<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Data Sharing with Facebook&#8217;s Beacon</title>
	<atom:link href="http://fstutzman.com/2007/11/10/data-sharing-with-facebooks-beacon/feed/" rel="self" type="application/rss+xml" />
	<link>http://fstutzman.com/2007/11/10/data-sharing-with-facebooks-beacon/</link>
	<description>Thoughts about information, social networks, and privacy</description>
	<lastBuildDate>Fri, 06 Jan 2012 21:54:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: fred</title>
		<link>http://fstutzman.com/2007/11/10/data-sharing-with-facebooks-beacon/comment-page-1/#comment-1035</link>
		<dc:creator>fred</dc:creator>
		<pubDate>Mon, 03 Dec 2007 01:22:00 +0000</pubDate>
		<guid isPermaLink="false">http://127.0.0.1/~fred/projects/blog/?p=523#comment-1035</guid>
		<description>A couple other sources have picked up this story.  Find coverage here on &lt;a HREF=&quot;http://www.pcworld.com/article/id,140182-c,onlineprivacy/article.html&quot; REL=&quot;nofollow&quot;&gt;PC World&lt;/a&gt;, which cites a &lt;a HREF=&quot;http://community.ca.com/blogs/securityadvisor/archive/2007/11/29/facebook-s-misrepresentation-of-beacon-s-threat-to-privacy-tracking-users-who-opt-out-or-are-not-logged-in.aspx&quot; REL=&quot;nofollow&quot;&gt;Computer Associates blog post&lt;/a&gt; that did the same cookie analysis as mine.&lt;br/&gt;&lt;br/&gt;To a certain extent, this coverage is piling-on, but we should be aware of who is tracking us and for what reasons.  A similar gaze should be cast upon Google.</description>
		<content:encoded><![CDATA[<p>A couple other sources have picked up this story.  Find coverage here on <a HREF="http://www.pcworld.com/article/id,140182-c,onlineprivacy/article.html" REL="nofollow">PC World</a>, which cites a <a HREF="http://community.ca.com/blogs/securityadvisor/archive/2007/11/29/facebook-s-misrepresentation-of-beacon-s-threat-to-privacy-tracking-users-who-opt-out-or-are-not-logged-in.aspx" REL="nofollow">Computer Associates blog post</a> that did the same cookie analysis as mine.</p>
<p>To a certain extent, this coverage is piling-on, but we should be aware of who is tracking us and for what reasons.  A similar gaze should be cast upon Google.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fred</title>
		<link>http://fstutzman.com/2007/11/10/data-sharing-with-facebooks-beacon/comment-page-1/#comment-1021</link>
		<dc:creator>fred</dc:creator>
		<pubDate>Thu, 15 Nov 2007 17:32:00 +0000</pubDate>
		<guid isPermaLink="false">http://127.0.0.1/~fred/projects/blog/?p=523#comment-1021</guid>
		<description>You&#039;ve got to rate a recipe to encounter Beacon.</description>
		<content:encoded><![CDATA[<p>You&#8217;ve got to rate a recipe to encounter Beacon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Niebylski</title>
		<link>http://fstutzman.com/2007/11/10/data-sharing-with-facebooks-beacon/comment-page-1/#comment-1020</link>
		<dc:creator>Niebylski</dc:creator>
		<pubDate>Thu, 15 Nov 2007 17:28:00 +0000</pubDate>
		<guid isPermaLink="false">http://127.0.0.1/~fred/projects/blog/?p=523#comment-1020</guid>
		<description>I loaded a Recipe page on Epicurious to see this in action but dont get any of the Pop-ups asking me if its OK to send info to Facebook (I have gotten them at Hotwire.com, so I know what i&#039;m looking for); I took a look at the Page Source and saw the reference to the Beacon JavaScript in the HTML Header - but no reference in the page Body (none of the c_user,login,etc. info that you covered in your post)  &lt;br/&gt;I wonder what determines whether or not the service is loaded on a page or not...I have a Facebook account and have been targeted by Beacon before, so why not now, when I&#039;m looking at an Apple-Cranberry Crisp recipe on Epicurious?</description>
		<content:encoded><![CDATA[<p>I loaded a Recipe page on Epicurious to see this in action but dont get any of the Pop-ups asking me if its OK to send info to Facebook (I have gotten them at Hotwire.com, so I know what i&#8217;m looking for); I took a look at the Page Source and saw the reference to the Beacon JavaScript in the HTML Header &#8211; but no reference in the page Body (none of the c_user,login,etc. info that you covered in your post)  <br />I wonder what determines whether or not the service is loaded on a page or not&#8230;I have a Facebook account and have been targeted by Beacon before, so why not now, when I&#8217;m looking at an Apple-Cranberry Crisp recipe on Epicurious?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cameronmarlow</title>
		<link>http://fstutzman.com/2007/11/10/data-sharing-with-facebooks-beacon/comment-page-1/#comment-1017</link>
		<dc:creator>Cameronmarlow</dc:creator>
		<pubDate>Tue, 13 Nov 2007 19:59:00 +0000</pubDate>
		<guid isPermaLink="false">http://127.0.0.1/~fred/projects/blog/?p=523#comment-1017</guid>
		<description>@Anonymous, I think if you do a little inspection on your Google cookies, you&#039;ll find that there are a few that uniquely identify you, namely your NID. This will follow you when you log in, regardless of what browser, machine, or IP address you&#039;re coming from. I haven&#039;t done any tests, but my guess is that you&#039;re assigned a random ID when you first visit a web page, then transitioned to your permanent ID if you log into any of Google&#039;s services.&lt;br/&gt;&lt;br/&gt;If you think Facebook is scary, Google already has &quot;beacons&quot; on every page containing AdSense. This means that every page you visit which has a &quot;Ads By Google&quot; box on it is tracking which pages you visit, which sites they&#039;re on, and connecting this to your search query logs.&lt;br/&gt;&lt;br/&gt;Frankly, I think the fact that Facebook puts this information in the public and typically allows you to edit it ex post facto means that they&#039;re concerned about people&#039;s feelings about the way their data is being used. I&#039;m not sure I can say the same about other companies with the same level of personal information.</description>
		<content:encoded><![CDATA[<p>@Anonymous, I think if you do a little inspection on your Google cookies, you&#8217;ll find that there are a few that uniquely identify you, namely your NID. This will follow you when you log in, regardless of what browser, machine, or IP address you&#8217;re coming from. I haven&#8217;t done any tests, but my guess is that you&#8217;re assigned a random ID when you first visit a web page, then transitioned to your permanent ID if you log into any of Google&#8217;s services.</p>
<p>If you think Facebook is scary, Google already has &#8220;beacons&#8221; on every page containing AdSense. This means that every page you visit which has a &#8220;Ads By Google&#8221; box on it is tracking which pages you visit, which sites they&#8217;re on, and connecting this to your search query logs.</p>
<p>Frankly, I think the fact that Facebook puts this information in the public and typically allows you to edit it ex post facto means that they&#8217;re concerned about people&#8217;s feelings about the way their data is being used. I&#8217;m not sure I can say the same about other companies with the same level of personal information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://fstutzman.com/2007/11/10/data-sharing-with-facebooks-beacon/comment-page-1/#comment-1016</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Tue, 13 Nov 2007 19:44:00 +0000</pubDate>
		<guid isPermaLink="false">http://127.0.0.1/~fred/projects/blog/?p=523#comment-1016</guid>
		<description>there is in fact something new.&lt;br/&gt;&lt;br/&gt;with doubleclick and other ad-networks - there was always a well defined way of clearing any information in the cookies. Kill the browser and/or clear the cookies. With Facebook - the data is being stored against a persistent userid and the user can never get rid of the logged data. Ad Networks also provide a standard opt-out site - see http://www.networkadvertising.org/managing/opt_out.asp&lt;br/&gt;&lt;br/&gt;and besides - the Doubleclick cookie is just an identifier for the browser - not for the user&#039;s identity. It&#039;s not portable from one machine to another. And doubleclick doesn&#039;t have our name and address.&lt;br/&gt;&lt;br/&gt;I think what&#039;s being attempted is unprecedented. Yahoo and Google have never done this before either.</description>
		<content:encoded><![CDATA[<p>there is in fact something new.</p>
<p>with doubleclick and other ad-networks &#8211; there was always a well defined way of clearing any information in the cookies. Kill the browser and/or clear the cookies. With Facebook &#8211; the data is being stored against a persistent userid and the user can never get rid of the logged data. Ad Networks also provide a standard opt-out site &#8211; see <a href="http://www.networkadvertising.org/managing/opt_out.asp" rel="nofollow">http://www.networkadvertising.org/managing/opt_out.asp</a></p>
<p>and besides &#8211; the Doubleclick cookie is just an identifier for the browser &#8211; not for the user&#8217;s identity. It&#8217;s not portable from one machine to another. And doubleclick doesn&#8217;t have our name and address.</p>
<p>I think what&#8217;s being attempted is unprecedented. Yahoo and Google have never done this before either.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fred</title>
		<link>http://fstutzman.com/2007/11/10/data-sharing-with-facebooks-beacon/comment-page-1/#comment-1015</link>
		<dc:creator>fred</dc:creator>
		<pubDate>Tue, 13 Nov 2007 15:23:00 +0000</pubDate>
		<guid isPermaLink="false">http://127.0.0.1/~fred/projects/blog/?p=523#comment-1015</guid>
		<description>Cameron, I agree - that&#039;s why I included my caveat.  There really isn&#039;t anything new here.  To that extent, it seems likely these privacy &quot;concerns&quot; won&#039;t resonate, except with tin foil hat types like me.  &lt;br/&gt;&lt;br/&gt;Where it gets interesting is in the confrontation.  How are people going to react as Facebook follows them around the web, and their actions confront them when they log back in to Facebook?   &lt;br/&gt;&lt;br/&gt;Perhaps it will be a big deal, perhaps it won&#039;t...thats the trouble with privacy.  We say we care, but...</description>
		<content:encoded><![CDATA[<p>Cameron, I agree &#8211; that&#8217;s why I included my caveat.  There really isn&#8217;t anything new here.  To that extent, it seems likely these privacy &#8220;concerns&#8221; won&#8217;t resonate, except with tin foil hat types like me.  </p>
<p>Where it gets interesting is in the confrontation.  How are people going to react as Facebook follows them around the web, and their actions confront them when they log back in to Facebook?   </p>
<p>Perhaps it will be a big deal, perhaps it won&#8217;t&#8230;thats the trouble with privacy.  We say we care, but&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cameronmarlow</title>
		<link>http://fstutzman.com/2007/11/10/data-sharing-with-facebooks-beacon/comment-page-1/#comment-1014</link>
		<dc:creator>Cameronmarlow</dc:creator>
		<pubDate>Tue, 13 Nov 2007 14:59:00 +0000</pubDate>
		<guid isPermaLink="false">http://127.0.0.1/~fred/projects/blog/?p=523#comment-1014</guid>
		<description>Hey Fred,&lt;br/&gt;&lt;br/&gt;This is the standard method used by pretty much all advertising networks to target advertising. You&#039;ll find that the practices of DoubleClick, Yahoo and Google preempt this move by Facebook. Any request made to a web server will send the cookies on your machine which have been stored by the given server. When you are logged in to Facebook, your Facebook ID is stored as a cookie on your computer, and when you make a request to the beacon server, this information is sent along with the request.&lt;br/&gt;&lt;br/&gt;Services like DoubleClick do this without your even being &quot;logged in,&quot; meaning that they store cookies on your machine regardless of your intent, and connect your activity across any number of sites which their advertising is displayed on.&lt;br/&gt;&lt;br/&gt;The flip-side of this privacy concern is the extent to which advertising networks can provide you with relevant advertising. You can always turn off cookies altogether (or just log out of Facebook when you&#039;re not using their site). This way the DoubleClicks and Facebooks won&#039;t be able to &quot;see&quot; you on these sites unless they correlate your IP address on their side. But these networks (and I assume Facebook) would argue that your experience would be diminished, getting advertisements that are unrelated and distracting.&lt;br/&gt;&lt;br/&gt;It&#039;s a tough line to tow, but that&#039;s the current tradeoff posed by advertising networks. I guess there&#039;s something to be said for the fact that you can &lt;a HREF=&quot;http://www.doubleclick.com/privacy/index.aspx&quot; REL=&quot;nofollow&quot;&gt;opt out of DoubleClick&lt;/a&gt; while search providers do not offer a similar service and are collecting &lt;a HREF=&quot;http://en.wikipedia.org/wiki/AOL_search_data_scandal&quot; REL=&quot;nofollow&quot;&gt;much more sensitive data&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>Hey Fred,</p>
<p>This is the standard method used by pretty much all advertising networks to target advertising. You&#8217;ll find that the practices of DoubleClick, Yahoo and Google preempt this move by Facebook. Any request made to a web server will send the cookies on your machine which have been stored by the given server. When you are logged in to Facebook, your Facebook ID is stored as a cookie on your computer, and when you make a request to the beacon server, this information is sent along with the request.</p>
<p>Services like DoubleClick do this without your even being &#8220;logged in,&#8221; meaning that they store cookies on your machine regardless of your intent, and connect your activity across any number of sites which their advertising is displayed on.</p>
<p>The flip-side of this privacy concern is the extent to which advertising networks can provide you with relevant advertising. You can always turn off cookies altogether (or just log out of Facebook when you&#8217;re not using their site). This way the DoubleClicks and Facebooks won&#8217;t be able to &#8220;see&#8221; you on these sites unless they correlate your IP address on their side. But these networks (and I assume Facebook) would argue that your experience would be diminished, getting advertisements that are unrelated and distracting.</p>
<p>It&#8217;s a tough line to tow, but that&#8217;s the current tradeoff posed by advertising networks. I guess there&#8217;s something to be said for the fact that you can <a HREF="http://www.doubleclick.com/privacy/index.aspx" REL="nofollow">opt out of DoubleClick</a> while search providers do not offer a similar service and are collecting <a HREF="http://en.wikipedia.org/wiki/AOL_search_data_scandal" REL="nofollow">much more sensitive data</a>.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

