Sexual abuse tip-off site could be sharing data with Facebook
sverigesradio.se
sverigesradio.se
How the hell does this just happen? Have people forgotten how to build simple forms and just use Facebook?
Some type of page download counter should not be impossible, and number of reports should also be easy metric. Why do they even think they need to get someone like Facebook involved...
And that won't change until enough large organizations get hit hard by fines that everyone else follows suit and hires actually capable CTOs with veto power over everyone else.
That said: This is a GDPR nightmare and so is Google Tag Manager
If they discover pageview events with PII in them, they throw them out.
I’m not justifying that hashed data is okay… but clear text data is not received or stored by Facebook via a Facebook Pixel, or their conversions API.
Data is not salted as far as I can tell, it's normalized and hashed via SHA256. They publish SDKs for serverside integrations so you can see how the code is set up.
https://developers.facebook.com/docs/marketing-api/conversio...
On my Mac, sha256() takes 288ns, so running nine billion of them to find the collision would take about 43 CPU-minutes.
I find it unfathomable someone needs to say that.
With a question as sensitive and personal as “am I transgender or not and how would I know,” it’s deeply important to me that visiting my website won’t accidentally get my users into trouble, even indirectly through tracking or federated cohort ad targeting.
- The only JavaScript is that which is necessary to run the site;
- The site only listens on HTTPS;
- There are no cookies;
- I explicitly opt users out of FLoC to prevent other sites targeting ads to my users based on my site’s content;
- I use a third-party hosting provider that only supplies aggregate passive server logs for a 30-day rolling window, which only shows me the domain name of the Referer, so I can’t know exactly where my users came from.
No JS is required to 'run' a site. I can and do use Hackernews without ever requiring JS to be enabled. Everything works via POST, it's quick and simple.
Yes. A Non-JS world is painful, and there are many difficulties, but ensuring your site works with noscript would do the world a huge favor.
But yeah, that’s certainly a bit of a novelty.
But I think "this site doesn't use JS so it must be safe" is...a really bad assumption.
My post above was concerned most of all with privacy, and the only scripts are for page rendering, they’re hosted from my domain, and they make no network calls. Bytecode in, DOM nodes out, all on the user’s device.
The Scottish health advice system was doing something similar.
https://www.theregister.com/2019/07/11/nhs_inform_loads_face...
A year ago it was the state-owned pharmacy Apoteket that leaked customer information and their orders to Facebook. Once it was revealed that multiple pharmacies did it, an investigation into three of them was started. Last month SR extended their search and found 100 pharmacies in Europe doing the same thing. Leaking information to Facebook.
I'm sure this is a really common issue because it's so convenient and useful when doing the marketing and analysis. People don't think about the consequences or the fact that it's against the rules of Facebook.
For example, Sweden has a Facebook Market competitor that uses Facebook _and_ Google for analytics. Now we know for a fact that Amazon has in past used AWS to spy on b&m and e-commerce competitors, i dont belive for a minute that Meta would be any better.
(good digging though!)
Depending on site owners and spyware companies, like Facebook, to solve the problem is super naive, and will never solve it. They directly benefit from these "leaks," and so they have no motivation to prevent them.
It's not that they can't understand it, it's that there's plenty of other stuff to pay attention to out there, for better or worse. The threat of cold and hunger comes before more abstracted threat vectors, and you are extremely lucky to have the mental space to consider and discuss such things as privacy on this here website. If you want to ride high on your sense of innate superiority, accept for yourself the mission you seem to imply for the technologically-literate and make privacy so simple even a small child could be protected.
Legislation is used to protect vulnerable groups and health data. Strong reasonable legislation is hard to write, and expensive to enforce, but effective enforcement will cause changes to internet sites. Think GDPR.
It is hard to manage cross-jurisdictional issues on the internet. In this case, Sweden could probably design good restrictions since it is a site local to Sweden?
Trying to get everyone to become security professionals is highly unrealistic.