Facebook Has Trackers in 25% of Websites and 61% of the Most Popular Apps (msn.com) 81
Megan Borovicka forget all about her Facebook account after 2013, reports the Washington Post. "But Facebook never forgot about her."
The 42-year-old Oakland, California, lawyer never picked any "friends," posted any status updates, liked any photos or even opened the Facebook app on her phone. Yet over the last decade, Facebook has used an invisible data vacuum to suction up very specific details about her life — from her brand of underwear to where she received her paycheck... It isn't just the Facebook app that's gobbling up your information. Facebook is so big, it has convinced millions of other businesses, apps and websites to also snoop on its behalf. Even when you're not actively using Facebook. Even when you're not online. Even, perhaps, if you've never had a Facebook account.
Here's how it works: Facebook provides its business partners tracking software they embed in apps, websites and loyalty programs. Any business or group that needs to do digital advertising has little choice but to feed your activities into Facebook's vacuum: your grocer, politicians and, yes, even the paywall page for this newspaper's website. Behind the scenes, Facebook takes in this data and tries to match it up to your account. It sits under your name in a part of your profile your friends can't see, but Facebook uses to shape your experience online. Among the 100 most popular smartphone apps, you can find Facebook software in 61 of them, app research firm Sensor Tower told me. Facebook also has trackers in about 25 percent of websites, according to privacy software maker Ghostery...
Facebook got a notice when I opened Hulu to watch TV. Facebook knew when I went shopping for paint, a rocking chair and fancy beans. Facebook learned I read the websites What To Expect, Lullaby Trust and Happiest Baby. Over two weeks, Facebook tracked me on at least 95 different apps, websites and businesses, and those are just the ones I know about. It was as if Facebook had hired a private eye to prepare a dossier about my life. Why does Facebook think that's okay? The company emailed me answers about how its tracking technology works, but declined my requests to interview its chief privacy officer or other executives about its alleged monopoly....
Who in their right mind thought they were signing up for this much surveillance back when they first joined Facebook?
The article points out that in 2014 Facebook began allowing its advertisers to target users based on websites they'd visited...and now also gathers more data about users from other companies. And "While many companies were using browser cookies, which could be easily cleared or blocked, Facebook tied what it learned to real identities — the names on our Facebook profiles." And beyond that, companies "can report other identifying information to Facebook like your email to help it figure out who you are... If you've never had a Facebook account at all? It may still be watching."
It's a lucrative business, the Post points out. "In 2013, the average American's data was worth about $19 per year in advertising sales to Facebook, according to its financial statements. In 2020, your data was worth $164 per year."
What does Facebook know about your off-Facebook activity? You can find out at this URL.
If you just want to stop them from giving this information to advertisers, the right side of that page has an option to "Clear History — Disconnect off-Facebook activity history from your account." But you then have to also click "More Options" and then "Manage Future Activity" to also stop them from later matching up more of your off-Facebook activity to your profile for advertisers.
If you try to select it, Facebook warns what you'll be missing — that "Keeping your future off-Facebook activity saved with your account allows us to personalize your experience." And proceeding anyways then generates a popup reminding you that "We'll still receive activity from the businesses and organizations you visit. It may be used for measurement purposes and to make improvements to our ads systems, but it will be disconnected from your account."
And apparently your activity on Oculus isn't covered, and will still remain connected to your Facebook account.
Here's how it works: Facebook provides its business partners tracking software they embed in apps, websites and loyalty programs. Any business or group that needs to do digital advertising has little choice but to feed your activities into Facebook's vacuum: your grocer, politicians and, yes, even the paywall page for this newspaper's website. Behind the scenes, Facebook takes in this data and tries to match it up to your account. It sits under your name in a part of your profile your friends can't see, but Facebook uses to shape your experience online. Among the 100 most popular smartphone apps, you can find Facebook software in 61 of them, app research firm Sensor Tower told me. Facebook also has trackers in about 25 percent of websites, according to privacy software maker Ghostery...
Facebook got a notice when I opened Hulu to watch TV. Facebook knew when I went shopping for paint, a rocking chair and fancy beans. Facebook learned I read the websites What To Expect, Lullaby Trust and Happiest Baby. Over two weeks, Facebook tracked me on at least 95 different apps, websites and businesses, and those are just the ones I know about. It was as if Facebook had hired a private eye to prepare a dossier about my life. Why does Facebook think that's okay? The company emailed me answers about how its tracking technology works, but declined my requests to interview its chief privacy officer or other executives about its alleged monopoly....
Who in their right mind thought they were signing up for this much surveillance back when they first joined Facebook?
The article points out that in 2014 Facebook began allowing its advertisers to target users based on websites they'd visited...and now also gathers more data about users from other companies. And "While many companies were using browser cookies, which could be easily cleared or blocked, Facebook tied what it learned to real identities — the names on our Facebook profiles." And beyond that, companies "can report other identifying information to Facebook like your email to help it figure out who you are... If you've never had a Facebook account at all? It may still be watching."
It's a lucrative business, the Post points out. "In 2013, the average American's data was worth about $19 per year in advertising sales to Facebook, according to its financial statements. In 2020, your data was worth $164 per year."
What does Facebook know about your off-Facebook activity? You can find out at this URL.
If you just want to stop them from giving this information to advertisers, the right side of that page has an option to "Clear History — Disconnect off-Facebook activity history from your account." But you then have to also click "More Options" and then "Manage Future Activity" to also stop them from later matching up more of your off-Facebook activity to your profile for advertisers.
If you try to select it, Facebook warns what you'll be missing — that "Keeping your future off-Facebook activity saved with your account allows us to personalize your experience." And proceeding anyways then generates a popup reminding you that "We'll still receive activity from the businesses and organizations you visit. It may be used for measurement purposes and to make improvements to our ads systems, but it will be disconnected from your account."
And apparently your activity on Oculus isn't covered, and will still remain connected to your Facebook account.
Re: (Score:1)
Don't forget Google.
All those lovely Javascript frameworks that people love to use all come with a cost. Spyware, trackers and all sorts of nasties lie in wait for the unwary.
If more people were to start blocking all FB, Google and other slimeball domains on their devices they might see two things. There are more than 5,000 of them.
1) a considerable speedup of sites and apps.
2) a lot less traffic going to the likes of Emperor Zuck. Starve them of data and the advertisers will go away or at least head off to
Re: (Score:3, Insightful)
Imagine the power of knowing mostly everything a person did the past 10 or more years. Senators, Presidents, CEOs, CFOs, Religious Leaders, Regulators, Health Authorities, Security Leaders, Generals, Billionaires, Millionaires, Policy Makers, Judges, Sports figures, Lawmakers, Drug Dealers, Non Profit Board Members, Principals, Union Leaders, ... imagine you have all that information, in the name of displaying an advertisement to store phone pictures for you very conveniently. This is not just a lot of powe
Re: (Score:2)
Re: (Score:1)
Customer Demand (Score:1)
Our e-commerce customers often ask us to support facebook integration and even support generating sales reports to sell to third parties. We just say no, get someone else to do it. I don't care if it means we lose an income stream.
Re: (Score:2)
Ah yes, those magic words: "income stream"!
Over and over, you think, "No one would do that!" But if the income stream is there - they certainly will. Cash is the universal solvent.
Burn all 'soclal media' to the ground (Score:2, Insightful)
Re: (Score:2)
^^^ This. A thousand times, this. (A thousand jail terms per offence)
Privacy Badger (Score:2)
This is why I am using the browser plug-in Privacy Badger [privacybadger.org].
Older versions of Privacy Badger used to list all domains that a page loaded from and let me block every one, but newer versions block only verified trackers.
But really, I think that browsers should have this functionality in themselves - the older functionality, that is.
Re: (Score:2)
Privacy Badger, uBlock Origin, HTTPS Everywhere are the 3 minimal plugins every browser should run. NoScript if you can deal with it also very good. There are probably more out there as well people can recommend.
Also every router should really have some amount of list filtering/blocking similar to what PiHole or PFBlockerNG provides to stop a lot of this nefarious stuff at the gates as well.
Re: (Score:2)
You forgot NoScript.
That one plugin knocks out most ads and disables a lot of other annoying shit too. I highly recommend it.
Re: (Score:2)
You forgot NoScript.
No he didn't. It's the 2nd sentence of his post.
Re: (Score:2)
My bad for missing that. I'd like to blame it on my old age and 5-second attention span.
Re: (Score:2)
NoScript breaks so many sites it's too much of a chore to use, the privacy extensions are better as you don't have to spend time configuring them for countless websites.
Re: Privacy Badger (Score:3, Insightful)
Unfortunately all those tools are web browser only. It won't help for contaminated apps. And you don't always know if an app is contaminated.
I don't do facebook, but I have no illusion that 'I have evaded them completely.
Re: (Score:2)
On your phone a lot of app home phone functions can be disabled with using an appropriate block list on blokada:
https://blokada.org/ [blokada.org]
Re: (Score:2)
And that won't work while at work.
The only good solution: Facebook has to quit.
Re:Privacy Badger (Score:5, Insightful)
cat
# localhost is used to configure the loopback interface
127.0.0.1 www.facebook.com
127.0.0.1 facebook.com
127.0.0.1 login.facebook.com
127.0.0.1 www.login.facebook.com
127.0.0.1 static.ak.connect.facebook.com
127.0.0.1 connect.facebook.net
127.0.0.1 www.connect.facebook.net
127.0.0.1 apps.facebook.com
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 connect.facebook.com
127.0.0.1 developers.facebook.com
127.0.0.1 ads.interfacelift.com
127.0.0.1 ads.ak.facebook.com.edgesuite.net
Re: (Score:2)
+1 for Privacy Badger, it's not perfect but at least coming from the EFF it's not going to be sold to some evil malware-producer tomorrow.
FWIW, The previous blocking function was more comprehensive but the heuristics broke important stuff, e.g. like 'Verified by Visa', causing online transactions to fail at checkout (by default, this wasn't due to manual selection).
I hit this issue a few years ago, eventually removed the extension, but reinstated it once it changed to verified trackers only.
Equal treatment under the law (Score:4, Insightful)
Corporations are people. And if an individual were to find the brand of underwear worn by every woman in his neighborhood there would be at the bare minimum some public outcry, if not an investigation. But when a corporation does it, we allow it and some even defend the practice.
The entire point of the legal fiction of corporations is for a business partnership to trade some freedom(in the form of regulation) for some protection (personal liability), not for corporations to get more freedom than even a private citizen enjoys.
Sadly we're going to react badly one day and swing to the other extreme in response. In that era, capital will be hard to come back and recessions will last a very long time. (assuming macroeconomists are even remotely correct)
Re:Equal treatment under the law (Score:4, Insightful)
I’ll believe corporations are people as soon as Texas executes one.
Re: (Score:2)
Some countries have a corporate death penalty. Where the organization is dissolved and its assets are confiscated to pay restitution and the remaining redistributed by the government. Not a popular idea in the US sadly.
Re: (Score:2)
I’ll believe corporations are people as soon as Texas executes one.
Or brought to trail... and I do mean the actual corporation, not a "representative" of it. Like, if I'm the prosecutor, I'd be "Where's the corporation?? I want the corporation on the stand, not this idiot representative of it. So?? WHERE IS THE CORPORATION??"
Facebook site to stop Facebook? (Score:4, Funny)
Isn't this sort of like having to go to Hell to tell Satan to leave you alone?
Re: (Score:2)
Well, I'm in "Private Mode" so I clicked on the "What does Facebook know about your off-Facebook activity?" link. It asked me to sign in. I have never had a Facebook signin. What I have had is members wanting to "friend" me on at least two of my email accounts and they clearly track those requests.
The biggest worry about this (Score:1)
Is by concentrating all this personal data in one place, it makes for a mighty ripe target for outsiders to "harvest" and resell.
I sure hope BookFace is better at DB security than Microsoft.
Re: (Score:1)
This is why just blaming users is idiotic, IMO. (Score:2)
Blacklist facebook.com (Score:2)
Just setup DNS or browser to blacklist facebook.com. No FB trackers.
Re:Blacklist facebook.com (Score:4, Interesting)
Just setup DNS or browser to blacklist facebook.com. No FB trackers.
Lest anyone think it's that easy, know that there are over 900 domains which need to be blocked in order to start thinking about blocking Facebook. It looks like this:
https://qz.com/1234502/how-to-... [qz.com]
That list is from 2018. There are likely many more by this point.
Re: Blacklist facebook.com (Score:2)
Well, that's why I generally whitelist. But there are also services to keep an up-to-date list of things to block.
Re: (Score:2)
I didn't count them at all, but I see maybe 10 domains that would need blocking? Where are you getting 900 from?
Re: (Score:3)
That list is in hosts file format (where's that apk dude?).
Re: (Score:2)
There aren't THAT many domains, but there are a lot of hosts. To do this at the DNS level, you need to configure your server to claim authority for fb.com, facebook.com, and similar. It won't try to recursively resolve ANY hosts in those domains, and just return whatever you want it to return.
At one time, I did it for *.doubleclick.net within our network It also took out all the ads associated with that domain.
But, it only works when you use your particular DNS server. A phone will generally use whatever th
Re: (Score:3)
My suspicion is that local blocking doesn't work, and these 'partner' companies are both supplying the fingerprinting scripts and sending the data from their servers.
I use uBlock Origin in hard mode and recently searched for a music interface on GumTree. Of the 31 domains, uBlock allows four (two gumtree first-party, then akamaiedge.net and ebayimg.com). My Facebook tab (same Firefox browser, different container) very quickly showed ads for the product.
This was inexplicable until today. I'm impressed that t
Re: Blacklist facebook.com (Score:2)
Why not just block third party JS? No need to focus on trackers, specifically.
Still no app to poison the well? (Score:4)
Or a browser plugin that does it?
There is one thing that's worse than no data. Way worse. It's poisoned data. Data where you cannot tell real data from manipulated data. Why didn't ever anyone create a tool that lets people swap about their cookies and/or visit a slew of garbage places to make everything they collect useless?
Re:Still no app to poison the well? (Score:5, Interesting)
That's been done for a long time, and google, facebook et al did their damnest to make sure as few people as possible hear about it:
https://adnauseam.io/ [adnauseam.io]
Re: (Score:1)
Re: (Score:2)
What is the purpose of facebook and google tracking you?
What does clicking on every ad offered do to this model?
Re: (Score:1)
Re: (Score:2)
Purpose of adnauseam is not to reduce google's and facebook's revenue, but to shield a person from having their interests tracked accurately.
Re: (Score:1)
Re: (Score:2)
I was thinking more along the lines of a plugin that shares among its peers the pages they visit, then then everyone in on it accesses the Facebook-tag so it looks to FB like they were visiting that page.
The idea is to make the whole data gathered about a user's browser habit worthless by essentially visiting EVERY page, thus increasing entropy to the point where all the data has to be tossed out.
Re: (Score:2)
How would you make this work in practice? Not a hypothetical "what if" but how would you actually handle the distribution, blocking of the browser fingerprinting and so on?
Re: (Score:2)
Browser fingerprinting relies on a couple of things that can be faked, that's basically where it starts. Next, shuffle the tracking cookies among the participants. Or, failing that, shuffle about the tracking cookie URLs so everyone can "access" them to ensure everyone visits every page, thus invalidating the data collected there.
Re: (Score:2)
You didn't answer the specific questions I had, because those are actually really hard questions to answer. Distributing your tracking cookie to someone else, and then getting a no-knock warrant served at your house because someone else used your individual cookie to upload some child porn is a very real problem, as we now know for certain in the wake of Apple's "we scan everything you upload" revelation that police is indeed served data on things like child porn.
Ad nauseam doesn't have those risks, while a
Re: (Score:2)
I'd expect pages that deal with the more questionable, read, illegal, material of the internet to not have too many ad trackers attached to their pages. For, well, obvious reasons.
What I want is to have all those Facebook-tags that give Facebook the info that you visited a certain page distributed, so everyone would hit every "visited" marker. If everyone hits every page equally, the information you gather from it becomes worthless, because everybody is as good as nobody in this context, it's 100% entropy w
Re: (Score:2)
At that point, facebook would make a deal with each site that would extend this to personal login data.
They already do this. In fact, they already do more than this. For example, they have an agreement with Lidl where purchase data from Lidl's bonus program is fed directly to facebook.
Your idea would simply motivate them to go deeper into spying. Right now, it's easily blockable. It's not hard to make it much harder to block and poison data. The only reason they don't do it is because they don't have to. Ye
Re: (Score:2)
We don't have to make it impossible. We only have to make it so expensive that they consider it unfeasible to try to harvest that data and instead go with what they can get from those that don't try to block and poison them.
Like I said elsewhere, one of the creeds we had in statistics is "if you can't get good data, better don't get any". In other words, before you accept data that may poison your data pool, just go with the data you can get where you can be reasonably certain that it's good data. All we ha
Re: (Score:2)
You seem to use "we" as in plural, rather than royal.
Reminder that most people not just don't care, but actively want personalized content. You will not get a meaningful amount of people for these applications. They will remain niche. Adnauseam has been out for a long time, doesn't have the most extreme of negative consequences of the system you suggest, and it still didn't get any traction. And not just because of lack of word of mouth. A lot of complaints about it are actually about it breaking personalis
Re: (Score:2)
Even better, then Facebook won't bother working against those that do value their privacy. They get their info from the duds, we get our privacy. It's win-win all over.
Re: (Score:2)
Re: (Score:2)
In Firefox and Chrome you can prevent most of this tracking by simply disabling 3rd party cookies.
At the moment Firefox blocks 3rd party cookies by default. Chrome will do in the next year or so, having announced the change a while back.
Obviously you should be running an ad blocker and privacy enhancer as well, but this change to the default setting will massively impact Facebook's ability to track users.
Re: (Score:2)
Not preventing. Perverting.
I've been in statistics for most of my early professional life, and if there was one thing we dreaded more than having no data it was having bogus data. One of the key creeds was "If you can't provide reliable data, just provide none". Because no data at least leaves the rest of the data intact.
If you throw in garbage with the data, up to the point where you can't tell real from fake, the whole data you have becomes utterly useless.
And that is my goal. To make the data they have u
"personalize your experience" (Score:2)
Including SlashDot ! (Score:2)
That "blue f" you see on webpages is an automatically loaded image that functions as a tracker. Most web-browsers will reply to cookie requests for same-domain IMG tags, so FB will have your userid if you leave FB cookies available when the evil "blue f" shows. I quarantine FB browsing in a separate profile where FB can read its own cookies and nothing else.
How can you block it without a facebook account? (Score:3)
TFA talks about how they track you even if you don't have a Facebook account, but the link they give to limit your data only works if you have an account. How can you decline if you don't opt into their system?
Re: (Score:2)
Yes, this. I don't have an account but it appears the only way to have any voice with FB is to have one.
Should someone open an account for the sole purpose of ensuring tracked data is explicitly tied to a No from the owner?
If so, does anyone have tips like use / don't use a burner email, etc.?
LOL, nope (Score:2)
I don't have a FaceCrap account, but they're welcome to collect all the statistical horseshit they like on me. It won't do them much good and will likely only pollute their stats in the long run.
Its about time the EU shut those bastards down (Score:1)
We need the government to stop this (Score:3)
Just kidding. The government just loves this, and FB's spy machine will continue to hum along smoothly as long as the scary 3 letter agencies are ensured access to this data.
FaceBook + Instagram = FBI
Screw FB (Score:1)
Only two... (Score:2)
Tech enmeshment (Score:1)
Re (Score:1)
The people who DIDN'T sign up for Facebook ever, because back in the day, they could see how intensely invasive it was even without all the crazy tracking that has been added in the past 15 years.