I said this yesterday on the original discussion. http://news.ycombinator.com/item?id=3033475 Good that you ran with it, though, and illustrated the point. Perhaps a better headline would have been "Facebook is still tracking you across the web even after you log out", though. Generally it's only hackers that know what "enough" means in this context, and Facebook's market is, as we all know, much much bigger than us.
not that I want to turn this into a pissing contest, but I emailed this to them on the 14th of November 2010. I emailed them again on the 12th of January this year. I have been sitting on it for that long. I updated my post to make that clear, that this is an issue that is almost a year old.
Logging out of Facbook is not enough
31–40 of 126 posts
Re: Logging out of Facbook is not enough
#32I can recommend this setup for any Mac users willing to spend $5 for Fluid. Alternatively you could probably rig up a 'Facebook' script to launch Chrome with a separate profile to achieve the same results.
Re: Logging out of Facbook is not enough
#33Re: Logging out of Facbook is not enough
#34I've deleted all Facebook cookies from Chrome and Safari, and now I use Facebook exclusively with a Fluid.app SSB with private cookie storage. I can recommend this setup for any Mac users willing to spend $5 for Fluid. Alternatively you could probably rig up a 'Facebook' script to launch Chrome with a separate profile to achieve the same results.
Re: Logging out of Facbook is not enough
#35> The entire process was so flaky and frustrating that I haven't bothered sending them two XSS holes that I have also found in the past year. You realise you're hurting innocent users much more than Facebook itself by not reporting them, right?
No one is "honor-bound" to report vulnerabilities; in fact, it seems unethical to expect any random person to try to fix any random problem they stumble upon, don't you think?
My philosophy: it's backwards to look down on those who don't report vulnerabilities; it's better to be pleasantly surprised when someone does.
But he's certainly not "hurting" anyone at all. He didn't disclose any details of the attacks.
Re: Logging out of Facbook is not enough
#36Why should any cookie last more than 30 minutes anyway in this day and age? Make all cookies session cookies. Also disable third-party-cookies entirely.
Re: Logging out of Facbook is not enough
#37I haven't looked, but I would bet any money that Google does the exact same thing, too.
Re: Logging out of Facbook is not enough
#38In Chrome 15 there's a flag (in about:flags) to disable third-party cookies from being read: Block all third-party cookies. When the option to block third-party cookies from being set is enabled, also block third-party cookies from being read. (Don't forget to activate blocking in Preferences > Under The Hood > Content Settings... > Cookies.)
But then some sites stop working, like Twitter and even some parts of Google :(
I routinely run with only direct cookies permitted (no third party ones) and with all cookies except those I have explicitly whitelisted being deleted each time my browser is closed.
I am not aware of any problem this has caused me for a long time, including on the sites you mentioned. Maybe there is some useful feature I'm not seeing at all because of the cookie restrictions I impose, but maybe they've just got better over time at not relying on cookies for things they shouldn't?
Re: Logging out of Facbook is not enough
#39Earlier quoted context omitted.
not that I want to turn this into a pissing contest, but I emailed this to them on the 14th of November 2010. I emailed them again on the 12th of January this year. I have been sitting on it for that long. I updated my post to make that clear, that this is an issue that is almost a year old.
You are not going to hear back from Facebook because they will not believe this is an "issue".
Re: Logging out of Facbook is not enough
#40Even after deleting FB cookies, what prevents them from tracking you (with reasonably good accuracy) using your IP address. In that case, you might as well just blacklist all of facebook.com. In my opinion, internet users must be aware that there is no easy way to be totally anonymous, whether it be Facebook, Google, etc. If you require complete anonymity, you might as well unplug your internet cable.
Or, indeed, using your combination of locale, useragent, etc. These are often unique. You can test yours here: http://panopticlick.eff.org/