[url="http://www.smh.com.au/technology/technology-news/facebooks-privacy-lie-aussie-exposes-tracking-as-new-patent-uncovered-20111004-1l61i.html"]Facebook's privacy lie: Aussie exposes 'tracking' as new patent uncovered[/url] : Sydney Morning Herald, October 4, 2011
[indent][quote name="Asher Moses"][floatright]
[size="2"]Causing a stir ... Nik Cubrilovic[/size][/floatright]Facebook has been caught telling porkies by an Australian technologist whose revelations that the site tracks its 800 million users even when they are logged out have embroiled Facebook in a global public policy ââ¬â and legal ââ¬â nightmare. Facebook's [url="http://nikcub.appspot.com/logging-out-of-facebook-is-not-enough#comment-319881438"]assurances[/url] that ââ¬Åwe have no interest in tracking peopleââ¬Â have been laid bare by a new Facebook [url="http://appft.uspto.gov/netacgi/nph-Parser?Sect1=PTO2&Sect2=HITOFF&u=%2Fnetahtml%2FPTO%2Fsearch-adv.html&r=1&p=1&f=G&l=50&d=PG01&S1=20110231240.PGNR.&OS=dn/20110231240&RS=DN/20110231240"]patent[/url], dated this month, that describes a method ââ¬Åfor tracking information about the activities of users of a social networking system while on another domainââ¬Â.
Nik Cubrilovic's [url="http://nikcub.appspot.com/logging-out-of-facebook-is-not-enough"]blog post[/url], which revealed that [url="http://www.smh.com.au/technology/technology-news/facebook-tracks-you-even-after-logging-out-20110926-1ksfk.html"]tracking cookies monitor Facebook users[/url] whenever they surf websites with a Facebook 'like' button, has led to political outrage in the US and Europe.
An Illinois man has [url="http://www.smh.com.au/technology/technology-news/facebook-sued-over-claims-it-tracks-users-activity-20111001-1l2qv.html"]filed a lawsuit[/url] over the tracking on behalf of Facebook users in the US and he is seeking class action status.
Facebook said certain cookies were tracking users in error and [url="http://nikcub.appspot.com/facebook-fixes-logout-issue-explains-cookies"]made several changes[/url] in response to Cubrilovic's revelations. However, it didn't stop tracking users altogether, maintaining that it needed the ability to track browsers after they logged out for safety, spam and performance purposes.
In new posts over the long weekend, Cubrilovic published [url="http://nikcub.appspot.com/howto-setup-secure-and-private-facebook-browsing"]instructions[/url] on how to setup secure and private Facebook browsing. His latest post contains [url="http://nikcub.appspot.com/facebook-re-enables-controversial-tracking-cookie"]new revelations[/url] that indicate Facebook has not switched tracking off at all.
Facebook said tracking cookies were only installed when users accessed Facebook.com but Cubrilovic found they were set by all sites that contained Facebook widgets.
In fact one of the tracking cookies used by Facebook, called ââ¬Ådatrââ¬Â, tracks users ââ¬Åeven if the user had never been to the Facebook site, and even if they didn't click a 'like' or share' buttonââ¬Â, Cubrilovic wrote. The cookie was previously disabled [url="http://online.wsj.com/article/SB10001424052748704281504576329441432995616.html"]following revelations[/url] in The Wall Street Journal earlier this year but has since returned.
Cubrilovic is not convinced by Facebook's assurances that it does not use the cookies to track users.
ââ¬ÅIf you set a cookie on a users machine from one website, and then read that cookie from that persons machine from another website, that is tracking,ââ¬Â he wrote.
Facebook's assurances have been put further in doubt following the discovery of a Facebook patent filing on user tracking dated just days before it told the world it had ââ¬Åno interest in tracking peopleââ¬Â.
The [url="http://appft.uspto.gov/netacgi/nph-Parser?Sect1=PTO2&Sect2=HITOFF&u=%2Fnetahtml%2FPTO%2Fsearch-adv.html&r=1&p=1&f=G&l=50&d=PG01&S1=20110231240.PGNR.&OS=dn/20110231240&RS=DN/20110231240"]patent[/url], ââ¬ÅCommunicating Information in a Social Network System about Activities from Another Domainââ¬Â, specifically refers to tracking users outside of Facebook.com.
It describes maintaining a ââ¬Åprofileââ¬Â of each user as they move around the web and ââ¬Ålogging the actions taken on the third-party websiteââ¬Â.
A Facebook spokesman said the patent was not intended to track logged out users. The patent, on "careful reading", actually described a fundamental part of the Facebook platform - "creating social experiences across the web without logging into Facebook repeatedly or third party sites at all".
It gave as an example its social plug-ins which mean, for instance, that Facebook users can see content friends have "liked" on a third-party site without having to log in to that website. Facebook said current functionality and future business plans shouldn't be inferred from its patent applications.
"Like many technology companies, we patent lots of ideas. Some of these ideas become products or features and some don't," Facebook said.
In the US, a group of privacy advocates and consumer rights organisations [url="http://www.democraticmedia.org/privacy-groups-ftc-investigate-redress-facebooks-latest-threat-its-user-privacy"]sent a letter[/url] to the Federal Trade Commission calling for a probe into Facebook.
It came just days after two US congressman made similar calls, arguing in a letter that when users log out of Facebook they are under the impression that Facebook is no longer monitoring their activities and ââ¬Åthis impression should be realityââ¬Â.
The FTC has yet to say whether it will begin an investigation.
Dutch MP Kees Verhoeven called in parliament for Facebook to be held more accountable after it had ââ¬Åbeen repeatedly linked to privacy violationsââ¬Â. Other MPs echoed his remarks and called for changes to the law to address Facebook privacy.
In Ireland, where Facebook has its European headquarters, the data protection commissioner is planning a ââ¬Ådetailed auditââ¬Â of Facebook's activities outside the US and Canada, the Financial Times reported.
It comes on top of political outrage directed at Facebook in other countries including Britain, Germany and Japan.
Last week, the Australian Privacy Commissioner, Timothy Pilgrim, said he was not going to investigate the Facebook tracking issue as the site had assured him it had rectified the matter. But Pilgrim has yet to comment on the revelations in Cubrilovic's latest blog post or the tracking systems outlined in Facebook's patent filing.
Separately, the rollout of Facebook's new Timeline feature, designed to turn profiles into a chronological scrapbook of major events in the user's life, is being delayed by a trademark infringement lawsuit filed by Timelines.com.
The site's other major change, ââ¬Åfrictionless sharingââ¬Â, whereby user activities are published on their profiles without any prompting by the user, has also sparked controversy.
The feature enables, for instance, users to automatically inform friends when they play a song on Spotify, but it has also led to more unfortunate disclosures such as one user inadvertently telling friends they visited a porn site.
Cubrilovic ââ¬â and many privacy groups ââ¬â fear that Facebook could combine ââ¬Åfrictionless sharingââ¬Â with the data it gets by tracking users around the web, risking significant unintended disclosures.
ââ¬ÅThese changes in business practices give the company far greater ability to disclose the personal information of its users to its business partners than in the past,ââ¬Â the privacy advocates wrote in their complaint letter to the FTC.
ââ¬ÅOptions for users to preserve the privacy standards they have established have become confusing, impractical and unfair.ââ¬Â
In announcing the new features, Facebook founder Mark Zuckerberg referred to ââ¬ÅZuck's lawââ¬Â ââ¬â his belief that Facebook users double the amount of information they share on the site each year.[/quote] [/indent]
[indent][quote name="Asher Moses"][floatright]
[size="2"]Causing a stir ... Nik Cubrilovic[/size][/floatright]Facebook has been caught telling porkies by an Australian technologist whose revelations that the site tracks its 800 million users even when they are logged out have embroiled Facebook in a global public policy ââ¬â and legal ââ¬â nightmare. Facebook's [url="http://nikcub.appspot.com/logging-out-of-facebook-is-not-enough#comment-319881438"]assurances[/url] that ââ¬Åwe have no interest in tracking peopleââ¬Â have been laid bare by a new Facebook [url="http://appft.uspto.gov/netacgi/nph-Parser?Sect1=PTO2&Sect2=HITOFF&u=%2Fnetahtml%2FPTO%2Fsearch-adv.html&r=1&p=1&f=G&l=50&d=PG01&S1=20110231240.PGNR.&OS=dn/20110231240&RS=DN/20110231240"]patent[/url], dated this month, that describes a method ââ¬Åfor tracking information about the activities of users of a social networking system while on another domainââ¬Â.
Nik Cubrilovic's [url="http://nikcub.appspot.com/logging-out-of-facebook-is-not-enough"]blog post[/url], which revealed that [url="http://www.smh.com.au/technology/technology-news/facebook-tracks-you-even-after-logging-out-20110926-1ksfk.html"]tracking cookies monitor Facebook users[/url] whenever they surf websites with a Facebook 'like' button, has led to political outrage in the US and Europe.
An Illinois man has [url="http://www.smh.com.au/technology/technology-news/facebook-sued-over-claims-it-tracks-users-activity-20111001-1l2qv.html"]filed a lawsuit[/url] over the tracking on behalf of Facebook users in the US and he is seeking class action status.
Facebook said certain cookies were tracking users in error and [url="http://nikcub.appspot.com/facebook-fixes-logout-issue-explains-cookies"]made several changes[/url] in response to Cubrilovic's revelations. However, it didn't stop tracking users altogether, maintaining that it needed the ability to track browsers after they logged out for safety, spam and performance purposes.
In new posts over the long weekend, Cubrilovic published [url="http://nikcub.appspot.com/howto-setup-secure-and-private-facebook-browsing"]instructions[/url] on how to setup secure and private Facebook browsing. His latest post contains [url="http://nikcub.appspot.com/facebook-re-enables-controversial-tracking-cookie"]new revelations[/url] that indicate Facebook has not switched tracking off at all.
Facebook said tracking cookies were only installed when users accessed Facebook.com but Cubrilovic found they were set by all sites that contained Facebook widgets.
In fact one of the tracking cookies used by Facebook, called ââ¬Ådatrââ¬Â, tracks users ââ¬Åeven if the user had never been to the Facebook site, and even if they didn't click a 'like' or share' buttonââ¬Â, Cubrilovic wrote. The cookie was previously disabled [url="http://online.wsj.com/article/SB10001424052748704281504576329441432995616.html"]following revelations[/url] in The Wall Street Journal earlier this year but has since returned.
Cubrilovic is not convinced by Facebook's assurances that it does not use the cookies to track users.
ââ¬ÅIf you set a cookie on a users machine from one website, and then read that cookie from that persons machine from another website, that is tracking,ââ¬Â he wrote.
Facebook's assurances have been put further in doubt following the discovery of a Facebook patent filing on user tracking dated just days before it told the world it had ââ¬Åno interest in tracking peopleââ¬Â.
The [url="http://appft.uspto.gov/netacgi/nph-Parser?Sect1=PTO2&Sect2=HITOFF&u=%2Fnetahtml%2FPTO%2Fsearch-adv.html&r=1&p=1&f=G&l=50&d=PG01&S1=20110231240.PGNR.&OS=dn/20110231240&RS=DN/20110231240"]patent[/url], ââ¬ÅCommunicating Information in a Social Network System about Activities from Another Domainââ¬Â, specifically refers to tracking users outside of Facebook.com.
It describes maintaining a ââ¬Åprofileââ¬Â of each user as they move around the web and ââ¬Ålogging the actions taken on the third-party websiteââ¬Â.
A Facebook spokesman said the patent was not intended to track logged out users. The patent, on "careful reading", actually described a fundamental part of the Facebook platform - "creating social experiences across the web without logging into Facebook repeatedly or third party sites at all".
It gave as an example its social plug-ins which mean, for instance, that Facebook users can see content friends have "liked" on a third-party site without having to log in to that website. Facebook said current functionality and future business plans shouldn't be inferred from its patent applications.
"Like many technology companies, we patent lots of ideas. Some of these ideas become products or features and some don't," Facebook said.
In the US, a group of privacy advocates and consumer rights organisations [url="http://www.democraticmedia.org/privacy-groups-ftc-investigate-redress-facebooks-latest-threat-its-user-privacy"]sent a letter[/url] to the Federal Trade Commission calling for a probe into Facebook.
It came just days after two US congressman made similar calls, arguing in a letter that when users log out of Facebook they are under the impression that Facebook is no longer monitoring their activities and ââ¬Åthis impression should be realityââ¬Â.
The FTC has yet to say whether it will begin an investigation.
Dutch MP Kees Verhoeven called in parliament for Facebook to be held more accountable after it had ââ¬Åbeen repeatedly linked to privacy violationsââ¬Â. Other MPs echoed his remarks and called for changes to the law to address Facebook privacy.
In Ireland, where Facebook has its European headquarters, the data protection commissioner is planning a ââ¬Ådetailed auditââ¬Â of Facebook's activities outside the US and Canada, the Financial Times reported.
It comes on top of political outrage directed at Facebook in other countries including Britain, Germany and Japan.
Last week, the Australian Privacy Commissioner, Timothy Pilgrim, said he was not going to investigate the Facebook tracking issue as the site had assured him it had rectified the matter. But Pilgrim has yet to comment on the revelations in Cubrilovic's latest blog post or the tracking systems outlined in Facebook's patent filing.
Separately, the rollout of Facebook's new Timeline feature, designed to turn profiles into a chronological scrapbook of major events in the user's life, is being delayed by a trademark infringement lawsuit filed by Timelines.com.
The site's other major change, ââ¬Åfrictionless sharingââ¬Â, whereby user activities are published on their profiles without any prompting by the user, has also sparked controversy.
The feature enables, for instance, users to automatically inform friends when they play a song on Spotify, but it has also led to more unfortunate disclosures such as one user inadvertently telling friends they visited a porn site.
Cubrilovic ââ¬â and many privacy groups ââ¬â fear that Facebook could combine ââ¬Åfrictionless sharingââ¬Â with the data it gets by tracking users around the web, risking significant unintended disclosures.
ââ¬ÅThese changes in business practices give the company far greater ability to disclose the personal information of its users to its business partners than in the past,ââ¬Â the privacy advocates wrote in their complaint letter to the FTC.
ââ¬ÅOptions for users to preserve the privacy standards they have established have become confusing, impractical and unfair.ââ¬Â
In announcing the new features, Facebook founder Mark Zuckerberg referred to ââ¬ÅZuck's lawââ¬Â ââ¬â his belief that Facebook users double the amount of information they share on the site each year.[/quote] [/indent]