San Francisco, April 19: Several third-party trackers are abusing Facebook Login, exfiltrating users' data including name, email address, age range, gender, locale and profile photo, a new security research report has claimed.

The unintended exposure of Facebook data to third party JavaScript trackers is not owing to a bug in Facebook's Login feature.

"Rather, it is due to the lack of security boundaries between the first-party and third-party scripts in today's web," said the report prepared by Steven Englehardt, Gunes Acar and Arvind Narayanan, researchers at Freedom to Tinker -- a digital initiative by Princeton University's Center for Information Technology Policy.

"We report yet another type of surreptitious data collection by third-party scripts that we discovered: the exfiltration of personal identifiers from websites through "login with Facebook" and other such social login APIs," the trio wrote.

Meanwhile, Facebook told the technology website TechCrunch that they were investigating into the security research report.

The researchers found two types of vulnerabilities: Seven third parties abusing websites' access to Facebook user data and one third party using its own Facebook "application" to track users around the web.

British political consultancy firm Cambridge Analytica was found misusing users' data collected by a Facebook quiz app which used the "Login with Facebook" feature.

"We've uncovered an additional risk: when a user grants a website access to their social media profile, they are not only trusting that website but also third parties embedded on that site," the report noted.

The researchers found seven scripts collecting Facebook user data using the first party's Facebook access.

"These scripts are embedded on a total of 434 of the top 1 million sites, including fiverr.com, bhphotovideo.com, and mongodb.com," they wrote.

The user ID collected through the Facebook API is specific to the website (or the "application" in Facebook's terminology), which would limit the potential for cross-site tracking.

"But these app-scoped user IDs can be used to retrieve the global Facebook ID, user's profile photo, and other public profile information, which can be used to identify and track users across websites and devices," the researchers warned.

"While we can't say how these trackers use the information they collect, we can examine their marketing material to understand how it may be used," they noted.

OnAudience, Tealium AudienceStream, Lytics, and ProPS all offer some form of "customer data platform", which collect data to help publishers to better monetise their users.

Forter offers "identity-based fraud prevention" for e-commerce sites while Augur offers cross-device tracking and consumer recognition services.

Hidden third-party trackers can also use "Facebook Login to deanonymise users for targeted advertising".

"This is a privacy violation, as it is unexpected and users are unaware of it," the researchers said.

There are steps Facebook and other social login providers can still take to prevent abuse.

"API use can be audited to review how, where, and which parties are accessing social login data. Facebook could also disallow the lookup of profile picture and global Facebook IDs by app-scoped user IDs," the report emphasised.

"It might also be the right time to make Anonymous Login with Facebook available following its announcement four years ago," the researchers added.

 

Let the Truth be known. If you read VB and like VB, please be a VB Supporter and Help us deliver the Truth to one and all.



New Delhi (PTI): The Congress on Saturday shared diary entries of Vallabhbhai Patel's daughter from a book to rebut Defence Minister Rajnath Singh's claim that India's first prime minister, Jawaharlal Nehru, wanted to build the Babri masjid using public funds, and demanded that Singh apologise for spreading "falsehoods".

Congress general secretary in charge of communications, Jairam Ramesh, claimed the defence minister was spreading falsehoods to “improve his relationship” with Prime Minister Narendra Modi.

“Here is Maniben's original diary entry in Gujarati on pages 212-213 in the book ‘Samarpit Padchhayo Sardarno’ by CA R S Patel 'Aaresh', published by Sardar Patel Vallabhbhai Patel Memorial Society, 2025,” Ramesh said on X, sharing screenshots of the relevant pages from the book.

“There is a huge difference between what is contained in the original diary entry and what Rajnath Singh ji and his fellow ‘distorians’ are propagating,” Ramesh said.

“The Defence Minister must apologise for the falsehoods he is spreading, simply to improve his relationship with the PM,” he claimed.

The Congress had earlier termed Singh's claim that Nehru wanted to build the Babri masjid using public funds a “lie” and “WhatsApp university story”, and said the defence minister should not walk in Prime Minister Narendra Modi's path.

Addressing a gathering at Sadhli village in Gujarat's Vadodara district last Tuesday, Singh said Nehru wanted to build the Babri masjid using public funds, but Sardar Vallabhbhai Patel didn't allow his plans to succeed.

The BJP had cited a book by Vallabhbhai Patel's daughter to double down on Singh's claims, and said the first prime minister also said he felt "repelled" by some of the temples in south India despite their beauty.

“The source of what Rajnath Singh said is the 'Inside Story of Sardar Patel, Diary of Maniben Patel'," BJP Rajya Sabha MP and national spokesperson Sudhanshu Trivedi had said at a press conference at the party headquarters while responding to media queries on the issue.

Trivedi claimed that on Page 24 of the book, it is written that Nehru also raised the question of the Babri mosque, but Sardar Patel made it clear that the government could not spend any money on building a mosque.