https://www.ghacks.net/2022/07/17/facebook-has-started-to-encrypt-links-to-counter-privacy-improving-url-stripping/ ghacks.net * Home * Windows * Linux * Software * Firefox * Chrome * Internet * Mobile Computing * Companies * Email * Misc * Deals * [svg][ghack-logo] * Home * Windows + Windows 11 News + Windows 11 Help + Windows 10 + Windows 8 + Windows 7 + Windows tips + Windows Update * Linux + Linux Mint * Software + Antivirus + Backup + Data Recovery + Encryption + File Sharing + Microsoft Office + Security * Firefox + Firefox add-ons * Chrome + Chrome Extensions * Internet + Brave + Internet Explorer + Microsoft Edge + Opera + Pale Moon + Vivaldi + VPNs + Google Maps + Search * Mobile Computing + Google Android + Apps + iOS * Companies + Amazon + Apple + Facebook + Google + Microsoft + Twitter + Yahoo + Youtube * Email + Gmail + Outlook + Thunderbird * Misc + Crypto & Blockchain + Development + Games + Hardware + Music and Video + Network + Tutorials * Deals Search for: [ ] [Search] ADVERTISEMENT Facebook has started to encrypt links to counter privacy-improving URL Stripping Martin Brinkmann Jul 17, 2022 Facebook | 10 Facebook has started to use a different URL scheme for site links to combat URL stripping technologies that browsers such as Firefox or Brave use to improve privacy and prevent user tracking. facebook encrypted linksfacebook encrypted links Some sites, including Facebook, add parameters to the web address for tracking purposes. These parameters have no functionality that is relevant to the user, but sites rely on them to track users across pages and properties. Mozilla introduced support for URL stripping in Firefox 102, which it launched in June 2022. Firefox removes tracking parameters from web addresses automatically, but only in private browsing mode or when the browser's Tracking Protection feature is set to strict. Firefox users may enable URL stripping in all Firefox modes, but this requires manual configuration. Brave Browser strips known tracking parameters from web addresses as well. ADVERTISEMENT Both web browsers use lists of known tracking parameters for the functionality. The lists need to be updated whenever sites change tracking parameters. Facebook could have changed the scheme that it is using, but this would have given Facebook only temporary recourse. It appears that Facebook is using encryption now to track users. Previously, Facebook used the parameter fbclid for tracking purposes. Now, it uses URLs such as https://www.facebook.com/ghacksnet/posts/ pfbid0RjTS7KpBAGt9FHp5vCNmRJsnmBudyqRsPC7ovp8sh2EWFxve1Mk2HaGTKoRSuVKpl? __cft__[0]= AZXT7WeYMEs7icO80N5ynjE2WpFuQK61pIv4kMN-dnAz27-UrYqrkv52_hQlS_TuPd8dGUNLawATILFs55sMUJvH7SFRqb_WcD6CCOX_zYdsebOW0TWyJ9gT2vxBJPZiAaEaac_zQBShE-UEJfatT-JMQT5-bvmrLz7NlgwSeL6fGKH9oY9uepTio0BHyCmoY1A &__tn__=%2CO%2CP-R instead. The main issue here is that there it is no longer possible to remove the tracking part of the URL, as Facebook merged it with part of the required web address. Removing the entire construct after the ? would open the main Facebook page of Ghacks Technology News, but it won't open the linked post. ADVERTISEMENT Since it is no longer possible to identify the tracking part of the web address, it is no longer possible to remove it from the address automatically. In other words: Facebook has the upper hand in regards to URL-based tracking at the time, and there is little that can be done about it short of finding a way to decrypt the information. Closing words There is no option currently to prevent Facebook's tracking of users via links. Users could avoid Facebook, but that may not be possible all the time. URL tracking does not help much if other tracking means, e.g., through cookies or site data, are not available. While Facebook gets some information from URL-based tracking, it can't link it if no persistent data is available. Users who don't sign into Facebook and clear cookies and site data regularly, may avoid most of the company's tracking. ADVERTISEMENT Now You: what is your take on this development? Beginning of a cat and mouse game, or game over for privacy already? (thanks N.J.) ADVERTISEMENT Summary Facebook has started to encrypt links to counter privacy-improving URL StrippingFacebook has started to encrypt links to counter privacy-improving URL Stripping Article Name Facebook has started to encrypt links to counter privacy-improving URL Stripping Description Facebook has started to use a different URL scheme for site links to combat URL stripping technologies that browsers use to improve privacy and prevent user tracking. Author Martin Brinkmann Publisher Ghacks Technology News Logo Ghacks Technology NewsGhacks Technology News Advertisement About Martin Brinkmann Martin Brinkmann is a journalist from Germany who founded Ghacks Technology News Back in 2005. He is passionate about all things tech and knows the Internet and computers like the back of his hand. You can follow Martin on Facebook or Twitter View all posts by Martin Brinkmann - Related content [svg][mozilla-meta-advertising-ipa] Mozilla and Meta develop privacy preserving advertising tech IPA WhatsApp Web Custom Sticker Maker - Add textWhatsApp Web Custom Sticker Maker - Add text WhatsApp Web gets a Custom Sticker Maker; Desktop version to follow next week facebook privacyfacebook privacy Facebook scatters privacy settings all over the place on mobile WhatsApp's View Once message feature has arrivedWhatsApp's View Once message feature has arrived WhatsApp's View Once message feature has arrived whatsapp view oncewhatsapp view once First look at WhatsApp's View Once media feature whatsapp facebook privacy updatewhatsapp facebook privacy update Facebook caves in: WhatsApp users who don't accept the new privacy policy won't have their accounts deleted Previous Post: << Mozilla and Meta develop privacy preserving advertising tech IPA Comments 1. Gavin B. said on July 17, 2022 at 3:59 pm Reply I bet that adds to the URL's carbon footprint! Facebook v. our planet 2. Yash said on July 17, 2022 at 4:23 pm Reply Yep, although I don't have a Facebook account(or any social media), many other users often share these links in chat groups. URL tracking prevention is tough and dare I say it, an impossible task. But solution is already in the article which works or atleast reduces tracking - 'Users who don't sign into Facebook and clear cookies and site data regularly, may avoid most of the company's tracking.' I would elaborate this for every website, don't sign-in on a website for the sake of it and if clear all data is too much, make site exceptions and clear everything else. 3. Jeremy said on July 17, 2022 at 4:25 pm Reply Clever, they ended this cat and mouse game before it even began. I suppose using a privacy front-end is the only realistic solution for this issue. https://github.com/mendel5/alternative-front-ends This list has some of them, though I personally only use a handful. 4. ECJ said on July 17, 2022 at 4:45 pm Reply "...Users could avoid Facebook, but that may not be possible all the time." Sure it is: 1) Delete your Facebook account. 2) Add the following to uBlock Origin. ||fb.*$important ||facebook.*$important ||fbcdn.*$important ||fbsbx.*$important ||atdmt.com^$important ||instagram.com^$important 3) F*ck Facebook 1. Klaas Vaak said on July 17, 2022 at 5:15 pm Reply @ECJ: where would you put that in uBO: My filters or My rules? 1. ECJ said on July 17, 2022 at 6:09 pm Reply Yes, "My Filters". To be clear though, this isn't a fix for their URL tracking parameters - this outright blocks Facebook and Instagram. 5. B.L. said on July 17, 2022 at 4:54 pm Reply The premise of this article is incorrect. The example URL *can* be stripped of the ?search portion, leaving only http:// www.facebook.com/ghacksnet/posts/ pfbid0RjTS7KpBAGt9FHp5vCNmRJsnmBudyqRsPC7ovp8sh2EWFxve1Mk2HaGTKoRSuVKpl -- which leads to the Intel Arc A750 article just like the full link does. It can be further burnt down to fb.com/ pfbid0RjTS7KpBAGt9FHp5vCNmRJsnmBudyqRsPC7ovp8sh2EWFxve1Mk2HaGTKoRSuVKpl The pfbid contains an encoded version of the old fbid; and a timestamp which isn't the timestamp of the post. So far I haven't figured out how to decode any more of it than the timestamp. (Learned the fbid through a different trick: 7733554110019848 -- fb.com/7733554110019848 leads once again to the Arc A750 article. 6. B.L. said on July 17, 2022 at 4:55 pm Reply Fully linked versions of those: https://fb.com/ pfbid0RjTS7KpBAGt9FHp5vCNmRJsnmBudyqRsPC7ovp8sh2EWFxve1Mk2HaGTKoRSuVKpl https://fb.com/7733554110019848 7. allen said on July 17, 2022 at 5:22 pm Reply One could argue that if you use links provided by/thru facebook, then you deserve whatever tracking you get. This, though, adds more impetus to the idea that "friends don't let friends use facebook." Nope, facebook must not like you (facebook users) very much. 8. Tom Hawack said on July 17, 2022 at 6:43 pm Reply Facebook has started to encrypt links. My take on this development would start with a few exotic words shouldn't the weather be so hot. Zen. Facebook now using encryption to track users. This confirms a company's total lack of respect for of users' privacy. No surprise even if I confess occasional stuns when I discover a company's privacy red line moves further than I could have imagined. > Beginning of a cat and mouse game, or game over for privacy already? The game has been over for all users of Facebook since the very beginning. The only way to keep winning is to avoid Facebook and to block all access to the company's servers : Facebook as well as the GAFAM companies, not to mention twitter and a few others, track users even if they've logged out and even if they have no account in these companies. Facebook is totally avoidable. Google requires fine tuning in order to allow access to its servers only for what we consider as the strict necessary. Remains sites connecting to Google for a font, a script ... the 'LocalCDN' extension handles that quite extensively. Personally? No Facebook account and totally blocked. No Google account and partially blocked (only Google Maps and mainly for its Street View, otherwise I prefer the OpenStreetmap display). No longer YouTube itself (Piped pipes YT very nicely, even for many embedded YouTube videos (Iframed). URL stripping handled here with uBO and dedicated filter lists : 'ClearURLs for uBo', ' Actually Legitimate URL Shortener Tool - Affiliate tag allowlist' and 'Actually Legitimate URL Shortener Tool'. Firefox's own Privacy query stripping is disabled given uBO and given I have no idea of what exactly is stripped, but it must be close to nothing. That's not about it because if I had to state all that is done on this machine to block, circumvent, bypass the increasing amount of privacy intrusions -- OS, applications, browsers, websites -- It'd be far too long to detail. What has become of the Web? What have they done to our Web, ma. A Wild, Wild Web. Leave a Reply Cancel reply [ ] [ ] [ ] [ ] [ ] [ ] [ ] Comment[ ] [ ]Check the box to consent to your data being stored in line with the guidelines set out in our privacy policy We love comments and welcome thoughtful and civilized discussion. Rudeness and personal attacks will not be tolerated. Please stay on-topic. Please note that your comment may not appear immediately after you post it. Name [ ] Email [ ] [ ] Save my name, email, and website in this browser for the next time I comment. [Post Comment] Search for: [ ] [Search] Advertisement Spread the Word Ghacks Newsletter Sign Up Please click on the following link to open the newsletter signup page: Ghacks Newsletter Sign up Advertisement Hot Discussions * Tor Browser's Connection Assist takes the frustration out of censorship circumvention * Light PDF Editing is coming to Firefox * Arc A750 GPU: Intel says it beats Nvidia's GeForce RTX 3060 video card * Facebook has started to encrypt links to counter privacy-improving URL Stripping Advertisement Recently Updated * Mozilla and Meta develop privacy preserving advertising tech IPA Published in: February 12, 2022 10:06 am | Updated in: February 12, 2022 10:06 am * WhatsApp Web gets a Custom Sticker Maker; Desktop version to follow next week Published in: November 25, 2021 6:35 am | Updated in: November 25, 2021 6:36 am * Facebook scatters privacy settings all over the place on mobile Published in: August 5, 2021 12:44 pm | Updated in: August 5, 2021 12:44 pm * WhatsApp's View Once message feature has arrived Published in: August 5, 2021 12:24 pm | Updated in: August 5, 2021 12:33 pm * First look at WhatsApp's View Once media feature Published in: July 1, 2021 9:20 am | Updated in: July 1, 2021 9:20 am Advertisement About gHacks Ghacks is a technology news blog that was founded in 2005 by Martin Brinkmann. It has since then become one of the most popular tech news sites on the Internet with five authors and regular contributions from freelance writers. * About * RSS Feeds * Legal Information * Terms of use * Privacy Policy * Cookie Policy * Cookie settings * Advertise with Us * Martin Brinkmann * Mike Turcotte * Ashwin * We Use The name and logo of Ghacks are copyrights or trademarks of SOFTONIC INTERNATIONAL S.A. Copyright SOFTONIC INTERNATIONAL S.A. (c) 2005- 2022 - All rights reserved [svg][ghack-logo-me] * Home * Windows * Linux * Software * Firefox * Chrome * Internet * Mobile Computing * Companies * Email * Misc * Deals