Facebook fixes cookie behavior after logging out
Summary: After denying allegations that it can track what you're doing online even if you log out of the social network, Facebook has changed how its cookies behave.
Update: US congressmen ask FTC to investigate Facebook cookies.
Over the weekend, self-proclaimed hacker Nik Cubrilovic accused Facebook of tracking its users even if they log out of the social network. The company responded by denying the claims and offering an explanation as to why its cookies behave the way they do. Now, Cubrilovic says Facebook has made changes to the logout process, and detailed what each cookie is responsible for.
Facebook has five cookies that persist: datr, lu, p, L, and act. There are also two session cookies that persist after the logout procedure: a_user and a_xs. The former, which is the user's ID, is now destroyed on logout. This is the one Cubrilovic had the most issue with. Here is how Facebook describes it:
What you see in your browser is largely typical, except a_user which is less common and should be cleared upon logout (it is set on some photo upload pages). There is a bug where a_user was not cleared on logout. We will be fixing that today.
The datr cookie is set when a browser first visits facebook.com (except via social plugin iframes), and helps Facebook "identify suspicious login activity and keep users safe." The lu cookie is also set the first time a browser visits facebook.com and is used to identify the browser – it helps "protect people using public computers." The a_xs cookie is a string used to prevent cross-site scripting attacks – it serves to check the payload of any requests to the server.
These cookies uniquely identify the browser being used even after logout, and Cubrilovic says that you shouldn't worry about them, unless you can't take Facebook at its word that the purpose of these cookies is only for what is being described. Cubrilovic says the remaining cookies are not very interesting: "they set things like the language of your browser and device dimensions." He believes the most interesting cookie, a_user, now behaves as it should.
Here is his conclusion on the whole fiasco:
Facebook has changed as much as they can change with the logout issue. They want to retain the ability to track browsers after logout for safety and spam purposes, and they want to be able to log page requests for performance reasons etc. I would still recommend that users clear cookies or use a separate browser, though. I believe Facebook when they describe what these cookies are used for, but that is not a reason to be complacent on privacy issues and to take initiative in remaining safe.
It's important to note that Facebook did not previously say it was going to make changes. Both statements I received, from a Facebook engineer and from a Facebook spokesperson, were written as explanations of the process. While Cubrilovic says nothing about Facebook's insistence it does not track users (as far as we know, this is true), it appears he was right about the logout issue, because according to him, the social network has now fixed it. I have contacted Facebook to verify this.
Update: A spokesperson has replied but did not offer an official statement. Instead, he once again pointed me to a comment made on my article, this time from Facebook engineer Gregg Stefancik. Here is what he wrote:
I'm an engineer who works on these systems. I want to make it clear that there was no security or privacy breach. Facebook did not store or use any information it should not have. Like every site on the internet that personalizes content and tries to provide a secure experience for users, we place cookies on the computer of the user. Three of these cookies on some users' computers included unique identifiers when the user had logged out of Facebook. However, we did not store these identifiers for logged out users. Therefore, we could not have used this information for tracking or any other purpose. In addition, we fixed the cookies so that they won't include unique information in the future when people log out.
I asked if I could also get a PR statement (like I did last time), but was denied. "That is the statement," the spokesperson told me.
See also:
- Facebook tracks you online even after you log out
- Facebook denies cookie tracking allegations
- Facebook offers new privacy policy for regular people
- Facebook moves privacy controls inline, simplifies sharing
- Facebook kills Places, but emphasizes location sharing more
- Security experts have mixed feelings about Facebook's privacy revamp
Photo credit: fairytalefrosting
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback
RE: Facebook fixes cookie behavior after logging out
RE: Facebook fixes cookie behavior after logging out
RE: Facebook fixes cookie behavior after logging out
Why should webelievee you? Facebook has a history of lying thats a fact. Idon'tt trust you as well, nothing here to say trust him
Quote
Facebook has changed as much as they can change with the logout issue. They want to retain the ability to track browsers after logout for safety and spam purposes
End Quote
That clearly says they are still tracking. And there are alot of "tracking cookies" cookies tthemselvesthemselfs from deletion so like i said why should we trust you.
RE: Facebook fixes cookie behavior after logging out
fdss
Badge Reel http://www.chinawholesaletown.com/wholesale-Digital-Money-Bank/ Car Mini Refrigerator Car Mini Refrigerator
Book Light http://www.chinawholesaletown.com/wholesale-Hockey-Set/ Wholesale Scale Wholesale USB Products
Lunch Box http://www.chinawholesaletown.com/wholesale-Cell-Phone-Sticky-Screen-Cleaner_93119/ Wholesale Tie Wholesale Apron
Wholesale Ruler http://www.chinawholesaletown.com/wholesale-Electric-Heating-Mugs/ Wholesale Scissors Wholesale Frisbee
Wholesale Scale http://www.chinawholesaletown.com/wholesale-Extraordinary-Shape-Clock/ China Wholesale Wholesale Playing Card
Sport Items http://www.chinawholesaletown.com/wholesale-Washing-Powder/ Wholesale USB Products CD Holde
Wholesale Golf Products http://www.chinawholesaletown.com/wholesale-Cell-Phone-Cleaner/ Wholesale Badge Wholesale iPod iPhone
Wholesale Compass http://www.chinawholesaletown.com/wholesale-Glass-Crystal-Clocks/ Wholesale Mirror Wholesale TelePhone
Outdoor Leisure Products http://www.chinawholesaletown.com/wholesale-Clip-Dispenser/ Silicone Products Promotional Products
Money Clip http://www.chinawholesaletown.com/wholesale-Stamps/ Wholesale Racks Wholesale Compressed Products
Sport Support Products http://www.chinawholesaletown.com/wholesale-Radius-Gauge/ Wine Pouch Wholesale Fan
Manicure Set http://www.chinawholesaletown.com/wholesale-Fish-Scale/ Pet Carrier Wholesale Umbrella
Wholesale Calculator http://www.chinawholesaletown.com/wholesale-Collapsible-Water-Bottle/ Pet Waste Bag Dispenser Coin Bank
Wholesale Pom Poms http://www.chinawholesaletown.com/wholesale-Fish-Scale/ Hockey Stick Pet Carrier
Wholesale Sticker http://www.chinawholesaletown.com/wholesale-Fruitpick/ Automotive Products Promotional Items
Ice Players Stick http://www.chinawholesaletown.com/wholesale-Bar-Caddy/ Wholesale Coaster Corner Flag
Digital Photo Frame http://www.chinawholesaletown.com/wholesale-Heart-Tin-Box/ Coca Cola Gifts Wholesale Scale
Wholesale USB Flash Drive http://www.chinawholesaletown.com/wholesale-Ring-Opener/ Safety Suppliers Jute Bag
Wholesale Thermometer http://www.chinawholesaletown.com/wholesale-Tin-CD-Case/ Wholesale Bedding Wholesale lable
Tube Cooler http://www.chinawholesaletown.com/wholesale-Corner-Flags/ Wholesale Golf Products Wholesale Banner
Beach Towel http://www.chinawholesaletown.com/wholesale-Car-Mini-Refrigerator/ Wholesale Halloween Gift Safety Suppliers
Wholesale Fan http://www.chinawholesaletown.com/wholesale-Ring-Opener/ Corner Flag Wholesale Binoculars
Waterproof Hard Case http://www.chinawholesaletown.com/wholesale-Fleece-Blanket/ Wholesale T-Shirts Home Appliances
Glass Rimmers http://www.chinawholesaletown.com/wholesale-Poncho-With-Key-Chain-Ball/ Inflatable Products Wholesale Album
Poncho Keychain http://www.chinawholesaletown.com/wholesale-Silicone-Cake-Mould/ Valentine Gifts Pet Dog Leash
Wholesale Vuvuzela http://www.chinawholesaletown.com/wholesale-Shaving-Set/ Bingo Bag Wholesale Glove
Wholesale Pin http://www.chinawholesaletown.com/wholesale-Folding-Caps/ Tape Measure Abacus
Wholesale Knife http://www.chinawholesaletown.com/wholesale-Whistle-Buckle/ Manicure Set Dog Waste Bag Dispenser
Tangle Puzzle http://www.chinawholesaletown.com/wholesale-Bingo-Bag/ Arts Crafts Wholesale Halloween Gift
Wholesale lable http://www.chinawholesaletown.com/wholesale-Hockey-Set/ Wholesale Knife Mini DV
Wholesale TelePhone http://www.chinawholesaletown.com/wholesale-Clap-Hands/ Wholesale Cards Computer Accessories
Wholesale Cap http://www.chinawholesaletown.com/wholesale-Stamper-Pen/ Pet Dog Leash Safety Products
Wholesale Glove http://www.chinawholesaletown.com/wholesale-Dumbbell/ Burlap Drawstring Bag Lunch Box
Wholesale Keychain http://www.chinawholesaletown.com/wholesale-Fruitpick/ Wholesale Glass Wholesale Camera
Wholesale Tie http://www.chinawholesaletown.com/wholesale-Fruitpick/ Promotional Gifts Muslim Products
Decision Maker http://www.chinawholesaletown.com/wholesale-Baby-Bib/ Wholesale Candle Wholesale Calendar
Tape Measure http://www.chinawholesaletown.com/wholesale-Tourniquet/ Flash Gift Book Light
Wholesale Kitchenware http://www.chinawholesaletown.com/wholesale-Coin-Tray/ Wholesale Compressed Products Wholesale Lanyard
Silicone Products http://www.chinawholesaletown.com/wholesale-Level-Ruler---Digital-Level/ Wholesale Thermometer Wholesale Keyboard
Promotional Items http://www.chinawholesaletown.com/wholesale-Clip-Dispenser/ Wholesale Camera Bar Holder Tray
China Wholesale http://www.chinawholesaletown.com/wholesale-Egg-Shakers/ Business Gift Wholesale Hardware Tools
So, Facebook tracks you online, even when logged out?
RE: Facebook fixes cookie behavior after logging out
RE: Facebook fixes cookie behavior after logging out
RE: Facebook fixes cookie behavior after logging out
it's users. This is a ZDnet cookie on my computer:
region
connectionspeed
satellite
regionconf
metrocode
countryconf
country
usa
city
atlanta
cityconf
citycode
domain
regioncode
latitude
longittude
Is all this information needed just to read an article?
cookie abuse
RE: Facebook fixes cookie behavior after logging out
Can you please try to explain to me what your IT iliterate congresswoman doesn't understand? Specifically what type of abuse gets under your skin?
Just run CCleaner...
zdnet spyware be gone!
RE: Facebook fixes cookie behavior after logging out
NOPE, but then it isn't designed for our intention, it is designed for THEIRS!
RE: Facebook fixes cookie behavior after logging out
RE: Facebook fixes cookie behavior after logging out
RE: Facebook fixes cookie behavior after logging out