this post was submitted on 28 Aug 2024
26 points (100.0% liked)

Technology

59601 readers
2940 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] intensely_human@lemm.ee 0 points 2 months ago (3 children)

Aren’t cookies already limited to the site at which they were created??

What the fuck? You mean to tell me sites have been sharing cookies?

I thought all browsers only delivered cookies back to the same site.

[–] unemployedclaquer@sopuli.xyz 0 points 2 months ago

NO.

https://en.m.wikipedia.org/wiki/Third-party_cookies

Maybe it's not allowed in your local jurisdiction? But it's been a problem since forever.

[–] Mongostein@lemmy.ca 0 points 2 months ago* (last edited 2 months ago) (1 children)

I know Facebook and Reddit are in cahoots.

I went to visit Reddit a couple weeks back to read the Deadpool & Wolverine comments, but used the wrong container tab and now Facebook feeds me endless Marvel related stuff.

A lot of it is culture war bullshit too. Hmmmmm 🤔

[–] lud@lemm.ee 0 points 2 months ago (1 children)

No, you don't know anything. Just because you have a suspicion because something happened to you once doesn't mean you are sure in any way.

[–] Mongostein@lemmy.ca 0 points 2 months ago (1 children)

Nah I’m sure.

I never once saw a post about Marvel fed to me by Facebook and now it’s constant

[–] lud@lemm.ee 0 points 2 months ago (2 children)

Did it start after the extremely popular marvel movie "Deadpool and Wolverine" released?

[–] Mongostein@lemmy.ca 0 points 2 months ago* (last edited 2 months ago) (1 children)

Before. “Couple weeks” is more like 5 months at this point now that I think about it.

I don’t mind some of it much, but the obvious culture-war bait is infuriating.

It’s not because the movie just came out. I’ve been diligent about keeping Facebook and Reddit in their container tabs for years. It’s just Marvel stuff, not just the movies. Marvel’s been putting out huge movies for years and this hasn’t happened around any of their other releases.

[–] lud@lemm.ee 0 points 2 months ago (1 children)

Why aren't you just using the official automatic Facebook container?

[–] Mongostein@lemmy.ca 0 points 2 months ago

I made it before that was a thing. Habit I guess. 🤷‍♂️

[–] 11111one11111@lemmy.world 0 points 2 months ago (1 children)

Lol that's your argument for why you think they don't know what they're talking about? Because all you did is make yourself seem like you have no idea how cookies work 🤣

[–] lud@lemm.ee 0 points 2 months ago

It's just one single person who noticed something once.

That's an awful awful sample size absolutely filled with bias and thought fallacies.

[–] Dave@lemmy.nz 0 points 2 months ago (3 children)

The problem is that a website is generally not served from one domain.

Put a Facebook like button on your website, it's loaded directly from Facebook servers. Now they can put a cookie on your computer with an identifier.

Now every site you visit with a Facebook like button, they know it was you. They can watch you as you move around the web.

Google does this at a larger scale. Every site with Google ads on it. Every site using Google analytics. Every site that embeds a Google map. They can stick a cookie in and know you were there.

[–] MonkderVierte@lemmy.ml 0 points 2 months ago (1 children)

Put a Facebook like button on your website, it's loaded directly from Facebook servers. Now they can put a cookie on your computer with an identifier.

Which is not allowed by GDPR btw, because they do that even if you don't click them. There are plenty guides online, how to create your own, not tracking facebook like button.

[–] Dave@lemmy.nz 0 points 2 months ago (1 children)

How does GDPR fit in to Google Analytics and personalised ads?

I would have thought it went something like: random identifier: not linked to personal info, just a collection of browsing history for an unidentified person, not under GDPR as not personal info.

Link to account: let them request deletion (or more specifically, delinking the info from your account is what Facebook lets you do), GDPR compliant.

Both Google and Facebook run analytics software that tracks users. I presume letting people request deletion once it's personally linked to them is probably what let's them do it? But I don't live in a GDPR country, so I don't know a whole lot about it.

[–] MonkderVierte@lemmy.ml 0 points 2 months ago

No, it should've been opt-in. But loophole with "vital interest" and politics being slow and surface-level like politics.

[–] intensely_human@lemm.ee 0 points 2 months ago (1 children)

Is that because the like button is an iframe?

[–] Dave@lemmy.nz 0 points 2 months ago (2 children)

It doesn't have to be. Your browser sends the cookies for a domain with every request to that domain. So you have a website example.com, that embeds a Facebook like button from Facebook.com.

When your browser downloads the page, it requests the different pieces of the page. It requests the main page from example.com, your browser sends any example.com cookies with the request.

Your browser needs the javascript, it sends the cookie in the request to get the JavaScript file. It needs the like button, it sends a request off to Facebook.com and sends the Facebook.com cookies with it.

Note that the request to example.com doesn't send the cookies for Facebook.com, and the request to Facebook.com doesn't send the cookie for example.com to Facebook. However, it does tell Facebook.com that the request for the like button came from example.com.

Facebook puts an identifier in the cookie, and any request to Facebook sends that cookie and the site it was loaded on.

So you log in to Facebook, it puts an identifier in your cookies. Now whenever you go to other sites with a Facebook like button (or the Facebook analytics stuff), Facebook links that with your profile.

Not logged in? Facebook sets an identifier to track you anyway, and links it up when you make an account or log in.

[–] Nightsoul@lemmy.world 0 points 2 months ago

Thank you for the explanation!

[–] intensely_human@lemm.ee 0 points 2 months ago (1 children)

How is Facebook able to know what site is requesting it? Is it in the referer header, or is it parameters in the javascript/image url?

[–] Dave@lemmy.nz 0 points 2 months ago

There is a referer header sent, but depending on the exact code added to the page, it's very likely they are loading a snippet of JavaScript that lets them collect other information and trigger their own sending of information to their server.

For example, Google Analytics has javascript added to the page, but loading fonts from Google's CDN (which many sites do) will rely on the referer.

[–] FuryMaker@lemmy.world 0 points 2 months ago (1 children)

Is this also how they know which ads to feed you?

[–] Dave@lemmy.nz 0 points 2 months ago

Yes, it's the reason for the tracking. To sell more targeted ads.

If you're up for reading some shennanigans, check out the book Mindf*ck. It's about the Cambridge Analytica scandal, written by a whistleblower, and details election manipulation using data collected from Facebook and other public or purchased data.