UPDATED 08:31 EDT / SEPTEMBER 28 2011

Facebook’s Security In Question for Offsite Activity Tracking

Facebook’s security and their users’ privacy had been in question since the very beginning. And those issues were only aggravated with each major Facebook update, especially the auto photo-tagging feature that came out earlier this year.  Since then, some users got vigilant, scrutinizing every aspect of the social network.

A few days ago, Nik Cubrilovic, a blogger who deems himself as an entrepreneur, a hacker and a writer, made news when he exposed some of Facebook’s latest security flaws.  Cubrilovic stated that Facebook is still able to track their users even if they log out because of the Facebook cookies left in your browser’s history.  Cubrilovic examined the cookies while he was logged in and when he logged out.  He stated that the primary cookies that identified him as a Facebook user was still in the history, and that Facebook only alters the state of the cookies instead of removing all of them when a user logs out.  He recommends that you delete all Facebook cookies from your browser history to stop it from tracking all your browsing history.

The evidence Cubrilovic presented was the experiment he did with multiple fake accounts using one browser.  He was baffled as to how Facebook came to recommend his fake accounts to be added in his real account.  This suggests that Facebook monitors all their users’ activities.  He also added that he first informed Facebook of their security flaws back in November of 2010 and made a follow up by January 2011, but he got no response.

Cubrilovic’s accusations were answered by Facebook engineer Gregg Stefancik and said that Facebook doesn’t use the cookies to spy on their users but used “to either provide custom content (e.g. your friend’s likes within a social plugin), help improve or maintain our service (e.g. measuring click-through rates to help optimize performance), or protect our users and our service (e.g. defending denial of service attacks or requiring a second authentication factor for a login from a suspicious location).”

As expected, commentators on Cubrilovic’s page stated their disbelief in Stefancik’s answer and some even went on to bash Facebook and stated the famous line “Remember, remember, the fifth of November” reminding them of hackers’ planed attack on Facebook.

Even if Facebook denied tracking their users when logged out, they still addressed the issue and Cubrilovic showed the changes in his blog post Facebook Fixes and Explains Logout Issue.  Simply put, Facebook destroys cookie identifiers when users log out.

Cubrilovic concluded, “Facebook has changed as much as they can change with the logout issue. They want to retain the ability to track browsers after logout for safety and spam purposes, and they want to be able to log page requests for performance reasons etc. I would still recommend that users clear cookies or use a separate browser, though. I believe Facebook when they describe what these cookies are used for, but that is not a reason to be complacent on privacy issues and to take initiative in remaining safe.”


A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.