Facebook counters cookie tracking allegations

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

About this blog

ZD Staff

Security Bullet In

Analysis of security, technology, and attempts to filter random noise

A Facebook engineer has said the social networking company does not use persistent cookies to track users when people are not logged in to Facebook.

Facebook cookies are primarily used for service and security reasons, Facebook login engineer Gregg Stefancik said on Monday.

"Our cookies aren't used for tracking. They just aren't," said Stefancik in comments on a blog post. "Instead, we use our cookies to either provide custom content (e.g. your friend's likes within a social plugin), help improve or maintain our service (e.g. measuring click-through rates to help optimize performance), or protect our users and our service (e.g. defending denial of service attacks or requiring a second authentication factor for a login from a suspicious location)."

Facebook has been repeatedly criticised over user privacy issues, and chief executive Mark Zuckerberg has acknowledged that there is often a "backlash" against new Facebook features.

Australian researcher Nik Cubrilovic said in a blog post on Sunday that Facebook alters the state of cookies stored on a user's computer when they have logged out, but does not remove the cookies. Moreover, nine cookies, including account identification, are sent to Facebook every time a user visits a site with a Facebook 'like' button, Cubrilovic said.

"With my browser logged out of Facebook, whenever I visit any page with a Facebook like button, or share button, or any other widget, the information, including my account ID, is still being sent to Facebook," said Cubrilovic. "The only solution to Facebook not knowing who you are is to delete all Facebook cookies."

Cubrilovic said that he had discovered a cookie called 'act', which he claimed stood for 'account number', which allowed Facebook to identify logged-out users online.

Stefancik countered this claim in a comment on Cubrilovic's blog post by saying that 'act' in fact stood for 'action', and was a UNIX timestamp used to measure and optimise the speed of the site. Moreover, Facebook deletes account-specific cookies when a user logs out, said Stefancik.

A Facebook spokeswoman on Monday confirmed that Stefancik had commented on Cubrilovic's blog.

Talkback

Hi there,

I wanted to send along a note on behalf of Facebook Communications.

Facebook does not track users across the web. Instead, we use cookies on social plugins to personalize content (e.g. Show you what your friends liked), to help maintain and improve what we do (e.g. Measure click-through rate), or for safety and security (e.g. Keeping underage kids from trying to signup with a different age). No information we receive when you see a social plugins is used to target ads, we delete or anonymize this information within 90 days, and we never sell your information.

Specific to logged out cookies, they are used for safety and protection, including identifying spammers and phishers, detecting when somebody unauthorized is trying to access your account, helping you get back into your account if you get hacked, disabling registration for a under-age users who try to re-register with a different birthdate, powering account security features such as 2nd factor login approvals and notification, and identifying shared computers to discourage the use of 'keep me logged in'.

One of our engineers, Gregg Stefancik, also posted a longer and more technical explanation on the original blog post: http://nikcub-static.appspot.com/logging-out-of-facebook-is-not-enough

andrewnoyes 26 September, 2011 18:47
Reply

@andrewnoyes Thanks for your comment. I'm a bit puzzled as to what it actually adds to the story as reported. The blog post says everything that you mention, plus it links to the Stefancik blog post you include.

If Facebook Communications would like to talk to us about privacy and data handling on the service, we'd be happy to talk. If you're posting prepared comments on news sites, it looks like you do want to be heard.

Karen Friar 27 September, 2011 10:11
Reply

My wife and youngest daughter use Facebook and never log out. I will not use Facebook because I have an old fashioned view to privacy and control of my data. My older children, now with families of their own, also use Facebook and I doubt they log out either.

In addition, I frequently close my browser to clear all data having configured the browser accordingly. I'm the only person I know who takes these precautions, that is unless I set it up for them.

Maybe I'm paranoid, but I don't have many problems with my computers and data.

Moley 27 September, 2011 11:53
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Malcolm Mcewen

Proof if we ever needed it that the boffins at CERN are incompetent and this article explains why we should be conCERNed about CERN:...

3 minutes ago by Malcolm Mcewen via Facebook on CERN neutrino shock may be down to faulty connector
IJ24

It's good to know that measures are made to make printing tasks easier aside of course from products like cheap Canon ink that help diminish the...

19 minutes ago by IJ24 on Cloud printers wrest ink from Google, HP
Paul Smyth

I'm bored of all the luddite Unity knockers. Think you can do better? Put up or shut up. I love Unity, it's elegant, beautiful, highly functional...

36 minutes ago by Paul Smyth via Facebook on Canonical defends its shift to Unity
DrJonno

Nice new agenda/mail client. Shame it doesn't appear to integrate with Bridge. The Bridge clients seem not to have changed at all. Overall...

2 hours ago by DrJonno on RIM delivers BlackBerry PlayBook OS 2.0
Keith Jamieson

@1000099915 I totally agree with you. I was just letting DmitryKirsanov know that there is more than "just" a receiver at work here. I dont own,...

2 hours ago by Keith Jamieson via Facebook on UK Sentinel study reveals GPS jammer use
1000099915

@Keith Jamieson You turn off GPS on your device. You don't block GPS in the surrounding area! If you are required by your company to be tracked by...

2 hours ago by 1000099915 on UK Sentinel study reveals GPS jammer use
Jake Rayson

If they can pull it off with phone manufacturers, this could be the back door for relatively widespread adoption of Ubuntu: who wouldn't want a...

2 hours ago by Jake Rayson on Ubuntu for Android arrives: In pictures
Keith Jamieson

@DmitryKirsanov There are companies who fit GPS trackers onto their vehicles. They are basically a GPS receiver and GSM (phone) transmitter. At...

4 hours ago by Keith Jamieson via Facebook on UK Sentinel study reveals GPS jammer use
catman1

My satnav always stops working through the channel tunnelwhen I exit UK end.It will not restart until 24hrs later.OK going from UK to france no...

4 hours ago by catman1 on UK Sentinel study reveals GPS jammer use
DmitryKirsanov

Wow. People from Facebook are either trolls or plain stupid. Why it is so hard to understand how GPS works? Is the difference between the...

4 hours ago by DmitryKirsanov on UK Sentinel study reveals GPS jammer use
Abz Izback

lol, before it was illegal for prisoners to remove their tags, and slaves to remove theirs or to burn their branding before that, now guess who the...

6 hours ago by Abz Izback via Facebook on UK Sentinel study reveals GPS jammer use
mileswade

I have no idea if GPS jamming in the US is a crime or not, it should be. There has been a lot of discourse civil and otherwise concerning jamming...

9 hours ago by mileswade on UK Sentinel study reveals GPS jammer use
whitty44

Gurpeet - GPS does not track you. Things such as your phone may use it, but all that GPS is are messages of the time it was sent. Matthew - GPS...

10 hours ago by whitty44 on UK Sentinel study reveals GPS jammer use
qst4

I've been quite happy with Ubuntu 11.10. And I'm happy to see Canonical making aggressive changes. I've been using this distro for the past month...

10 hours ago by qst4 on Canonical defends its shift to Unity
Matthew Shea

What a police state the UK has become. Dear God!

10 hours ago by Matthew Shea via Facebook on UK Sentinel study reveals GPS jammer use
Matthew Shea

How about No. What a load of bullshit this article is. People have the right to not be surveillanced if they wish so long as they aren't causing...

10 hours ago by Matthew Shea via Facebook on UK Sentinel study reveals GPS jammer use
Simon Bisson

Set the clock forward, and then set the clock back. That resets the lock out timer. No need to connect while "in the future" - in fact you'll get a...

11 hours ago by Simon Bisson via Facebook on BlackBerry PlayBook OS 2.0
bluedalmatian

"Even in the Gnome world now, they're talking about design and user experience and user research and user testing in a way that was never important...

14 hours ago by bluedalmatian on Canonical defends its shift to Unity
Gurpeet Sangera

God save GPS? Invasion of privacy more like it. True freedom is to be able opt out of being tracked and recorded.

14 hours ago by Gurpeet Sangera via Facebook on UK Sentinel study reveals GPS jammer use
Mast sense

they have tried to get planning permison to errect a 50ft 4g mast 38 ft from our back fence, yet they claim there will be no side effects to it....

16 hours ago by Mast sense on Almost 1m households to be hit by 4G interference

Community highlights

Alan Priestley

Fears about cloud security are largely unjustified

Blog Post Despite cloud technologies being adopted at a relentless pace there is always...

22 February, 2012 by Alan Priestley
First Take

Samsung Series 7 Chronos

Blog Post The Samsung Series 7 Chronos isn't the kind of notebook we normally spend...

21 February, 2012 by First Take
Jake Rayson

I am a mighty advertiser!

Blog Post I’ve noticed an interesting trend of late in the social networking world:...

21 February, 2012 by Jake Rayson
J.A. Watson

SimplyMEPIS 11.0.12 Released

Blog Post I came across something else that happened while I was away the past few...

21 February, 2012 by J.A. Watson