Live data from Hacker News

Logging out of Facbook is not enough

nikcub.appspot.com

31–40 of 126 posts

Re: Logging out of Facbook is not enough

#31
post #27
post #21

I said this yesterday on the original discussion. http://news.ycombinator.com/item?id=3033475 Good that you ran with it, though, and illustrated the point. Perhaps a better headline would have been "Facebook is still tracking you across the web even after you log out", though. Generally it's only hackers that know what "enough" means in this context, and Facebook's market is, as we all know, much much bigger than us.

not that I want to turn this into a pissing contest, but I emailed this to them on the 14th of November 2010. I emailed them again on the 12th of January this year. I have been sitting on it for that long. I updated my post to make that clear, that this is an issue that is almost a year old.

You are not going to hear back from Facebook because they will not believe this is an "issue".

Re: Logging out of Facbook is not enough

#32
I've deleted all Facebook cookies from Chrome and Safari, and now I use Facebook exclusively with a Fluid.app SSB with private cookie storage.

I can recommend this setup for any Mac users willing to spend $5 for Fluid. Alternatively you could probably rig up a 'Facebook' script to launch Chrome with a separate profile to achieve the same results.

Re: Logging out of Facbook is not enough

#34

I've deleted all Facebook cookies from Chrome and Safari, and now I use Facebook exclusively with a Fluid.app SSB with private cookie storage. I can recommend this setup for any Mac users willing to spend $5 for Fluid. Alternatively you could probably rig up a 'Facebook' script to launch Chrome with a separate profile to achieve the same results.

Thanks for the update, that Fluid now has private Cookie storage.

Re: Logging out of Facbook is not enough

#35

> The entire process was so flaky and frustrating that I haven't bothered sending them two XSS holes that I have also found in the past year. You realise you're hurting innocent users much more than Facebook itself by not reporting them, right?

It's not his duty to report such things.

No one is "honor-bound" to report vulnerabilities; in fact, it seems unethical to expect any random person to try to fix any random problem they stumble upon, don't you think?

My philosophy: it's backwards to look down on those who don't report vulnerabilities; it's better to be pleasantly surprised when someone does.

But he's certainly not "hurting" anyone at all. He didn't disclose any details of the attacks.

Re: Logging out of Facbook is not enough

#36
post #28

Why should any cookie last more than 30 minutes anyway in this day and age? Make all cookies session cookies. Also disable third-party-cookies entirely.

Many users would be annoyed to lose their persistent login. Disabling 3rd party cookies globally will break many sites that use 3rd party services and may be against the site's TOS as it would negatively impact their ad revenue.

Re: Logging out of Facbook is not enough

#37
post #23

I haven't looked, but I would bet any money that Google does the exact same thing, too.

This seems like a gross privacy violation to not honor the logout button, and continue to track the account ID of the user. I would be very surprised if Google were doing this too. And I would be surprised if Facebook were not hauled into court over this (at least in the EU if not in the US).

Re: Logging out of Facbook is not enough

#38
post #22
post #2

In Chrome 15 there's a flag (in about:flags) to disable third-party cookies from being read: Block all third-party cookies. When the option to block third-party cookies from being set is enabled, also block third-party cookies from being read. (Don't forget to activate blocking in Preferences > Under The Hood > Content Settings... > Cookies.)

But then some sites stop working, like Twitter and even some parts of Google :(

Could you elaborate?

I routinely run with only direct cookies permitted (no third party ones) and with all cookies except those I have explicitly whitelisted being deleted each time my browser is closed.

I am not aware of any problem this has caused me for a long time, including on the sites you mentioned. Maybe there is some useful feature I'm not seeing at all because of the cookie restrictions I impose, but maybe they've just got better over time at not relying on cookies for things they shouldn't?

Re: Logging out of Facbook is not enough

#39
post #27

Earlier quoted context omitted.

not that I want to turn this into a pissing contest, but I emailed this to them on the 14th of November 2010. I emailed them again on the 12th of January this year. I have been sitting on it for that long. I updated my post to make that clear, that this is an issue that is almost a year old.

You are not going to hear back from Facebook because they will not believe this is an "issue".

[deleted]

Re: Logging out of Facbook is not enough

#40
post #15

Even after deleting FB cookies, what prevents them from tracking you (with reasonably good accuracy) using your IP address. In that case, you might as well just blacklist all of facebook.com. In my opinion, internet users must be aware that there is no easy way to be totally anonymous, whether it be Facebook, Google, etc. If you require complete anonymity, you might as well unplug your internet cable.

Or, indeed, using your combination of locale, useragent, etc. These are often unique. You can test yours here: http://panopticlick.eff.org/

It is indeed sort of disturbing that panopticlick gives me the message "Your browser fingerprint appears to be unique among the 1,769,884 tested so far."
Post reply on HN