Live data from Hacker News

Facebook Is Giving Advertisers Access To Your Shadow Contact Information

gizmodo.com

211–220 of 478 posts

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#211
post #180

Earlier quoted context omitted.

> Isn't this it though, the engineers designing the ad targeting system at Facebook is linking the random emails you use as "catch all" to your main identity so you can be targeted specifically even though neither party has full knowledge of the linkage between your catchall email and your main identity email. If you use the method described in the grandparent, you use a unique email address for every site (e.g site1…

This is no longer "just a little bit of effort and minimal cost" - most likely no one will use unique emails for every site as well as use private browsing mode permanently in order to avoid cross cookie / cross site contamination via 3rd party (non facebook) tracking. Which is cited as a "feature" - allowing clients to bring their own ad tracking database and integrating that into the FB one in order to make ad targ…

Lots of people do this, in the past it has exposed data leaks.

My if my site-specific email giqjtodvdksu@... has been getting spam lately then it is likely that either they sold it or they got hacked.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#212

Earlier quoted context omitted.

> The reason I never give fb my mobile Here's the issue with it. You might not give it but your friends would. Therefore, this strategy is pretty useless as network effects kick in.

TIP which I discovered by accident: create a bogus account with your phone number. Facebook will remove the phone number from your account when you do that. You can also use that to check who are your friend who gave FB your phone number.

this is an interesting idea but probably one already-implemented feature from being circumvented

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#213
post #180

Earlier quoted context omitted.

> Isn't this it though, the engineers designing the ad targeting system at Facebook is linking the random emails you use as "catch all" to your main identity so you can be targeted specifically even though neither party has full knowledge of the linkage between your catchall email and your main identity email. If you use the method described in the grandparent, you use a unique email address for every site (e.g site1…

It is completely possible to fingerprint a browser and then group all the email accounts used on it and treat them as a single user. When was the last time you lent your device to someone so they could check their email?

Google claims that multiple people checking their e-mail in the same browser is common enough that they had to redesign browser log-in around it.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#214

Inaccurate headline. Being targetable is different than them "giving access" to the information. The actual information is not shared with anyone.

Though you can probably gat at least an IP address, and if you create a nice looking fake e-shop with something your target may want, ... they may give you the rest.

Phishing ads on FB may be less obvious than sending them a phishing link over e-mail.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#215
post #102
post #77

Earlier quoted context omitted.

Everybody punts security issues from identification to the next guy. Eventually the only safeguard left between you and the bad guys is a minimum wage salesman working at the t-mobile counter. It's sad to know that all of your primary email addresses, with links to online shopping accounts with credit cards, bank accounts, etc, can all be accessed by spoofing your phone number.

I honestly wish sites would use client side certs or auth via a private key.

Client side certs mean now every user has a verifiable identity. Maybe you're OK with Facebook knowing your full ID, but is it also OK to tell Grindr, Redtube and Amazon?

Security Keys are better here. The security key can prove to a site that its the same one as before. "Before what?" Well that's up to the site. In most cases it's going to register one or more keys when you sign up to the site, and then check you still have one when logging in. This is completely useless for everything except the one thing it's intended for, a Second Factor during login.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#217

Earlier quoted context omitted.

Isn't this it though, the engineers designing the ad targeting system at Facebook is linking the random emails you use as "catch all" to your main identity so you can be targeted specifically even though neither party has full knowledge of the linkage between your catchall email and your main identity email. This is facilitated by information that is not under your control. If facebook was able to design and build th…

Check the TOS and/or implementations for many of the tracking providers and you’ll see they use hashed emails. Show me a way to extract the common domain name from the below: 9425ca8eb02d022309ec175a7067b1567a5f741ec7010cc1b5034287f9db6e2f 4d1c86b9f418c713e784760fea809e34418c2f13e993d907783572ecc2c9bb6e

If the hashing algorithm is known (and my guess is it is at least possible to reverse engineer it, if it isn't documrnted) then cracking a hash with a GPU may be quite feasible.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#218
post #169

Earlier quoted context omitted.

> just as my email addresses have That doesn’t need to be the case though with just a little bit of effort and minimal cost. Use your own domain for email and set your account to be a catchall. Then use facebook.com@yourdomain.tld and your email address is no longer a cross site unique identifier.

>Then use facebook.com@yourdomain.tld and your email address is no longer a cross site unique identifier. unless sites smarten up and realize facebook@johndoe.com is the same person as pizzaplace@johndoe.com, especially when johndoe.com isn't a "common" email domain like hotmail.com

As someone that has created a facebook account with an unused email without using my name or any information they still recommend my friends, family and interests. Instagram did the same thing with my interests.

There's a lot more going on than linking email addresses.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#219
post #211

Earlier quoted context omitted.

This is no longer "just a little bit of effort and minimal cost" - most likely no one will use unique emails for every site as well as use private browsing mode permanently in order to avoid cross cookie / cross site contamination via 3rd party (non facebook) tracking. Which is cited as a "feature" - allowing clients to bring their own ad tracking database and integrating that into the FB one in order to make ad targ…

Lots of people do this, in the past it has exposed data leaks. My if my site-specific email giqjtodvdksu@... has been getting spam lately then it is likely that either they sold it or they got hacked.

>Lots of people do this...

You mean a very small percentage of FB users do this?

The point being as parent comment said it’s not “a little effort and minimal cost”. Figure a $10-15 overhead cost for the domain and maybe $5/month/e-mail account? Effectively to minimize tracking on Facebook one would have to spend a minimum of $70/year?

It doesn’t seem like a great solution...go with a “free product” like Facebook in exchange allowing them to collect and monetize your data, only to pay to combat their business model? May as well offer a competing service that doesn’t track you, collect/monetize your data and pay say...half the cost of a domain and email.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#220

People of multiple platforms dislike me for discrediting facebook. Simply talking about facts and what they could expect. They think they know it all. Some corps are good some are evil. People tend to forget that an evil person could also be your most trusted and reliable one. I work as a cyber security engineer and the things i have see flying by are crazy. The fact that information is sold without you4 knowledge is…

What can we do about it? I realize this is probably not answerable in this thread but I find myself asking this question more frequently lately and I still cannot answer it.

would be happy to see this discussion split into an Ask HN: or other, I think this topic should be debated quite a bit more than it is with the goal of attaining real results on fixing these issues.

Post reply on HN