Live data from Hacker News

Why is there a TikTok tracking pixel on UberEats what is this crap?

user-images.githubusercontent.com

221–230 of 232 posts

Re: Why is there a TikTok tracking pixel on UberEats what is this crap?

#221
post #182
post #128

Earlier quoted context omitted.

If they know how their campaigns are doing -> they can target better and earn more money and in turn give you more discounts. So it’s just good karma to let them run the tiny js script which does no more harm than 100 other services running on your machine, which you never used either.

> they can target better I don't want to be targetted. > So it’s just good karma to let them run ... No. It's my machine, not theirs, they don't get to use it to track me. Not one single cycle. It certainly isn't "good karma" to allow advertisers free reign like that, it's letting the fox loose in the hen-house.

As I replied in the other comment, if you don’t want to be targeted or a single cycle of your machine to be used by developers, don’t open their website. no more foxes in the house :)

Re: Why is there a TikTok tracking pixel on UberEats what is this crap?

#222
post #209
post #13

As someone that has spent a sizable amount of my career in ad products, the outrage here is kind of (sadly) funny. A conversion pixel? Hah, if you only had an idea of what the Facebook data faucet looked like in 2007-2017, your hairs would stand. Pretty sure they were breaking all kinds of PII laws.

> if you only had an idea of what the Facebook data faucet looked like in 2007-2017, your hairs would stand. I'm pretty sure everyone of technical aptitude knew Facebook's data faucet. But maybe I missed something. As far as I know, Facebook: a) Had all the freely provided data, PII/likes/social graph/etc. b) On Facebook's site or mobile app, the were fingerprinting your device, examining your scrolling/mouse/clickin…

This is an excellent summary.

I don't think you missed anything substantial... but I'll add two extensions:

(1) Social graphs change slowly. And they still own Instagram, so for many users they have a live social graph still.

(2) Facebook Pixel is dead. Long live Facebook Pixel!

The Facebook Pixel is now (or at least nearing) effectively dead on modern up-to-date devices running ad blockers. Of course that leaves plenty of desktop machines where people aren't running ad blockers.

But more importantly, Facebook has acknowledged the elephant in the room and moved from client side to server side with Conversions API (CAPI) (aka the new "Facebook Pixel"). And there's nothing ad blockers can do about server-side analytics...

Re: Why is there a TikTok tracking pixel on UberEats what is this crap?

#223
post #209

Earlier quoted context omitted.

> if you only had an idea of what the Facebook data faucet looked like in 2007-2017, your hairs would stand. I'm pretty sure everyone of technical aptitude knew Facebook's data faucet. But maybe I missed something. As far as I know, Facebook: a) Had all the freely provided data, PII/likes/social graph/etc. b) On Facebook's site or mobile app, the were fingerprinting your device, examining your scrolling/mouse/clickin…

This is an excellent summary. I don't think you missed anything substantial... but I'll add two extensions: (1) Social graphs change slowly. And they still own Instagram, so for many users they have a live social graph still. (2) Facebook Pixel is dead. Long live Facebook Pixel! The Facebook Pixel is now (or at least nearing) effectively dead on modern up-to-date devices running ad blockers . Of course that leaves pl…

I left out Facebook Login. That may be a help as well, although I don't think they get much from that they don't get from the other integrations in mobile apps/websites already.

Re: Why is there a TikTok tracking pixel on UberEats what is this crap?

#224

Earlier quoted context omitted.

This comment adds little more than name calling. Can ads be annoying? Yes. So is paying money for the things you enjoy. Very few online businesses have been able to find a business model that does not amount to selling ads or selling links. Some people find ads more intrusive than others but personally I find paywalls to be much more of a nuisance than seeing a banner ad. If free as in beer comes at the cost of heari…

Ads aren't just annoying, they're often malicious and downright dangerous. Linking to apps with 0 click subscriptions, illegal porn or with recurring card payments and banking trojans. God forbid you're in the crypto space, every fucking ad is a scam or malicious, people lose their whole life savings to scams pushed through Google ads every day and there is no easy way to stop them. I run an ad blocker because Google…

That's a lot of words, and I'm sure the pain you feel and need for Google to maintain a registry of crypto ads you find acceptable is real. But, an excuse is an excuse.

Re: Why is there a TikTok tracking pixel on UberEats what is this crap?

#225
post #221
post #182

Earlier quoted context omitted.

> they can target better I don't want to be targetted. > So it’s just good karma to let them run ... No. It's my machine, not theirs, they don't get to use it to track me. Not one single cycle. It certainly isn't "good karma" to allow advertisers free reign like that, it's letting the fox loose in the hen-house.

As I replied in the other comment, if you don’t want to be targeted or a single cycle of your machine to be used by developers, don’t open their website. no more foxes in the house :)

Not sure I see a reply to another comment of mine!

>> Don't open their website

Sure, or just don't allow them to load these things.

Honestly I'm moving in the direction of not visiting. Instead of a useless do-not-track header, I'd much rather send a "will-not-render" header. I'd be quite happy to tell your server that under no circumstances will my browser be participating in tracking or even rendering your ads. If you'd rather not serve me the page at that point then cool, lets go our separate ways.

I imagine a company like uber eats, who I am actually trying to pay when I visit their site, might still like to serve me the page. Ad-supported content less so.

Re: Why is there a TikTok tracking pixel on UberEats what is this crap?

#227

Earlier quoted context omitted.

The solution to this is simple though by no means easy: treat ones digital data as private property.

I don’t see why that would solve the issue. your browser is communicating with facebook’s servers, so if they log your communication it’s not exactly a violation of your private property rights

In principle, sending your data in a way that's decipherable to the backend isn't in principle required. WhatsApp encrypts (or at least used to, not sure about now) messages.

And no doubt it's not compatible with their current business model. Which is the point, it's a model that exploits property that isn't theirs for unfair gain.

Re: Why is there a TikTok tracking pixel on UberEats what is this crap?

#228

Earlier quoted context omitted.

Any developer can still send almost any data they want into FB to track basically anything. 'offline conversion' still allows you to send in names, age, bday, gender, etc for matching, IP, UA. Though now it's hashed before going to FB. And you can pass almost whatever custom data you want in. So I can in my industry optimize for a long term political donor, or potentially an early vote. Or someone accidentally sends…

> Though now it's hashed before going to FB. It is however an easily-reversible hash, by design as that's how FB can correlate between the different datasets. When it comes to finite sets such as phone numbers or dates of birth it's also trivial to search the entire space by bruteforce.

IIRC it's sha256. Is that really reversible now?

For sure on a rainbow table for something like cell phone. but i don't know why that would matter? Anyone can generate all the possible phone numbers.

The whole point is that it is matchable. Like if they already have my email then they know if it's a match, but if they don't have my email they don't know what the missing email is.

Like what's my email from this (without knowing my email) below: 2c03e4a168bed89f5208250cdefbe97d4d87ba7812df896311676acc2ddfcdb4

Re: Why is there a TikTok tracking pixel on UberEats what is this crap?

#229

Earlier quoted context omitted.

I used to tell people if they know how ad tech worked it would be banned tomorrow. I doubt it's on FB during that period though? I would guess though that a bunch of health tech sent (perhaps accidentally just not understanding) a bunch of patient data though. Seems they are the responsible party. There's been other examples beyond FB of 'auto track' too. devs just don't know or forget to turn it off. Not to mention…

> I would guess though that a bunch of health tech sent I worked for a "healthtech" company in London at the beginning of the pandemic. They had the Facebook SDK malware embedded in the app that people were supposed to use for GP consultations. I don't believe any explicit health data was sent (there was no intent to do so, and I’m not sure if that would even be possible), but merely the fact that I'm talking to a do…

I don't know as much about the app SDK, but from the pixel it used to auto detect things like form fill ins, clicks, url params, urls etc. So there is potential it incidentally collected something bad!

Re: Why is there a TikTok tracking pixel on UberEats what is this crap?

#230

Earlier quoted context omitted.

> Though now it's hashed before going to FB. It is however an easily-reversible hash, by design as that's how FB can correlate between the different datasets. When it comes to finite sets such as phone numbers or dates of birth it's also trivial to search the entire space by bruteforce.

IIRC it's sha256. Is that really reversible now? For sure on a rainbow table for something like cell phone. but i don't know why that would matter? Anyone can generate all the possible phone numbers. The whole point is that it is matchable. Like if they already have my email then they know if it's a match, but if they don't have my email they don't know what the missing email is. Like what's my email from this (witho…

Depends, for DOB and phone numbers the search space is finite and very small for a modern computer (especially so for a big tech adversary having access to near-infinite computing power) so you can just enumerate all the possibilities.

Names and emails can be bruteforced with various lists from existing data breaches or data brokers and you'll probably reverse 80% of them.

However reversing them is not even necessary - an adversary like Facebook can infer it based on other data, for example, let's say they know your phone number but not your email - now you buy/sign up to vendors providing both that phone number and email and they provide it to Facebook - now Facebook knows that you signed up to those vendors with your number (as they have the plain text value, can hash it on their side and compare), but they also see that there's a mysterious email hash - they don't know its plaintext value, but it perfectly matches the same vendors that have your phone number. They can infer that it's probably your email address, and while they still don't know what it is, they can use the hashed value to track you across other vendors without ever having to know the plaintext value.

Post reply on HN