This highlights the dangers of the seemingly harmless social widgets. Anyone who doesn't already, I highly recommend using a plugin such as ghostery[1] to block them.
This highlights the dangers of the seemingly harmless social widgets. Anyone who doesn't already, I highly recommend using a plugin such as ghostery[1] to block them.
Using libraries like this makes that interaction absolutely explicit, with minimal loss of ease of use, which means that nothing is shared until that explicit signal that the user wants to share.
The mere loading of the widget sends a signal to Facebook that you visited the shoes page. You don't have to interact with the widget for the info to be sent.
Ghostery blocks the widget from loading.
It's usually obvious to spot the CDNs and avoid the spies.
It breaks a lot of things initially, but after a while, the sites you use often are properly whitelisted, and it isn't a pain anymore.
A lot of the time it's a big pain to get it working right (say, to watch a video on a news site), but that's simply the price I have to pay in today's web to retain at least a bit of privacy and security.
If anyone wants to make a neat extension, it seems like all these extensions could be combined into one with a slightly better user interface. If you want to make it really spiffy, the black/white listing for these could be shared in a distributed hash table with some sort of voting/trust mechanism.
It seems that the more locked-down hardware manufacturers may have accidentally stumbled upon a kind of end-user workflow that may actually work for controlling what they want to share with the web!
https://www.requestpolicy.com/ and https://addons.mozilla.org/en-US/firefox/addon./RequestPolic...
It does use a cookie to track your preference. The default is to enable them (since most users are not tech savvy enough to know they want them off, and those same users wouldn't easily find a button to turn them on).
How does this even work? Is the shoe seller placing some kind of JavaScript snippet on their website in order to allow Facebook to track users? Is this coming from their "Like" button?
More information straight from Facebook: https://www.facebook.com/help/186325668085084
Second way, and probably the best, would be to go to its store page, and in the URL will be the extension ID; for Ghostery, it's "mlomiejdfkolichcflejclcbmpeaniij". Now, just find that in your Chrome installation directory, e.g. for Win7 the extension would be located at %LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\.
The last way would be to intercept or otherwise directly down the .crx file (curl, wget, etc.), which is just a compressed zip archive. You can do the same for FF extensions as well, those .xpi files are just zip files.
They're also an ad (analytics?) company. I just don't trust them.