Live data from Hacker News

Facebook Is Giving Advertisers Access To Your Shadow Contact Information

gizmodo.com

171–180 of 478 posts

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#171
post #17

As a security engineer, I cannot overstate just how horrible this is. Phone numbers might not be an ideal 2nd factor for authentication, but to punish users for setting up 2FA by using the provided phone number for ad targetting is incredibly unethical.

It's also something that people should have expected. I don't understand how people have not noticed that all of the major sites that generate revenue through user profiling and advertising have been pushing hard for users to either be obligated to register using their phone, or to setup a two factor authentication using their phone when it's not necessary for registration.

The reason I say it's something people should have expected is because if people were more critical of the things asked of them, then things like this would never get off the ground. Instead, because people do not seem inclined to naturally believe that corporations might have ulterior motives, such practice has become common place and on some sites even mandatory.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#172
post #90

Earlier quoted context omitted.

Most internet service companies, including Facebook and Google, don't give you the option of paying for privacy even if you wanted to.

I think that if it's possible to define a way of operating businesses in a way that doesn't harvest data in a way that's nonessential to the services, then there should be a law requiring this option: to pay out of your pocket directly the amount of revenue the company would have expected to make, in exchange for the company not doing this data collection. But it seems difficult to get to such a definition. I think t…

Indirectly GDPR does this. All data collection must be either opt in, or necessary to provide the service.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#173
post #140

Google has been pushing SMS 2FA a little more aggressively over the past couple of years, too. And I think Apple made it "easier to use SMS 2FA" in iOS 12 for the same reason. I also said before that this is exactly why Facebook wanted to "verify people's faces for security purposes", too. It just seemed so obvious to me that Facebook would use security as an excuse to get people to put their own 100% accurate face s…

> And I think Apple made it "easier to use SMS 2FA" in iOS 12 for the same reason. Wait. You think Apple is selling your phone number to advertisers?

Information and data is the modern day 'gold'. There's much more value to tying an account to something that with negligible doubt identifies them than just selling it to advertisers. It lets you create sophisticated models and track and model users' behavior across services, and even outside the digital domain.

There are also extrinsic benefits outside advertising. Apple, for instance, is also a member of PRISM and one can only imagine how many other surveillance programs across the world that remain classified. Companies are undoubtedly 'compensated' for their involvement in these programs, and the more information they have and can gain - the more valuable their participation would be seen as.

This conflict of interest is why I think we will never see any sort of significant guarantee of privacy at the federal level in the US. The more information companies obtain, the more information the government has access to.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#174
post #169

Earlier quoted context omitted.

> just as my email addresses have That doesn’t need to be the case though with just a little bit of effort and minimal cost. Use your own domain for email and set your account to be a catchall. Then use facebook.com@yourdomain.tld and your email address is no longer a cross site unique identifier.

>Then use facebook.com@yourdomain.tld and your email address is no longer a cross site unique identifier. unless sites smarten up and realize facebook@johndoe.com is the same person as pizzaplace@johndoe.com, especially when johndoe.com isn't a "common" email domain like hotmail.com

Most marketing companies don’t share raw email addresses (rather md5/sha1/sha256 hashes of the emails). In that scenario, linking the common domain name is very difficult to near impossible to do currently.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#175
post #21

Another personal observation. I have an Instagram account that I thought was fully incognito. I never connected it to any other social account, I used a separate email for authentication etc. Just days after the Instagram founders left Facebook I started receiving friend suggestion on my IG that were very very relevant. Those were people I knew in real life and mostly connected via Facebook but not only. I shouldn't…

This is a perfect example of the need for physical comparmentation. Separate devices never connected through the same internet service. As far as devices go, to think you have separated “anything” on only one device, you’re living in fantasyland.

If the app can look at your wireless, even that is not enough. It can just make a map of the SSID/BSSID around you.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#176

Earlier quoted context omitted.

> just as my email addresses have That doesn’t need to be the case though with just a little bit of effort and minimal cost. Use your own domain for email and set your account to be a catchall. Then use facebook.com@yourdomain.tld and your email address is no longer a cross site unique identifier.

Isn't this it though, the engineers designing the ad targeting system at Facebook is linking the random emails you use as "catch all" to your main identity so you can be targeted specifically even though neither party has full knowledge of the linkage between your catchall email and your main identity email. This is facilitated by information that is not under your control. If facebook was able to design and build th…

Check the TOS and/or implementations for many of the tracking providers and you’ll see they use hashed emails. Show me a way to extract the common domain name from the below:

9425ca8eb02d022309ec175a7067b1567a5f741ec7010cc1b5034287f9db6e2f

4d1c86b9f418c713e784760fea809e34418c2f13e993d907783572ecc2c9bb6e

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#177
post #69

Earlier quoted context omitted.

This is basically how FBI Director Comey's secret Instagram account (and thus Twitter account) was unmasked. But it was even worse - you are suggested to 3rd party people who just follow the people who know you: https://gizmodo.com/this-is-almost-certainly-james-comey-s-t...

Yep, something similar I discovered recently that if you sign up to Instagram with somebody's email that they use on Facebook then within a day or two you'll start to see all of their friends from Facebook whom are also on Instagram in your recommended follows. All of this happens without email verification..

Yep, I have a relatively common name and @gmail.com address. Last week, some guy with my name signed up for Instagram with my email adddress and started posting without ever verifying his email.

I reset his password and tried to close the account after he kept trying to access it by resetting his password again. Instagram support asked me to send a clear photo of myself holding up some random number to prove it was me. Nope lol.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#178

Earlier quoted context omitted.

I agree with your sentiment. But, as someone who understands that not all people and companies use the same moral set as myself, this is why I've never set up 2fa using a phone. Why should I give some company my phone number? Increasingly it's become a single point of metadata to uniquely describe myself (just as my email addresses have).

> just as my email addresses have That doesn’t need to be the case though with just a little bit of effort and minimal cost. Use your own domain for email and set your account to be a catchall. Then use facebook.com@yourdomain.tld and your email address is no longer a cross site unique identifier.

You can do it with Gmail to some extent already. E.g. instead of using myemail@gmail.com I would use myemail+facebook@gmail.com. Gmail ignores anything after the plus. As someone mentioned, marketing companies usually share just the hash of email. The trick is not too popular and I didn't experience a company handling it yet.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#179

Earlier quoted context omitted.

I think that if it's possible to define a way of operating businesses in a way that doesn't harvest data in a way that's nonessential to the services, then there should be a law requiring this option: to pay out of your pocket directly the amount of revenue the company would have expected to make, in exchange for the company not doing this data collection. But it seems difficult to get to such a definition. I think t…

Indirectly GDPR does this. All data collection must be either opt in, or necessary to provide the service.

Oh, I forgot an important detail. I should have added another aim I would want is that as a result of paying this money, you wouldn't receive any advertisements from the service.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#180

Earlier quoted context omitted.

> just as my email addresses have That doesn’t need to be the case though with just a little bit of effort and minimal cost. Use your own domain for email and set your account to be a catchall. Then use facebook.com@yourdomain.tld and your email address is no longer a cross site unique identifier.

Isn't this it though, the engineers designing the ad targeting system at Facebook is linking the random emails you use as "catch all" to your main identity so you can be targeted specifically even though neither party has full knowledge of the linkage between your catchall email and your main identity email. This is facilitated by information that is not under your control. If facebook was able to design and build th…

> Isn't this it though, the engineers designing the ad targeting system at Facebook is linking the random emails you use as "catch all" to your main identity so you can be targeted specifically even though neither party has full knowledge of the linkage between your catchall email and your main identity email.

If you use the method described in the grandparent, you use a unique email address for every site (e.g site1@yourdomain.tld, site2@yourdomain.tld, etc). The domain will be the common part, which would be very hard for a company to use because most domains are shared between many separate users.

Post reply on HN