Facebook sent some user data to advertisers

 

Summary

Facebook appears to have violated its promise not to share "identifiable" user data with advertisers in a situation it says it has since corrected.

Events

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

Facebook's privacy policy promises, in no uncertain terms, that it doesn't "share your information with advertisers without your consent." Only "non-personally identifiable" data, it says, are shared.

But the social-networking site confirmed late Thursday that it has, at least in some circumstances, sent the user name of a Facebook member to its advertising partners. That can be used to glean a person's name, interests, and list of friends.

A Facebook spokesman told CNET that the apparent privacy leak has been fixed.

News of this data sharing, which appeared in the Wall Street Journal on Thursday evening, could prove embarrassing to the social-networking site, which is already on the defensive after Washington politicians have been calling for regulatory action on privacy grounds and over a dozen advocacy groups have charged that Facebook engages in "unfair and deceptive" business practices.

Facebook's admission also may conflict with its previous statements. In a blog post last month, a company official wrote: "We don't share your information with advertisers unless you tell us to...Any assertion to the contrary is false. Period."

"We were recently made aware of one case where if a user takes a specific route on the site, advertisers may see that they clicked on their own profile and then clicked on an ad," the Facebook spokesman said on Thursday. "We fixed this case as soon as we heard about it. In addition, we have been working on ways to no longer include user IDs in Referer: URLs."

Browsers typically send a Web site, in what's called a Referer: field, the location of the page you last visited. This lets Web operators know where their visitors are coming from, and it's viewed as a perfectly normal and commonplace practice.

The rub: if you're logged into Facebook, the Referer: field can reveal your user name to advertisers.

Ben Edelman, an assistant professor at Harvard Business School who has a background in Internet advertising, described the problem in a new essay that says: "When a user views her own profile, or a page linked from her own profile, the "?ref=profile" tag is added to the URL--exactly confirming the identity of the profile owner." Facebook could eliminate any privacy concerns by configuring a different type of Referer: set-up, Edelman said.

Other social-networking sites


Other social-networking sites also included the Referer: field, but Facebook appears to be the only one that uses it--inadvertently or intentionally--to signal the identity of who's logged on.

That's not necessarily a privacy leak. If someone clicks on an theoretical advertisement on, say, Twitter.com/jessicaalba or Myspace.com/usher, the Referer: field won't reveal the identity of the reader.

And MySpace, Twitter, Digg, Xanga, and Live Journal downplayed the issue when contacted by the Journal, saying it was standard industry practice.

"While access to a MySpace 'FriendID' does not permit anyone access to information beyond what a user has already made publicly available, MySpace is currently implementing a methodology that will obfuscate the 'FriendID' in any URL that is passed along to advertisers," MySpace said in an e-mail statement.

Facebook acknowledged the issue and said it did not consider the data personally identifiable although it was nonetheless working to change its practice.

"As is common with advertising across the Web, the data that is sent in a referrer URL includes information about the Web page the click came from. This may include the user ID of the page but not the person who clicked on the ad. We don't consider this personally identifiable information and our policy does not allow advertisers to collect user information without the user's consent," a Facebook spokesman said in e-mail.

Edelman, however, says his analysis shows that the user name is frequently leaked. He pointed to a paper (PDF) outlining precisely this issue written by AT&T Labs and Worcester Polytechnic Institute researchers, which was presented at a conference in Barcelona last August.

It's unclear whether any advertisers have acted on the information they received, but Google's DoubleClick and Yahoo's Right Media told the newspaper they were unaware of the situation and had not used any such data. In Google's case, as a result of DoubleClick's 2002 settlement with state attorneys general, advertisers (and not Google) own the data.

This article was first published as a blog post on CNET News.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

Rise in <b>Chinese</b>-funded acquisitions could trigger more hurdles http://t.co/0pXBS1HR

Rise in Chinese-funded acquisitions could trigger more hurdles: By Ellyne Phneah , ZDNet Asia on May 22, 2012 (6... http://t.co/W3SOdw2c

RT @zdnetasia: CFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb

CFOs increasingly involved in IT investment decisions http://t.co/XD1LerFq via @zdnetasia #PrivateCloud #SC2012 #CAPEX

Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o

RT @zdnetasia: Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 hour ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

Rise in Chinese-funded acquisitions could trigger more hurdles - ZDNet Asia: Rise in Chinese-funded acquisitions... http://t.co/bZaAQnRL

Rise in Chinese-funded acquisitions could trigger more hurdles http://t.co/mIsuZjnU http://t.co/erFX4aVv #arcavir

http://t.co/VNaZtseV Rise in Chinese-funded acquisitions could trigger more hurdles: "Cash r... http://t.co/N0gZZEdR http://t.co/wiqY9ktt

Rise in Chinese-funded acquisitions could trigger more regulatory clearance issues overseas http://t.co/cvLSpTwo #in

Alibaba seeks $2.3B from shareholders for Yahoo deal. http://t.co/qLRAhRQk

CFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb

Quickflix WatchNow 2.0 http://t.co/XWti5VWT

Official UEFA #EURO2012 app with Orange 2.0 http://t.co/yoAOXTI1 #hotpeopleifollow

Why wouldn't they be?: CFOs increasingly involved in IT investment decisions http://t.co/4gHYrmQy via @zdnetasia

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

1 day ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

1 day ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

3 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

3 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

4 days ago by wykoong on Drop the egos, copy ideas, then innovate