Skip to content
The English Post – Breaking News, Politics, Entertainment, Sports

The English Post – Breaking News, Politics, Entertainment, Sports

Primary Menu
  • Home
  • Top Stories
  • City
    • Metro Cities
      • Bengaluru
      • Top Stories
      • Chennai
      • Delhi
      • Hyderabad
      • Kolkata
      • Mumbai
    • Other Cities
      • Agra
      • Agartala
      • Ajmer
      • Ahmedabad
      • Prayagraj
      • Amritsar
      • Amravati
      • Aurangabad
      • Bhopal
      • Bareilly
      • Bhubneshwar
      • Chandigarh
      • Coimbatore
      • Cuttak
      • Dehradun
      • Faridabad
      • Ghaziabad
      • Gandhinagar
      • Goa
      • Gorakhpur
      • Gurugram
      • Guhawati
      • Indore
      • Imphal
      • Jaipur
      • Jammu
      • Jamshedpur
      • Jodhpur
      • Kanpur
      • Kozhikode
      • Kochi
      • Lucknow
      • Ludhiana
      • Meerut
      • Mysore
      • Madurai
      • Nagpur
      • Nashik
      • Noida
      • Patna
      • Puducherry
      • Pune
      • Raipur
      • Rajkot
      • Ranchi
      • Shimla
      • Shillong
      • Srinagar
      • Surat
      • Thane
      • Thiruvananthapuram
      • Udaipur
      • Vadodara
      • Varanasi
      • Vijayawada
      • Visakhapatnam
  • India
  • World
    • Asia
    • US
    • Middle East
    • Europe
  • Sports
    • World Cup 2019
  • Gadgets
  • Entertainment
  • Business
  • News In Brief
  • More
    • Education
    • Fashion
    • Auto
    • Science & Technology
  • Home
  • Gadgets
  • Third-parties abusing ‘Facebook Login’ to steal users’ data: Report
  • Gadgets
  • Latest News

Third-parties abusing ‘Facebook Login’ to steal users’ data: Report

Abhinandan April 19, 2018, 10:58 AM IST
face_480x480

San Francisco :  Several third-party trackers are abusing Facebook Login, exfiltrating users’ data including name, email address, age range, gender, locale and profile photo, a new security research report has claimed.

The unintended exposure of Facebook data to third party JavaScript trackers is not owing to a bug in Facebook’s Login feature.

“Rather, it is due to the lack of security boundaries between the first-party and third-party scripts in today’s web,” said the report prepared by Steven Englehardt, Gunes Acar and Arvind Narayanan, researchers at Freedom to Tinker — a digital initiative by Princeton University’s Center for Information Technology Policy.

“We report yet another type of surreptitious data collection by third-party scripts that we discovered: the exfiltration of personal identifiers from websites through “login with Facebook” and other such social login APIs,” the trio wrote.

Meanwhile, Facebook told the technology website Tech Crunch that they were investigating into the security research report.

The researchers found two types of vulnerabilities: Seven third parties abusing websites’ access to Facebook user data and one third party using its own Facebook “application” to track users around the web.

British political consultancy firm Cambridge Analytica was found misusing users’ data collected by a Facebook quiz app which used the “Login with Facebook” feature.

“We’ve uncovered an additional risk: when a user grants a website access to their social media profile, they are not only trusting that website but also third parties embedded on that site,” the report noted.

The researchers found seven scripts collecting Facebook user data using the first party’s Facebook access.

“These scripts are embedded on a total of 434 of the top 1 million sites, including fiverr.com, bhphotovideo.com, and mongodb.com,” they wrote.

The user ID collected through the Facebook API is specific to the website (or the “application” in Facebook’s terminology), which would limit the potential for cross-site tracking.

“But these app-scoped user IDs can be used to retrieve the global Facebook ID, user’s profile photo, and other public profile information, which can be used to identify and track users across websites and devices,” the researchers warned.

“While we can’t say how these trackers use the information they collect, we can examine their marketing material to understand how it may be used,” they noted.

OnAudience, Tealium AudienceStream, Lytics, and ProPS all offer some form of “customer data platform”, which collect data to help publishers to better monetise their users.

Forter offers “identity-based fraud prevention” for e-commerce sites while Augur offers cross-device tracking and consumer recognition services.

Hidden third-party trackers can also use “Facebook Login to deanonymise users for targeted advertising”.

“This is a privacy violation, as it is unexpected and users are unaware of it,” the researchers said.

There are steps Facebook and other social login providers can still take to prevent abuse.

“API use can be audited to review how, where, and which parties are accessing social login data. Facebook could also disallow the lookup of profile picture and global Facebook IDs by app-scoped user IDs,” the report emphasised.

“It might also be the right time to make Anonymous Login with Facebook available following its announcement four years ago,” the researchers added.

IANS

Post navigation

Previous: Learn coding on mobile with Google’s Grasshopper app
Next: SC dismisses plea for SIT probe in Judge Loya case

More Stories

Elon Musk IANS (1)
  • Gadgets
  • India

Social media platform X has been acquired by this company, know more about this deal

Abhinandan March 29, 2025, 2:24 PM IST
Starlink (1) (1)
  • Gadgets
  • India
  • Top Stories

This Indian company has partnered with Elon Musk’s SpaceX to bring Starlink’s high-speed internet to India

Abhinandan March 11, 2025, 11:26 PM IST
One Plus CE 4 Lite (1)
Photo: IANS
  • Gadgets
  • India

OnePlus launches Nord CE 4 Lite 5G with 50MP camera in India

Abhinandan June 25, 2024, 1:36 PM IST

Follow us on Twitter

Tweets by @thenglishpost

Follow Our Facebook Page

You may have missed

WhatsApp ChatGPT Image Nov 29, 2025, 11_45_11 PM (1)
  • India
  • Top Stories

Govt orders WhatsApp, Telegram, other apps to block access without active SIM

Abhinandan November 30, 2025, 1:55 AM IST 0
Shri Prakash Jaiswal 2 (1)
  • India
  • Top Stories

Former Union Minister Shriprakash Jaiswal passes away at 81

Abhinandan November 29, 2025, 1:16 AM IST 0
Donald Trump 2233 (1) (1)
  • Top Stories
  • World

President Trump calls this country “Hellhole On Earth” and then said it would pay a heavy price

Abhinandan November 27, 2025, 4:47 PM IST 0
Fire in hongkong buildings 44 dead IANS (1) (1)
  • Top Stories
  • World

44 killed as massive fire engulfs high-rise buildings in Hong Kong, 3 arrested

Abhinandan November 27, 2025, 10:19 AM IST 0
Police Investigating ChatGPT Image Nov 26, 2025, 05_10_45 PM (1)
  • India
  • Top Stories

Pan masala tycoon’s daughter-in-law found dead in Delhi home; suicide suspected

Abhinandan November 26, 2025, 5:16 PM IST 0
  • About Us
  • Advertise With Us
  • Contact Us
  • Disclaimer
  • Greviance Redressal
  • Privacy Policy
  • Terms of Services
Copyright © All rights reserved. | CoverNews by AF themes.