Recent Entries

Seeking References on Cellphone Surveillance

Cuil not so Cool

New “Cuil” Search Engines Decides User Logs Aren’t Necessary

Local Library uses RFID to Manage Materials, but Privacy Concerns Abound

Visibility of Googe’s Privacy Policy Depends on Where you Live

A Code of Best Practices in Fair Use for Online Video

Google (Quietly/Oddly) Adds Privacy Link to Homepage

Court Orders Google to Give All YouTube User Histories to Viacom


Categories

4S  4th Amendment  A2K  AOIR  AOL  Academic  Amateur data mining  Andrew Keen  Ask.com  Auto Black Boxes  Behavioral targeting  Blogging  Books  CEPE  CFP08  Cellphones  Censorship  China  ChoicePoint  Conferences  Constitution  Contextual Integrity  Cookies  Copyright  DRM  DSRC  Dan Solove  Data Aggregation  Data mining  Data retention  Dataveillance  Dissertation  DoubleClick  Ethics  Facebook  Facial recognition  Flickr  GPS  Gmail  Google  Google News  Google Print  HealthVault  Humor  IINW  ISP  Identity  Identity 2.0  Information theory  Intellectual Privacy  Intellectual Property  Interfaces  Internet  Knowledge Tools  Law  Libraries  Locational privacy  Media  Media Ecology  Microsoft  MySpace  Netaveillance  Networked Vehicle Systems  Online Privacy  Orkut  PORTIA  Paid Search  Perfect Search  Personal  Personalized Search  Privacy  Privacy in Public  Privacy on the Roads  Publications  Quaero  RFID  Reputation systems  Riya  Search Engine Bias  Search Engines  Search privacy  Siva Vaidhyanathan  Social networks  Spyware  Street View  Surveillance  Talks  Technology  Technology & Society  TrackMeNot  Uncategorized  Values in Design  Web 2.0  Wi-fi  Wikipedia  Yahoo  YouTube  eHealth  iPod  iTunes 

Rss Feed




  • Powered by FeedBlitz
  • Campaigns

    Join EFF Today

    I support individual rights

    Stop Data Retention

    I am a hard bloggin' scientist. Read the Manifesto.

    Meta

    Creative Commons License

    Facebook Beacon Worse than Most Thought (And Still Is)

    Posted on Sunday, December 2nd, 2007 at 10:51 pm

    I had a hunch…

    Last week we welcomed Wendy Seltzer at the Yale Information Society Project, who gave a talk on “Online Privacy in Context.” Most of our discussion centered on the controversy swirling around Facebook’s Beacon advertising platform, where Facebook cookies are retrieved at third-party e-commerce sites, users are given 20-seconds to opt out (the default is to participate, and the screen disappears with the option still checked if no action is taken), and users’ likenesses are appropriated to shill for products.

    I asked Wendy if she knew whether Facebook was still collecting user purchasing data even if that that user opted out of openly sharing a particular purchase with her Facebook friends. Wendy noted that Facebook claimed that wasn’t happening, which is supported by statements from Chamath Palihapitiya, vice president of product marketing and operations at Facebook, who, in an interview with The New York Times, was asked whether Facebook would receive information about a user’s purchase if the user declined to broadcast the purchase to his Facebook friends. His answer: “Absolutely not. One of the things we are still trying to do is dispel a lot of misinformation that is being propagated unnecessarily.”

    Not so fast.

    PC World is reporting on research conducted by a Computer Associates security expert who discovered that Beacon will report back to Facebook on members’ activities on third-party sites even if the users are logged off from Facebook and have declined having their activities broadcast to their Facebook friends.

    Unbelievable. Facebook just announced plans to increase user privacy, but, as Stefan Berteau (the CA researcher) notes, “Facebook is materially misrepresenting the privacy impact of their Beacon program, and presenting users with the appearance of control over their information when in fact they have almost none.”

    Facebook: please answer my plea.

    UPDATE: Contradicting their early statements (above), Facebook now admits that their Beacon ad system does tracks users’ off-Facebook activities even if those users are logged off from the social-networking site and have previously declined having their activities on specific external sites broadcast to their Facebook friend. Story is here. Unbelievable.

    Related Posts:

    One Response to “Facebook Beacon Worse than Most Thought (And Still Is)”

    1. Logical Extremes Says:

      This is quite bad behavior on Facebook\’s part.

      It\’s not as simple as adding an ad server to your hosts file to block it either, as the beacon code gets served from a subdirectory rather than a subdomain:

      http://www.facebook.com/beacon/

      But hopefully the various browser plugins and scripts will incorporate blocking these ads.

    Leave a Reply