{"id":31950,"date":"2021-03-22T15:49:10","date_gmt":"2021-03-22T19:49:10","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=31950"},"modified":"2021-03-23T14:56:55","modified_gmt":"2021-03-23T18:56:55","slug":"backblaze-b2-leaks-metadata-to-facebook","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2021\/03\/22\/backblaze-b2-leaks-metadata-to-facebook\/","title":{"rendered":"Backblaze B2 Leaks Metadata to Facebook"},"content":{"rendered":"<p><a href=\"https:\/\/twitter.com\/Benjojo12\/status\/1373707799054712836\">Ben Cox<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=26536019\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/Benjojo12\/status\/1373707799054712836\"><p>@backblaze&rsquo;s B2 web UI seems to submit all of the names and sizes of my files in my B2 bucket to facebook. I noticed because I saw &ldquo;waiting for facebook.com&rdquo;  at the bottom while trying to download a backup&#8230;<\/p><p>?!?!?!?<\/p><p>I even opted out of their tracking widget thing!<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/backblaze\/status\/1373710670277963777\">Backblaze<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/backblaze\/status\/1373710670277963777\">\n<p>Believe that&rsquo;s the Facebook pixel we use for tracking, we&rsquo;ve forwarded to our web team for review in case that is not intended behavior.<\/p>\n<p>[&#8230;]<\/p>\n<p>An update on the fix we pushed: we removed the offending code from the logged in web pages.<\/p>\n<p>[&#8230;]<\/p>\n<p>The pixels we use are primarily for audience building when we advertise on other platforms like Facebook for example. You can read about it in <a href=\"https:\/\/www.backblaze.com\/company\/cookies.html\">our terms<\/a>[&#8230;]<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/DeftNerd\/status\/1373834656559292417\">Adam Brown<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/DeftNerd\/status\/1373834656559292417\"><p>The &ldquo;Advertising Cookies&rdquo; section says that you don&rsquo;t use them. Then in the FB section, you say that it&rsquo;s so people can easily share pages and content the user finds interesting. Then you slip in a catch-all &ldquo;we may use it for advertising&rdquo;.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/keff85\/status\/1373976714360061953\">Tom&aacute;&#x161; Kafka<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/keff85\/status\/1373976714360061953\"><p>I hope you realise this isn&rsquo;t a &lsquo;frontend issue&rsquo;, but a security breach. As a customer with sensitive data, I don&rsquo;t want you &lsquo;pushing a fix&rsquo;, I want you to do a full review of how this happened, and a process to not let 3rd party trackers access user data ever again.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/zetafleet\/status\/1374022969819824129\">Colin Snover<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/zetafleet\/status\/1374022969819824129\">\n<p>Regrettably, this is just another example of Backblaze&rsquo;s inability\/unwillingness to follow basic software development best practices. To those saying &ldquo;they should notify all users&rdquo;: they should, and they probably won&rsquo;t, because they haven&rsquo;t before.<\/p>\n<\/blockquote>\n\n<p>There is a long history of engineering problems. Just one example: it seems to <a href=\"https:\/\/help.backblaze.com\/hc\/en-us\/articles\/217665498-Why-hasn-t-Backblaze-backed-up-my-new-files-yet-\">still be the case<\/a> that the Backblaze client reports files as successfully backed up as many as eight hours <em>before<\/em> they are actually committed to the server. If something happens to your Mac in the interim, you won&rsquo;t be able to restore them.<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/02\/15\/arq-7\/\">Arq 7<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2018\/11\/05\/backblaze-bzfileids-dat-scaling-and-little-snitch\/\">Backblaze bzfileids.dat Scaling and Little Snitch<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2016\/01\/13\/backblaze-mails-unencrypted-hard-drives\/\">Backblaze Mails Unencrypted Hard Drives<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2014\/10\/15\/begemanns-backblaze-review\/\">Begemann&rsquo;s Backblaze Review<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2014\/05\/22\/what-backblaze-doesnt-back-up\/\">What Backblaze Doesn&rsquo;t Back Up<\/a><\/li>\n<\/ul>\n\n<p id=\"backblaze-b2-leaks-metadata-to-facebook-update-2021-03-23\">Update (2021-03-23): <a href=\"https:\/\/www.backblaze.com\/blog\/privacy-update-third-party-tracking\/\">Backblaze<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.backblaze.com\/blog\/privacy-update-third-party-tracking\/\">\n<p>We take the privacy of our customers&rsquo; data and personal information very seriously and have made completing the root cause analysis a top priority. Our Engineering, Security, and Compliance\/Privacy teams&mdash;as well as other staff&mdash;are continuing to investigate the cause and working on steps to help ensure this doesn&rsquo;t happen again. We will update this post as we have more information to share.<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Ben Cox (Hacker News): @backblaze&rsquo;s B2 web UI seems to submit all of the names and sizes of my files in my B2 bucket to facebook. I noticed because I saw &ldquo;waiting for facebook.com&rdquo; at the bottom while trying to download a backup&#8230;?!?!?!?I even opted out of their tracking widget thing! Backblaze: Believe that&rsquo;s the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2021-03-22T19:49:14Z","apple_news_api_id":"69cd3c9e-8ec0-4e02-8b34-4f1c83d27399","apple_news_api_modified_at":"2021-03-23T18:56:58Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAg==","apple_news_api_share_url":"https:\/\/apple.news\/Aac08no7ATgKLNE8cg9JzmQ","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[534,146,25,30,1891,355,96],"class_list":["post-31950","post","type-post","status-publish","format-standard","hentry","category-technology","tag-backblaze","tag-backup","tag-facebook","tag-mac","tag-macos-11-0","tag-privacy","tag-web"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/31950","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=31950"}],"version-history":[{"count":3,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/31950\/revisions"}],"predecessor-version":[{"id":31974,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/31950\/revisions\/31974"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=31950"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=31950"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=31950"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}