless they're talking about two different prompts?
I am not much concerned about this – but I'm starting to, sometimes it is actually a bit creepy –, but I see a lot more people concerned about Facebook tracking them than Google, which I don't understand, since Google has been doing it far longer and in a much more pervasive way, yet very few people express concern about Google these days. I remember the uproar when Gmail introduced content targeted ads, but now nobody cares anymore, directing all attention only to Facebook.
Tangentially, the issues raised by dontbubble.us concern me more than being tracked.
[1] - http://www.foxbusiness.com/technology/2011/11/04/investors-u...
You can sync all Chrome browsers, on all your devices, with both your Google Apps account for work and your personal Gmail account. It means that each profile have their own bookmarks, history & most visited pages, extensions, saved passwords (...) synced in real-time (you can even sync open tabs!). It's very powerful to improve your focus, because you only use 1 browser (no need to switch your habits) and you're never get distracted by notifications, mails, docs, rss when you're in your work/perso "station".
Fortunately, you can keep your Gmail/Google apps chat accounts of each profiles open in the background with the official Google Talk extension https://chrome.google.com/webstore/detail/nckgahadagoaajjgaf... (works on Mac, Windows, Linux & ChromeOS).
You don't seem like the kind of user FB targets anyway...
Your definition of "essential" might vary, but last time I checked there is: mail, sms, phone and talking face to face.
Also, what is "essential" for "people under 20"? Not reading the latest silly high-school gossip from their pals?
Events - a lot of people post events on Facebook and trust that all of their friends will see it.
Photos - a lot of people only share photos through Facebook. If you want to see or download photos someone has taken at an event you were at your probably need to use Facebook.
Email - most younger people do not use email (unless they have to for school/business. Instead they use Facebook messages.
I won't bother addressing you last comment. Maybe your experience of high-scool was different than mine was, which consisted of a lot more that 'silly high-school gossip'.
But you're also isolating yourself by simply drawing a point that you don't have Facebook anymore. It's an eye roll producer on the level of saying "Oh, I don't have cable/TV anymore." Sure, lots of people agree with that notion but it's used to drive a wedge in-between you and others by most
At what point will you decide to ban Facebook? Will you stop using their services if they find a way to spy on your cross-browser behavior? Or will you just sandbox them further into a VM, or even another physical machine? What if other sites you use regularly also start tracking you so aggressively?
I deleted my FB account when I learned that more of my profile info was being made public over time. This was before Like buttons.
I was not a heavy user, but this decision had its price; there are people I no longer communicate with because of it. Still, I'm happy I took a stand, all the more so because things have deteriorated much further since then in terms of privacy.
With that preface, it's my impression right now that https://singly.com deserves a serious look from communities such as hacker news. So, I'm mentioning it here.
A little about them: they're led by the guy who created XMPP (aka Jabber). He's written a new distributed protocol based on JSON instead of XML ( http://www.telehash.org/ ). They've been joined by the guy who lead Canonical (publishers of Ubuntu). Like Wordpress, they are part free software project and part optional hosting company.
No, I am not affiliated with them. But I am really thinking that I would like to be...
For instance if you have website a and say the user profile "mitsuhiko" can only be edited when you are logged in as "mitsuhiko" on http://a.example.com/profile/edit/mitsuhiko you could use this code to see if the logged in user is "mitsuhiko":
<script type="text/javascript" src="http://a.example.com/profile/edit/mitsuhiko"
onload="user_is_logged_in()" onerror="user_is_logged_out()" async="async"></script>
Why does this work? Because onload is fired if the resource answers with 200 OK, not if it's a valid script. onerror is called for any other error code.So if you know what you are probing for: easy.
// Edit: Yes, this is most likely not what Facebook is doing if that's their only method of security. However see my reply to the first comment here about the security aspect for a possible way to solve this problem.
Also, for something like that you should use <img> instead so it's less of an XSS risk.
Yes. But depending on how gmail works it could me made reliable and secure. For instance if you can share images with gmail users you could generate a unique image for that user, do the same thing with an <img> tag, access the image data with JavaScript, send it back to the server and compare if the contents are the one you shared.
I do not have a gmail account so I don't know if this is possible, it it seems like it would be possible for Google+ from briefly looking at it.
And if it was an image generated by Facebook, then Facebook must have access to the account beforehand, and there's no benefit to using this system over OAuth.
// EDIT: ignore what was here, you're right.
https://grepular.com/Abusing_HTTP_Status_Codes_to_Expose_Pri...
GMail doesn't seem to be working any more though. But the concept is still useful to learn.
Subsequent attempts make the auth dialog flash briefly without displaying any content and still present the "You can change your password immediately because you are logged into your email account on this browser" message.
If yes, user can be verified quickly and reset their password in an easier fashion for them. Facebook is trying to make things smoother and not making you jump into your email to click a link or copy some token id or something. This is good UX.
Edit: I just profiled the process, and it is using OpenID. It pops open a new window that will check your OpenID login and call back with a success and will close the window if it is. I had to slow down my connection to actually see it.
Instead, they should have make a block, so that you are forced to logout of your gmail and login to your gmail to enhance security.
Now I have a nice separate window for browsing Facebook and nothing but Facebook.
Separate cookie store is awesome.
It definitely does on my version, which is 6 months old, but it caused me to not use it.
It uses (by purpose) the same session though as the main Chrome instance.
But it should be possible to implement an option to use a separate session. This might even be much simpler than my current approach (which not only shares the session, it also uses the same Chrome process).