Facebook: Cookie tracking issue is limited, fix coming today

By | October 4, 2011, 9:52am PDT

Summary: Facebook has confirmed a tracking cookie bug and said it will fix it today. The company has also explained that the issue is limited in scope – only some third-party websites are affected.

Soon after self-proclaimed hacker Nik Cubrilovic discovered Facebook is once again setting its datr cookie via the Like button and other social plugins, the company has made an attempt to clarify the findings. Facebook has confirmed this is indeed a bug, but says that it is limited in scope and that it will be fixed today.

The cookie in question can be set even if the user has never been to Facebook, and even if he or she doesn’t click on a given Facebook widget. It can be read later to track a user across different Web properties and back to the Facebook site. Cubrilovic said it is reportedly the first cookie set on all third-party websites with a Facebook social plugin, and for all users of the social network – whether you are logged in or logged out.

I contacted Facebook and a spokesperson pointed me to a comment made to Cubrilovic by Facebook engineer Gregg Stefancik:

I am a engineer at Facebook who works on Facebook’s login systems. Thanks for raising this issue. We still have a policy of not building profiles based on data from logged out users. Reports like this help us make sure we’re adhering to that policy which has not changed. As we discussed last week, we are examining our cookie setting behavior to make sure we do not inadvertently receive data that could be associated with a specific person not logged into Facebook.

We have been made aware of 2 instances in the past 2 weeks related to cookies which needed to be addressed. What you describe in this post is not a re-enabling of anything, but a separate issue involving a limited number of sites, including CBSSports. We have moved quickly to investigate and resolve this latest issue which will be fully addressed today. We encourage security researchers to test our practices and report them to us through our whitehat program which rewards people like you who identify issues.

I also asked for further clarification on how many third-party websites have this issue and why not all websites are affected. “Sites that called our API in a non-standard way, one in which we had not considered to protect against cookie-setting for non-users, were impacted by this bug,” a Facebook spokesperson said in a statement.

It looks like another mystery has been solved, although something tells me this story is not over. Going forward, Facebook is going to face much closer scrutiny related to its cookies and user tracking than it ever has before.

Part of this will come from legal bodies. 10 privacy groups and US congressmen last week sent letters asking the Federal Trade Commission (FTC) to investigate Facebook for these and other practices. Furthermore, Ireland’s Data Protection Commissioner has agreed to conduct a privacy audit of Facebook. Given that the social network’s international headquarters is in Dublin, the latter is the more serious one as the larger majority of the site’s users could be affected. Facebook has even had to defend itself in regards to a recent patent it filed, arguing that the document does not describe how to track logged-out users.

See also:

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Emil Protalinski has covered the tech industry for five years for multiple publications.

Disclosure

Emil Protalinski

Emil has nothing to disclose.

Biography

Emil Protalinski

Emil Protalinski has covered the tech industry for five years for multiple publications, including Neowin for two years and Ars Technica for three years. He has written 1,000s of articles for both, with a particular focus on scrutinizing Microsoft products and services. Recently, Emil has expanded his coverage to non-Microsoft technologies, including the social networking giant Facebook.

9
Comments

Join the conversation!

Just In

RE: Facebook: Cookie tracking issue is limited, fix coming today
jackson1984-24316069205748857739440257893812 10th Oct
I have not checked in best right here for merely a minor nfl jersey despite the fact that because of with the actuality I regarded it had been obtaining tiresome, even while almost quite possibly the most contemporary posts are wonderful fine quality i fully guess I will include you oh no- my day by day bloglist
MR Zuckerberg im here to return the favour and insert a cookie in your ******* on november 5
Facebook will always "claim" to fix these problems but will just end up using different ways to collect this data.

I'm sure they'll merge a few cookies next and the result is the tracking data will be folded into the cookies they use "for security and anti-spam" purposes
metin2 pvp serverler
mt2
metin2
metin2 hile
yemek tarifleri
guzel sozler
sex hikayeleri
metin2 indir
metin2 pvp serverlar
metin2 turk
mt2 pvp
face
sex
Knight Pvp Serverler
Knight online serverler
Now I want to hear the same guys that cried when Google invaded their mysterious privacy with Google Street Cars tracking SSIDs to cry for Facebook smelling right into their a-ss.
But if you don't allow 3rd party cookies, forget signing up with them! Limited my butt! Just sniff a connection or two and watch what goes on!
Looks like Twitter and many other sites do the same thing. Try this. Clear your cookies and reload this page, you will get about 2 dozen cookies from different sites.
Now I'm Pis&ed! Why does zdnet put com.com, crowdscience.com, imrworldwide.com, revsci.com, scorecardresearch.com, stumbleupon.com, tag.admeld.com and twitter.com in my browser? Are these tracking cookies. I just might stop using zdnet because of this behavior. I do, of course, have my browsers set to delete all cookies, history, passwords and everything else when I exit, but that still doesn't make it right to shove cookies down my throat. BAD, BAD, ZDNET!!!! As I have stated before, FB and Twitter, etc ., are junk!!!
0 Votes
+ -
Facebook Cookie Tracking "Fix"
hectorj102 Updated - 6th Oct
"Going forward, Facebook is going to face much closer scrutiny related to its cookies and user tracking than it ever has before."

That's a good thing! The problem is that interest will fade (barring further revelations) and FB will continue to devise more devious methods to collect and track our personal activity to pad its' bottom line.
0 Votes
+ -
RE: Facebook: Cookie tracking issue is limited, fix coming today
jackson1984-24316069205748857739440257893812 10th Oct
I have not checked in best right here for merely a minor nfl jersey despite the fact that because of with the actuality I regarded it had been obtaining tiresome, even while almost quite possibly the most contemporary posts are wonderful fine quality i fully guess I will include you oh no- my day by day bloglist

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix