Logged in or out, Facebook is watching you

Researchers at software vendor CA have discovered that social networking site Facebook is able to track the buying habits of its users on affiliated third-party sites even when they are logged out of their account or have opted out of its controversial "Beacon" tracking service.

Read This:

Facebook: The Google of social networks?

Since lifting its university-only restrictions in September 2006, Facebook has become the poster child for social networks and attracted more than 100 million users. But will it survive 'the next big thing'?
Read More

Beacon, launched in November, tracks the transactions Facebook users make at e-commerce sites such as ticketing company Fandango and Blockbuster Video, in order to list them in the user's "mini-feed". It is intended, Facebook claims, as a means of "social marketing" -- users recommending products and services to their peers.

Responding to privacy concerns, Facebook has since moved to reassure users that it only tracks and publishes data about their purchases if they are both logged in to Facebook and have opted-in to having this information listed on their profile.

But in "extremely disconcerting" findings that directly contradict these assurances, researchers at CA's Security Advisory service have found that data about these transactions are sent to Facebook regardless of a user's actions.

Tests by CA researcher Stefan Berteau, published here, seem to prove the point.

During the test, Berteau executed actions (saved a recipe) on Facebook affiliate site epicurious.com three times.

In the first instance, he saved a recipe while still logged in to Facebook.

"An alert appeared allowing me to opt-out of Facebook's publishing this as a story on my feed, which I did," he said.

He then saved a recipe on Epicurious.com with the Facebook window closed, but while he was still logged in to Facebook. Again he was alerted, and this time chose "No, thanks" -- and therefore opting out of the service.

He then saved a third recipe while he was completely logged out of the Facebook site under a new browser session, and received no alert.

Berteau then consulted CA's network traffic logs, and found that in all three cases, data (such as his Facebook account name and details of his actions on the affiliate site) had been submitted to Facebook.

Berteau claims the results of the tests prove that Facebook is able to collect information about its members' surfing habits on affiliate sites, regardless of whether permission has been granted.

Facebook replied to CA's concerns in a letter describing the ease with which user's can opt out of having the purchasing information listed on the "mini-feed" on their profile.

"I replied explaining that I was not particularly worried about the feeds, which are only shown to friends who I have previously vetted, but that I was more concerned about the silently collected data, particularly the possibility of that data being sold to third parties," Berteau said.

Facebook has since released a statement claiming that it has no choice but to collect the data so that it can be used should the user decide to "opt-in" to the service.

"If a Facebook user clicks 'No, thanks' on the partner site notification, Facebook does not use the data and deletes it from its servers.

"Separately, before Facebook can determine whether the user is logged in, some data may be transferred from the participating site to Facebook. In those cases, Facebook does not associate the information with any individual user account, and deletes the data as well," the statement said.

Berteau said that while such a statement is reassuring, there is nothing in Facebook's privacy policy that acknowledges it doesn't store or use that data.

"The fact that the data continues to be sent to Facebook.com continues to pose a risk to user's privacy until a binding, public mechanism is in place to assure that the above policy stays in place, and that users are notified if it ever changes.

"Facebook's privacy policy is such a mechanism. Officially stating in its policy that it will not store or use data which is not associated with a logged in Facebook account which opted in to Beacon would go a long way towards providing clarity and an assurance of privacy towards their users," he said.

Advertisement

Talkback 8 comments

    Guess its time to leave Facebook..... Anonymous -- 19/07/08

    That they transmit my data even after I opt-out is just plain wrong, and the statement "Facebook has since released a statement claiming that it has no choice but to collect the data so that it can be used should the user decide to "opt-in" to the service." Is pure nonsense.

    Facebook has no choice but to collect the data? Give me a break, and that fact that Berteau finds the statement 'reassuring' leads me to question Berteau's competency.

    Bye, bye Facebook. I wonder how many more are like me and will be leaving now?

    Facebook Anonymous -- 13/11/08 (in reply to #320107177)

    All this stuff puts me out of facebook, toooo scary, I'm gone

    I'm affraid the Future is much Darker then it looks like Cillver -- 20/07/08

    The whole Internet is becoming a big Hole in our systems; There is no such thing called Privacy on the NET; Sometimes i feel like the Conspirecy Theorists were right all the way

    conspiracy morgen someguy -- 24/07/08 (in reply to #320107232)

    read the terms of use for facebook, as you should with anything, expecially on the net. Its all being sent to the u.s. government for terrorist watch. We conspiracy theorists are mostly right we dont just pull it out of our rectums. The majority of claims are logical you just gotta be willing to see it.

    Cookies Anonymous -- 24/07/08

    Relax, just block cookies from facebook and you'll be done with it.

    Blocking Cookies - Not good enough Mavrick-ww -- 04/08/08 (in reply to #320107524)

    Blocking standard cookies is not an effective method of preventing sites from tracking your browsing habits. You will have to block Flash as well. Flash has it’s own cookie like functionality that stores information on your hard drive. If you want to test this go to Pandora.com then clear your cookies. It will remember who you are. See http://www.ghacks.net/2007/05/04/flash-cookies-explained/ for more information.

    Telstra Phones Anonymous -- 15/10/08

    Please BEWARE.Contract on my phone nearly finished.Got 2 new LGTU550 as per phone call.Came from PHONE ZONE (TELSTRA)NO COOLING OFF period. Bad reception in country areas.Bad customer service and unwilling to have phones sent back.

    Telstra Phones Anonymous -- 05/05/09 (in reply to #320114268)

    Got to agree with you there...I've had the same problem with them.......They are just sooooo hard to get anywhere with. I got an LG managed to get it sent back 3 times...still dosen;t work...got rid of it ...but it costs

Add your opinion

Latest Videos

Blogs

  • Darren Greenwood Telecom NZ savings damage prospects
    If Telecom NZ wants to have any of the NZ$1.5 billion the government intends to spend on its new broadband network, it had better think long and hard before offshoring 1500 jobs.
  • Array iiNet: The whys and what nows
    Last week the Federal Court ruled that internet service providers are not responsible for copyright violation by their customers. This is an important decision not just for iiNet, which spent around $4 million defending the case, but for all ISPs in Australia and, indeed, globally.
  • Array Govt, hurry up with releasing data
    A programmer scraped data from the My School website to make some really cool heat maps showing regions of smart schools — no thanks to the government, which didn't supply the data in any useful kind of format.
  • More blogs »

Tags

Back to top

Featured