Live data from Hacker News

Facebook detects if you are logged in Gmail

webapps.stackexchange.com

41–50 of 98 posts

Re: Facebook detects if you are logged in Gmail

#41
post #35

Earlier quoted context omitted.

I have a Ubuntu virtual machine(VMware Player) for Facebook only. I don't see any sufficient reason to link all my online activity to my account.

That's a pretty solid way to handle security. I wonder if there's a way to make sure you're always booting from the same starting point so that nothing is persisted to the image between vm sessions.

Easy way is to just boot a live CD in a sandbox (virtualbox, vmware)..if your really concerned about security check out http://en.wikipedia.org/wiki/The_Amnesic_Incognito_Live_Syst...

Re: Facebook detects if you are logged in Gmail

#42
post #39
post #33

Earlier quoted context omitted.

>Not sure how they are doing this Did you happen to read the answers? Two specifically mention that Facebook requests authentication access (OpenID, I believe) the first time. It appears this user authorized Facebook at some point in the past and forgot about it. When I look at this page: https://accounts.google.com/b/0/IssuedAuthSubTokens I can see that at some point in the past, I allowed Facebook access to my Goog…

Did you happen to read the comments on the answers? > Nope it's not that unfortunately. I tried it myself removing all linked accounts. The event above still happens.

I was talking about this one: http://webapps.stackexchange.com/questions/20018/facebook-de...

"The OAuth tokens for Google are at https://accounts.google.com/b/0/IssuedAuthSubTokens (it's different from Linked Accounts).

When I tried it, Facebook created a popup with a OAuth prompt the first time and only briefly opened a blank popup on subsequent attempts. De-authorizing facebook makes the prompts appear again."

Unless they're talking about two different prompts?

Re: Facebook detects if you are logged in Gmail

#46
post #30

Not sure how they are doing this, but I have gotten tired of having to play “whack-a-mole” with FB scraping private information from my browser in other ways, so what I have done is sandboxed it: I have a separate “Facebook” account on OS X, and I assume that anything I do on that account is shared with Facebook. I don’t log into Facebook for any reason on my normal user account, and I don’t log into anything else on…

There's a comprehensive choice of browsers ( http://en.wikipedia.org/wiki/List_of_web_browsers ). I picked one that I knew I wouldn't need and dedicated it to my facebook usage.

That's a great idea. I think I'll do the same for my online banking.

Re: Facebook detects if you are logged in Gmail

#47
post #31

Earlier quoted context omitted.

being so afraid, what's the point of using it?

I can't speak for raganwald, but in my case there are people who refuse to communicate using anything else.

A bunch of organizations seem to be more consistent adding "Events" to their Facebook page than updating their website, also, so I need to periodically check if I don't want to miss things.

Re: Facebook detects if you are logged in Gmail

#48

Not sure how they are doing this, but I have gotten tired of having to play “whack-a-mole” with FB scraping private information from my browser in other ways, so what I have done is sandboxed it: I have a separate “Facebook” account on OS X, and I assume that anything I do on that account is shared with Facebook. I don’t log into Facebook for any reason on my normal user account, and I don’t log into anything else on…

I was browsing Facebook in Chromium in Mac OS when all of sudden, something started requesting Key Chain access for just just about every web site login I have stored. Coincidence? I have no idea what was going on, never happened before or since.

Re: Facebook detects if you are logged in Gmail

#50

So Facebook uses oauth to login with google, I don't get why this is worth 114 points..

IMHO, this does not seem to be related to OAuth. OAuth is three-leg authentication, and the service provider - Google in this case - will prompt the user to allow the consumer - facebook in this case - to allow an authentication attempt. Except of course the user has done the authentication in a previous attempt and facebook cached the token, but based on facebook's wording, because you are logged into your email account on this browser, does not seem to support this.
Post reply on HN