Live data from Hacker News

Facebook’s Instant Personalization Is the Real Privacy Problem

gigaom.com

21–30 of 41 posts

Re: Facebook’s Instant Personalization Is the Real Privacy Problem

#21

wont it be odd if you go to a website for the first time and u see that the website knows more about u than you know about the website?

u r rite abt that lol

Or to be more precise, please use proper English. If English is your second language, we are forgiving -- unless your first language is AOLspeak.

Re: Facebook’s Instant Personalization Is the Real Privacy Problem

#22
post #9
post #6

Even with instant personalization turned off, your friends can share your info on any service they get suckered into using. Given how many of my Facebook friends bombard me with quizzes and Farmville, I'm guessing that's going to happen a lot. You have to block each application individually. Moreover, any site can display your profile information. http://cnn.com even seems to combine it with what CNN stories they lik…

We were told that third parties can't get any information from the social plugins. The data is served directly from Facebook using an iframe.

That's true for the social plugins, but if you've authenticated with the site (e.g., click the "log in" button at the top of any CNN page and log in with FB), any 3rd party running javascript on the page will have access to all of the data you've allowed the parent site to access.

Facebook uses their parent-child-parent iframe tricks to assign a first-party cookie for the host domain. This cookie contains the Facebook user id and the OAuth access token used to make requests to the Graph API.

Any javascript running on the page can snatch that cookie and send the data back up to its mothership, which can then impersonate the host domain to make API requests on behalf of the user. Fun stuff.

Re: Facebook’s Instant Personalization Is the Real Privacy Problem

#23

Forget about Google... Facebook is gunning for Claritas and other profiling companies that have been doing this for years, though behind the scenes and not in real time (see http://epic.org/privacy/profiling/ for more about profiling). Google may have (deservedly) gotten a black eye for the Buzz debacle, but they have a lot of cultural DNA that values privacy (their CEO aside) and at least some systems in place to al…

That is some really scary stuff in the link you gave!!! People need to realize that it's not worth the $0.25 off a can of green beans you get by using a loyalty card, if a sleazy merchant is going to swoop in at some vulnerable time in your life and help separate you from hundreds or thousands of your dollars.

Re: Facebook’s Instant Personalization Is the Real Privacy Problem

#25

Forget about Google... Facebook is gunning for Claritas and other profiling companies that have been doing this for years, though behind the scenes and not in real time (see http://epic.org/privacy/profiling/ for more about profiling). Google may have (deservedly) gotten a black eye for the Buzz debacle, but they have a lot of cultural DNA that values privacy (their CEO aside) and at least some systems in place to al…

That is some really scary stuff in the link you gave!!! People need to realize that it's not worth the $0.25 off a can of green beans you get by using a loyalty card, if a sleazy merchant is going to swoop in at some vulnerable time in your life and help separate you from hundreds or thousands of your dollars.

You got it. I worked in marketing for years and was always shocked at how much personal data we could get our hands on. It makes the recent dust ups about online privacy look (almost) tame in comparison, yet these profiling companies get away with it because no one realizes what's going on.

Re: Facebook’s Instant Personalization Is the Real Privacy Problem

#26

Forget about Google... Facebook is gunning for Claritas and other profiling companies that have been doing this for years, though behind the scenes and not in real time (see http://epic.org/privacy/profiling/ for more about profiling). Google may have (deservedly) gotten a black eye for the Buzz debacle, but they have a lot of cultural DNA that values privacy (their CEO aside) and at least some systems in place to al…

That is some really scary stuff in the link you gave!!! People need to realize that it's not worth the $0.25 off a can of green beans you get by using a loyalty card, if a sleazy merchant is going to swoop in at some vulnerable time in your life and help separate you from hundreds or thousands of your dollars.

Can you give an example of how they are going to 'help separate you from hundreds or thousands of your dollars'?

Re: Facebook’s Instant Personalization Is the Real Privacy Problem

#27
post #24

What's the best way to block this entirely? /etc/hosts won't work because it's not on a subdomain (the iFrame loads from http://www.facebook.com/plugins/activity.php ). This would make a nice Chrome/Firefox extension.

Any decent browser should be able to block content by URL. Use your adblocker.

Re: Facebook’s Instant Personalization Is the Real Privacy Problem

#28
post #14
post #4

Earlier quoted context omitted.

I did just that, and this is what it told me: "Please keep in mind that if you opt out, your friends may still share public Facebook information about you to personalize their experience on these partner sites unless you block the application."

But what does "public" mean there? If your privacy settings have information access as "visible to friends only", can "these partner sites" access that data if your friend doesn't opt out of this sharing?

See http://www.facebook.com/settings/?tab=privacy&section=ap...

For those who don't want to have to log in to find out:

"What your friends can share about you through applications and websites:

When your friend visits a Facebook-enhanced application or website, they may want to share certain information to make the experience more social. For example, a greeting card application may use your birthday information to prompt your friend to send a card

If your friend uses an application that you do not use, you can control what types of information the application can access. Please note that applications will always be able to access your publicly available information (Name, Profile Picture, Gender, Current City, Networks, Friend List, and Pages) and information that is visible to Everyone."

(I'm pretty sure at least current city wasn't on that list until fairly recently.)

Checkboxes for lots of other information follow.

Re: Facebook’s Instant Personalization Is the Real Privacy Problem

#29

Forget about Google... Facebook is gunning for Claritas and other profiling companies that have been doing this for years, though behind the scenes and not in real time (see http://epic.org/privacy/profiling/ for more about profiling). Google may have (deservedly) gotten a black eye for the Buzz debacle, but they have a lot of cultural DNA that values privacy (their CEO aside) and at least some systems in place to al…

That is some really scary stuff in the link you gave!!! People need to realize that it's not worth the $0.25 off a can of green beans you get by using a loyalty card, if a sleazy merchant is going to swoop in at some vulnerable time in your life and help separate you from hundreds or thousands of your dollars.

If you're worried about it, get a loyalty card and provide fictitious information on the form. I've never been asked to provide any proof of identity to get a supermarket loyalty card.

Though if you use your loyalty card and then pay with a credit card I guess they could link back to the "real" you.

Re: Facebook’s Instant Personalization Is the Real Privacy Problem

#30
Years ago, when caller ID was becoming commonplace, a company (I think it was American Express) started answering customer calls by name--- "Hello Mr. Jones, how can we help you."

This proved to be very unpopular with customers and they stopped doing it... they probably still use the caller ID but don't let you know that they are.

Post reply on HN