Live data from Hacker News

Sexual abuse tip-off site could be sharing data with Facebook

sverigesradio.se

31–40 of 62 posts

Re: Sexual abuse tip-off site could be sharing data with Facebook

#31

They (Swedish Radio) have done a few stories on Facebook pixel during the last year. A year ago it was the state-owned pharmacy Apoteket that leaked customer information and their orders to Facebook. Once it was revealed that multiple pharmacies did it, an investigation into three of them was started. Last month SR extended their search and found 100 pharmacies in Europe doing the same thing. Leaking information to F…

People just don't understand how valuable data is.

For example, Sweden has a Facebook Market competitor that uses Facebook _and_ Google for analytics. Now we know for a fact that Amazon has in past used AWS to spy on b&m and e-commerce competitors, i dont belive for a minute that Meta would be any better.

Re: Sexual abuse tip-off site could be sharing data with Facebook

#32
post #9

Earlier quoted context omitted.

Subresource Integrity fixes that: "hmm, must be a bug at Google's end"

It really doesn’t fix it, since the whole point of GTM is to allow arbitrary code execution on any page by marketing teams. (Yes, this is as bad of an idea as it sounds)

You just don't allow GTM, citing a security and GDPR risk

Re: Sexual abuse tip-off site could be sharing data with Facebook

#34

They (Swedish Radio) have done a few stories on Facebook pixel during the last year. A year ago it was the state-owned pharmacy Apoteket that leaked customer information and their orders to Facebook. Once it was revealed that multiple pharmacies did it, an investigation into three of them was started. Last month SR extended their search and found 100 pharmacies in Europe doing the same thing. Leaking information to F…

People just don't understand how valuable data is. For example, Sweden has a Facebook Market competitor that uses Facebook _and_ Google for analytics. Now we know for a fact that Amazon has in past used AWS to spy on b&m and e-commerce competitors, i dont belive for a minute that Meta would be any better.

Got a link for the Amazon/AWS spying?

Re: Sexual abuse tip-off site could be sharing data with Facebook

#35
post #32

Earlier quoted context omitted.

It really doesn’t fix it, since the whole point of GTM is to allow arbitrary code execution on any page by marketing teams. (Yes, this is as bad of an idea as it sounds)

You just don't allow GTM, citing a security and GDPR risk

More like GDPR violation thanks to Schrems II.

Re: Sexual abuse tip-off site could be sharing data with Facebook

#36

Earlier quoted context omitted.

Something is off here. When PII data is shared with Facebook, it gets hashed before it gets sent. In fact, Facebook warns you if you are “leaking” PII in places like URL parameters that get picked up by their tracking pixel. If they discover pageview events with PII in them, they throw them out. I’m not justifying that hashed data is okay… but clear text data is not received or stored by Facebook via a Facebook Pixel…

If facebook had the clear or hashed data anywhere else you’re still leaking it just with extra steps. Hashes don’t by themselves anonymize. If you have access to the original data it’s trivial to recompute the hash and build your association that way. You could assume the data is salted but that’s not always a safe assumption.

[deleted]

Re: Sexual abuse tip-off site could be sharing data with Facebook

#37

Earlier quoted context omitted.

Poor supervision over something like Google Tag Manager resulting in someone on the PR team adding extra stuff without being fully aware of the repercussions

The way I could imagine it happens is that they use GTM to trigger Facebook tags, for example to remarket people who have donated to ECPAT, since people who donate are likely to do so again after say a month or during Christmas so that's a perfect audience to have available for an ad campaign. But they have GTM fire FB on every single page out of convenience, since setting up rules in GTM on where to trigger it is wo…

Not 100% on this but if they aren't granted sufficient GTM access and the site is an SPA devs may not even have access of where to trigger it beyond blocking instantiation on certain pages.

Re: Sexual abuse tip-off site could be sharing data with Facebook

#38
post #18
post #14

If you have a website where privacy is absolutely essential, you should NEVER include any third party content. I find it unfathomable someone needs to say that.

Case study: I help run a site that has resources for trans and LGBT people. With a question as sensitive and personal as “am I transgender or not and how would I know,” it’s deeply important to me that visiting my website won’t accidentally get my users into trouble, even indirectly through tracking or federated cohort ad targeting. - The only JavaScript is that which is necessary to run the site; - The site only lis…

[dead]

Re: Sexual abuse tip-off site could be sharing data with Facebook

#39

„Swedish Radio News reporters have tested the tip-form on ECPAT's website and found that their name, email and telephone numbers were shared with Facebook.“ How the hell does this just happen? Have people forgotten how to build simple forms and just use Facebook?

Something is off here. When PII data is shared with Facebook, it gets hashed before it gets sent. In fact, Facebook warns you if you are “leaking” PII in places like URL parameters that get picked up by their tracking pixel. If they discover pageview events with PII in them, they throw them out. I’m not justifying that hashed data is okay… but clear text data is not received or stored by Facebook via a Facebook Pixel…

As of a few years ago, this was not the case. The facebook conversion "pixel" would capture raw form data and upload it to facebook.

Re: Sexual abuse tip-off site could be sharing data with Facebook

#40
The only way to stop this from happening in the long term is to educate users that companies are spying on them, and tell them about the tools to prevent it.

Depending on site owners and spyware companies, like Facebook, to solve the problem is super naive, and will never solve it. They directly benefit from these "leaks," and so they have no motivation to prevent them.

Post reply on HN