Live data from Hacker News

Off-Facebook activity

facebook.com

81–90 of 395 posts

Re: Off-Facebook activity

#81
post #42

Hmm. I have no website activity listed - but seemingly every single Android game and a few other apps is sending "activity" to FB, despite me never using any feature to associate the two. This sounds like: https://privacyinternational.org/report/2647/how-apps-androi... Any sensible way of stopping this?

the Android advertising_id property and the ios IDFA (identifier for advertisers) are available to every app, and once an association against the id and your Facebook account is made further interactions can be attributed to your identity.

Both of these identifiers can be reset at any time via os features, making you appear as a new user (at least until fingerprinted or a new association with PII is made)

Re: Off-Facebook activity

#82
I am in Europe, so by law (GDPR) I have the right to make them delete all of this data.

How do I do so?

Also, I never consented to this being collected. How can their practice of collecting this type of data be GDPR compliant?

Re: Off-Facebook activity

#83
post #25

My off-facebook activity was empty. That's encouraging, because it looks like my countermeasures have been working: - Fingerprinting resistance in Firefox (privacy.resistFingerprinting = true) - First-party isolation in Firefox (privacy.firstparty.isolate = true) - Blocking third-party cookies in Firefox (network.cookie.cookieBehavior = 1) - Firefox container when I need to login to ad/tracking companies (Facebook, G…

Thanks for sharing BTW, how does PiHole help in regards to anonymity?

> how does PiHole help in regards to anonymity?

By blocking many advertisers tracking cookies (by blocking all access to those hosts via point the DNS result elsewhere) it reduces how far your information immediately spreads.

Far from massively effective because it does nothing to stop 1st party tracking and those 1st parties sharing further, or 3rd party cookies for new hosts not in the blocklists yet, but it can still help.

My use of PiHole isn't really an anonymity/tracking avoidance thing, my priorities in using it are avoiding ad network related annoyances like drive-by install attempts from less reputable (and/or hacked) networks, auto-playing audio, pop-ups/-unders, bandwidth waste (particularly from auto-playing video clips), occasional attempts to access microphone and/or camera, etc.

Re: Off-Facebook activity

#84
post #25

My off-facebook activity was empty. That's encouraging, because it looks like my countermeasures have been working: - Fingerprinting resistance in Firefox (privacy.resistFingerprinting = true) - First-party isolation in Firefox (privacy.firstparty.isolate = true) - Blocking third-party cookies in Firefox (network.cookie.cookieBehavior = 1) - Firefox container when I need to login to ad/tracking companies (Facebook, G…

Thanks for sharing BTW, how does PiHole help in regards to anonymity?

Block requests to all of FB's domains in the hope that it can't load FB's scripts or buttons or "like" buttons; literally anything from FB as far as humanly possible.

Re: Off-Facebook activity

#85
post #25

My off-facebook activity was empty. That's encouraging, because it looks like my countermeasures have been working: - Fingerprinting resistance in Firefox (privacy.resistFingerprinting = true) - First-party isolation in Firefox (privacy.firstparty.isolate = true) - Blocking third-party cookies in Firefox (network.cookie.cookieBehavior = 1) - Firefox container when I need to login to ad/tracking companies (Facebook, G…

Thanks for sharing BTW, how does PiHole help in regards to anonymity?

It allows you to block the domains of known third-party tracking companies. However, this measure is going to become less effective over time with the increasing usage of first-party tracking.

Re: Off-Facebook activity

#86
I apparently have no records of off-Facebook activity. This is probably because of blocking all 3rd-party cookies and enabling the blocking of social media trackers in both uBlock as well as that built into Firefox.

Re: Off-Facebook activity

#87
post #51

Earlier quoted context omitted.

I don't think they will tell you the whole truth. It's just like with Google history you can "delete". They have the data stored for the authorities anyway. They are required to do it by law (Patriot Act etc.)

> I don't think they will tell you the whole truth. This is true: >We receive more details and activity than what appears in your off-Facebook activity. For technical and accuracy reasons, we don’t show all the activity we’ve received. This includes things like information we’ve received when you’re not logged into Facebook, or when we can’t confirm that you’ve previously used Facebook on that device. We also don’t s…

Thanks for that link. Looks like the infamous "ghost profiles" are officially confirmed now.

I wish they would show the ghost profiles as well, but since it's not linked with 100% confidence they are probably not allowing it because it could be a privacy violation if it turns out that the link was incorrect (i.e. they showed a ghost profile to the wrong user).

Re: Off-Facebook activity

#88
post #72
post #8

A bit weird that my Monzo seems to be sending data to Facebook?

I have Monzo in my list too and downloaded the actual data. The only things listed are `ACTIVATE_APP` events. It doesn't seem to send any details to Facebook aside, from that you "activated" (opened) the app. Still not ideal, but not completely terrible.

When I used to have https://lua.xprivacy.eu/ it used to prompt me a lot, saying "This app is calling this API, do you want to allow or deny? (or allow/deny for 1 minute or 10 minutes). The Facebook app would query what packages/apps are installed on the Android phone.

Yeah, Android devs, why is that an accessible API call?

For one thing this is how FB could figure out how popular their competitors like WhatsApp, Instagram or Snapchat were, and why they bought them, or tried to.

Re: Off-Facebook activity

#89

Wow that's creepy. It lists apps where a) I didn't use FB login/signup and b) used a different email address to sign up. How do they cross-reference that to me? Hand how can I prevent that outside of their tools (which I assume still violate my privacy)?

By far the worst thing are android phone applications (not only FB official app). They have their spyware bundled and can slurp from you the data which are normally unaccessible by web browser, from phone number, imei, mail addresses to all your contacts and there is almost nothing you can do except installing vpn based firewall (like NetGuard) and block all access and add permissions one by one for each url. This should just be illegal.

Re: Off-Facebook activity

#90

One thing I'm not clear on - when I click on Coinbase (just one example) I see the following under 'What you can do'; - View coinbase.com - Turn off future activity from coinbase.com - Give feedback about this activity Does 'turn off' mean they won't share this information again, or that I won't be told about it again?

I believe the vague wording is intentional, so they can just stop displaying it to you, while continuing to collect the data. It's like how "delete account" works.
Post reply on HN