Live data from Hacker News

Facebook Defends Getting Data From Logged-Out Users

blogs.wsj.com

1–10 of 77 posts

Re: Facebook Defends Getting Data From Logged-Out Users

#2
I'd be interested to see how many competing social networks exhibit the same behavior. Specifically, Twitter and Google+ has similar social buttons.

Imagine I wanted to do this but not be get caught. What would you improve? Clearly the cookies will need to look different pre and post logout, but how different?

Re: Facebook Defends Getting Data From Logged-Out Users

#3
Bejar said Facebook is looking at ways to avoid sending the data altogether but that it will “take a while.”

Maybe I'm naive, but why would turning off the gathering of information take a while? This reminds me of unsubscribing to email newsletters, where the final goodbye says something like "you should stop receiving our emails within 6-8 weeks."

Re: Facebook Defends Getting Data From Logged-Out Users

#4

Bejar said Facebook is looking at ways to avoid sending the data altogether but that it will “take a while.” Maybe I'm naive, but why would turning off the gathering of information take a while? This reminds me of unsubscribing to email newsletters, where the final goodbye says something like "you should stop receiving our emails within 6-8 weeks."

I wonder if that involves something like collecting the data and storing it locally on your computer, then only sending the data once you log into facebook...

Re: Facebook Defends Getting Data From Logged-Out Users

#5
The company says the data is sent because of the way the “Like” button system is set up; any cookies that are associated with Facebook.com will automatically get sent when you view a “Like” button.

They have a point. This is going to be the same for any site that has static content served elsewhere with cookies attached to the domain. Hot link to an image on my blog you commented on? OFFLINE DATA GATHERING ZOMG.

Re: Facebook Defends Getting Data From Logged-Out Users

#6
Their defence doesn't hold much water. But then, I can't imagine any excuse that would satisfy me.

They say “The onus is on us is to take all the data and scrub it,” said Arturo Bejar, a Facebook director of engineering. “What really matters is what we say as a company and back it up.”, except their track record on that matter isn't exactly stellar.

We know they don't actually delete messages or things you delete on FB, they just mark them "deleted". With that attitude to "deleting" things, what does it even matter?

And I don't care if they promise the data is not used for targeting ads, that is just one of the many ways this type of data can be abused.

The argument they use it to prevent "spam and phishing attacks" also seems dubious to me. How does that work? And the cookie that's kept contains just your facebook ID, so wouldn't that be trivial for spammers and phishers to work around?

And the most important thing is, they might act all innocent about it now, that they did it with the best intentions and not to continue tracking people after they log out. Let's believe that and lets assume this behaviour doesn't involve any other privacy implications: Facebook is by now well known for their feature-creep, if we hadn't caught them red-handed now, what's to say they wouldn't be using this data in a few months from now?

Sorry but it's all bullshit. Facebook doesn't care one bit about their user's privacy, they've made that perfectly clear by now, and them pretending to do otherwise in this article is absolutely laughable.

Re: Facebook Defends Getting Data From Logged-Out Users

#7
post #5

The company says the data is sent because of the way the “Like” button system is set up; any cookies that are associated with Facebook.com will automatically get sent when you view a “Like” button. They have a point. This is going to be the same for any site that has static content served elsewhere with cookies attached to the domain. Hot link to an image on my blog you commented on? OFFLINE DATA GATHERING ZOMG.

the difference is, that's not linked to your FB accounts and friends network / social graph.

not that third-party cookies aren't a big privacy issue, but this goes one step further.

Re: Facebook Defends Getting Data From Logged-Out Users

#8

Bejar said Facebook is looking at ways to avoid sending the data altogether but that it will “take a while.” Maybe I'm naive, but why would turning off the gathering of information take a while? This reminds me of unsubscribing to email newsletters, where the final goodbye says something like "you should stop receiving our emails within 6-8 weeks."

Any code changes take a non-trivial amount of time. It sounds like the solution is to delete more of the cookies on logout, but there may be other Facebook services that use them and need to be transitioned away.

Re: Facebook Defends Getting Data From Logged-Out Users

#10
post #2

I'd be interested to see how many competing social networks exhibit the same behavior. Specifically, Twitter and Google+ has similar social buttons. Imagine I wanted to do this but not be get caught. What would you improve? Clearly the cookies will need to look different pre and post logout, but how different?

I would remain suspicious if there was any identifying or unique information in cookies after logout. Ideally, logout should delete all cookies.
Post reply on HN