Live data from Hacker News

Facebook Bots Are Not Stealing Your Ad Spend

simplereach.com

11–20 of 30 posts

Re: Facebook Bots Are Not Stealing Your Ad Spend

#11
post #5

All the Facebook campaigns I have run use url parameter tagging to track clicks (i.e. for Google Analytics append &utm_source=facebook...) to the url. I think this is fairly standard practice so it seems unlikely to me that they'd have to use the referrer exclusively

I've checked a handfull of the facebook ads and I didn't find any querystring paramete attached.

Re: Facebook Bots Are Not Stealing Your Ad Spend

#12
post #6

> The first is that the traffic coming in had JavaScript disabled. If this was the case then the JavaScript analytics software would not detect the incoming traffic and therefore would not be able to log the result at all. Did you read their post? To quote: > Here's what we found: on about 80% of the clicks Facebook was charging us for, JavaScript wasn't on. And if the person clicking the ad doesn't have JavaScript,…

If this was the case then the JavaScript analytics software would not detect the incoming traffic and therefore would not be able to log the result at all.

Most Javascript analytics packages also wrap an image call in a noscript tag to capture hits for browsers which do not have JS enabled. So yes, you can log the result with JS turned off.

Re: Facebook Bots Are Not Stealing Your Ad Spend

#13
post #4
post #2

So this article is claiming that 80% of people clicking on Facebook ads have chosen to use https? Seems way too high to me.

Facebook has been strongly recommending people switch this on (a one-step process, prompted in your news feed) for over a year now. http://www.insidefacebook.com/2011/06/02/https-secure-browsi... I'd be surprised if the number was as low as 80%.

I've never received that prompt. If you read further down in that misleading article you linked to, you would see that they don't show the prompt to all their users:

> we're displaying this prompt when a user who has not enabled secure browsing (through the account settings option) manually changes their browser's address bar to https://, which does not fully protect their Facebook traffic.

I just had to go hunting through privacy and security settings for 5 minutes to figure out how to enable HTTPS.

So no, I would guess fewer than 0.1% of Facebook users have this enabled.

Re: Facebook Bots Are Not Stealing Your Ad Spend

#14
Here's another possibility that popped into my head while reading this article. What about browser prefetches? Is it possible that a browser, say Chrome, is prefetching linked pages and that prefetching is being detected by Facebook as an ad click?

I'll admit I know little to nothing about how prefetching works.

Re: Facebook Bots Are Not Stealing Your Ad Spend

#15
post #6

> The first is that the traffic coming in had JavaScript disabled. If this was the case then the JavaScript analytics software would not detect the incoming traffic and therefore would not be able to log the result at all. Did you read their post? To quote: > Here's what we found: on about 80% of the clicks Facebook was charging us for, JavaScript wasn't on. And if the person clicking the ad doesn't have JavaScript,…

If this was the case then the JavaScript analytics software would not detect the incoming traffic and therefore would not be able to log the result at all. Most Javascript analytics packages also wrap an image call in a noscript tag to capture hits for browsers which do not have JS enabled. So yes, you can log the result with JS turned off.

"wrap an image call in a noscript tag"

Although the author of the original post said nothing, i assume that's what they did.

Re: Facebook Bots Are Not Stealing Your Ad Spend

#16
post #8
post #3

I was hoping the article would be a little more informative and definitive according to the title. It is based on assumptions itself with a little theory behind it. As for the statement - "The first is that the traffic coming in had JavaScript disabled. If this was the case then the JavaScript analytics software would not detect the incoming traffic and therefore would not be able to log the result at all." You can t…

I can't believe someone who has 'delivered highly scalable solutions' actually managed to write this line on his blog with a straight face. How were you not able to deduce that the devs likely detected disabled javascript without the use of javascript? His whole post is devoid of content and nothing but statements without any real substance or evidence.

How do you reliably check that javascript is turned off without resorting to javascript?

edit: never mind; an img in a noscript tag.

Re: Facebook Bots Are Not Stealing Your Ad Spend

#17
post #6

> The first is that the traffic coming in had JavaScript disabled. If this was the case then the JavaScript analytics software would not detect the incoming traffic and therefore would not be able to log the result at all. Did you read their post? To quote: > Here's what we found: on about 80% of the clicks Facebook was charging us for, JavaScript wasn't on. And if the person clicking the ad doesn't have JavaScript,…

If this was the case then the JavaScript analytics software would not detect the incoming traffic and therefore would not be able to log the result at all. Most Javascript analytics packages also wrap an image call in a noscript tag to capture hits for browsers which do not have JS enabled. So yes, you can log the result with JS turned off.

You can also just look at the server logs. That's what most of us did before Google Analytics (and still do).

Re: Facebook Bots Are Not Stealing Your Ad Spend

#18
post #8
post #3

I was hoping the article would be a little more informative and definitive according to the title. It is based on assumptions itself with a little theory behind it. As for the statement - "The first is that the traffic coming in had JavaScript disabled. If this was the case then the JavaScript analytics software would not detect the incoming traffic and therefore would not be able to log the result at all." You can t…

I can't believe someone who has 'delivered highly scalable solutions' actually managed to write this line on his blog with a straight face. How were you not able to deduce that the devs likely detected disabled javascript without the use of javascript? His whole post is devoid of content and nothing but statements without any real substance or evidence.

The point of my article was not on how the dev was detecting JS. So I didn't want to go into detail on it. Even if he did that (which he never claims he does) He would only see that people are coming in with JS turned off, not that they came from facebook.

Re: Facebook Bots Are Not Stealing Your Ad Spend

#19
post #4

Earlier quoted context omitted.

Facebook has been strongly recommending people switch this on (a one-step process, prompted in your news feed) for over a year now. http://www.insidefacebook.com/2011/06/02/https-secure-browsi... I'd be surprised if the number was as low as 80%.

I've never received that prompt. If you read further down in that misleading article you linked to, you would see that they don't show the prompt to all their users: > we're displaying this prompt when a user who has not enabled secure browsing (through the account settings option) manually changes their browser's address bar to https:// , which does not fully protect their Facebook traffic. I just had to go hunting…

It's a year-old article. My company builds (among other things) Facebook apps and we definitely receive this alert these days on test accounts that are purely accessing via HTTP.

Re: Facebook Bots Are Not Stealing Your Ad Spend

#20
post #4
post #2

So this article is claiming that 80% of people clicking on Facebook ads have chosen to use https? Seems way too high to me.

Facebook has been strongly recommending people switch this on (a one-step process, prompted in your news feed) for over a year now. http://www.insidefacebook.com/2011/06/02/https-secure-browsi... I'd be surprised if the number was as low as 80%.

I tend to agree with the parent of this comment. Most people on facebook are clueless when it comes to even simple privacy fixes, and even the technorati have trouble tweaking things properly.

I thought the same thing as parent. It seems the poster is suggesting that tons of people are using https, and I can almost certainly say that just about everyone I know does not use that feature.

I believe the poster of that facebook post (Limited Run) said they would post their analytics details or something like that. I'd kind of like to see them, myself.

Post reply on HN