Live data from Hacker News

Facebook can track your browsing even after you've logged out, judge says

theguardian.com

121–130 of 208 posts

Re: Facebook can track your browsing even after you've logged out, judge says

#121

If you delete the Facebook cookie (i.e. are completely logged out including username), then click on a link in an email notification from Facebook, it will silently log you in again, restoring the cookie and web-wide tracking. This can be tested by pasting an email notification link to a new private browsing window.

So, they're spewing login credentials all throughout users' emails? How is their security team okay with this?

Do they require that it be from a previously used IP/user-agent or something?

Re: Facebook can track your browsing even after you've logged out, judge says

#122
post #19

Earlier quoted context omitted.

And why not? It would forbid a lot of outdoor photography if I couldn't accidentally catch a photo of someone in their house. Google Street view would be gone.

not necessarily, they would be forced anonymize faces.

Like Google Street View already does.

Re: Facebook can track your browsing even after you've logged out, judge says

#123

Earlier quoted context omitted.

> When I open a new private window, I'm logged in as well. Not in firefox, or, at least not for me.

It depends on whether all private windows have been closed. If you open a new private window when another is already open, you remain logged into sites. If you close all your private windows and then open another, it's a clean slate. (At least for me.)

I can see why they do this but it is actually not what I expected. I'd expect all windows to have their own set of cookies and credentials and for all tabs associated with a window to share them.

Re: Facebook can track your browsing even after you've logged out, judge says

#124

Earlier quoted context omitted.

I use the Tor browser for just Facebook. Stymies IP tracking, and I expect it to do more of the right things to deal with fingerprinting too. Plus it's super slow, encouraging me to not spend too much time on Facebook...

Why not just quit Facebook?

It's necessary for event planning, at least in my social circles.

For everything else, there's email, sms, and a half dozen other social networks.

Re: Facebook can track your browsing even after you've logged out, judge says

#125
Wouldn't something like Pi-Hole be a good network-wide way to manage this tracking? I know plugins are convenient but they all have to intercept and modify css/etc coming in on the fly which can lead to slower page loads. Plus I'd imagine some of those plugins will allow certain domains through regardless?

Or are the sneakier ways sites track users something that can get by the OOTB settings?

Re: Facebook can track your browsing even after you've logged out, judge says

#126
post #99
post #89

Earlier quoted context omitted.

I've been tempted to write something that goes a bit further. I'd like traffic to each site to be routed through proxies with different IP addresses. (Perhaps even to the point where my devices are automatically managing a set of nodes or Lambdas on AWS.) Along with that, it will still be necessary to fix some browser information leaks that could be used for fingerprinting If someone is tempted to beat me to it, go f…

Thats going to break so many websites for you ... Pretty much any service that uses server side sessions across domains. Downloads are often whitelisted to a session, which get invalidated on ip changes.

For exactly those sorts of reasons, I don't expect to apply such a system universally any time soon. In practice I suspect it will only make sense to employ it with a modest number of problematic domains. Currently I use uBlock with javascript defaulting to disabled, manage cookies and local storage, disable referrer headers, etc., but there are still some huge privacy leaks.

On the other hand, it might be possible to devise a solution that works generally but employs white lists or other exceptions for sites that need certain IP-address behavior. That would take a fair amount of effort, but the approach has worked well in similar contexts, such as ad blockers.

Re: Facebook can track your browsing even after you've logged out, judge says

#128
post #89
post #15

Firefox has a pretty neat feature I discovered recently: https://wiki.mozilla.org/Security/Contextual_Identity_Projec... It lets you run multiple sessions in one window, where each tab belongs to a specific session with separated cookies and such. I've got a bunch of tabs where I'm logged in to Facebook, another set where I'm logged in to Google and the rest of them where I'm not logged in to either. Of course they c…

I've been tempted to write something that goes a bit further. I'd like traffic to each site to be routed through proxies with different IP addresses. (Perhaps even to the point where my devices are automatically managing a set of nodes or Lambdas on AWS.) Along with that, it will still be necessary to fix some browser information leaks that could be used for fingerprinting If someone is tempted to beat me to it, go f…

Did you just described tor?

Re: Facebook can track your browsing even after you've logged out, judge says

#129
post #121

If you delete the Facebook cookie (i.e. are completely logged out including username), then click on a link in an email notification from Facebook, it will silently log you in again, restoring the cookie and web-wide tracking. This can be tested by pasting an email notification link to a new private browsing window.

So, they're spewing login credentials all throughout users' emails? How is their security team okay with this? Do they require that it be from a previously used IP/user-agent or something?

Works with a VPN, so not linked to IP. URL includes email used for FB auth.

Edit: received FB email about "login from unknown device".

Re: Facebook can track your browsing even after you've logged out, judge says

#130
post #66

Nice, if i don't lock my door, its my fault they steal my things.

> Nice, if i don't lock my door, its my fault they steal my things. In many, if not most European countries you can get a ticket for not protecting your vehicle. If you leave your car unlocked and someone steals it, it's your fault. Police if have to investigate it etc, but they also give you a ticket, because it not thoughtlessness, they wouldn't have to do it.

> If you leave your car unlocked and someone steals it, it's your fault.

Getting a ticket for that does not mean the theft gets blamed solely on the owner so that the thief is not even considered committing a crime. It's just the owner may have violated a law, too. How about you a.) quote those laws, and even assuming you are correct in how you put it, show how b.) one instance of victim blaming would justify another. To me that's like drinking a second bottle of bleach because you already downed one. That runs so much counter my own intuition I'm kind of intrigued.

Post reply on HN