Hacker News new | ask | show | jobs
by dillondoyle 1567 days ago
I used to tell people if they know how ad tech worked it would be banned tomorrow.

I doubt it's on FB during that period though?

I would guess though that a bunch of health tech sent (perhaps accidentally just not understanding) a bunch of patient data though. Seems they are the responsible party.

There's been other examples beyond FB of 'auto track' too. devs just don't know or forget to turn it off.

Not to mention for some reason at that time putting a FB like button on all the porn. Who clicks that?!?!

1 comments

> I would guess though that a bunch of health tech sent

I worked for a "healthtech" company in London at the beginning of the pandemic. They had the Facebook SDK malware embedded in the app that people were supposed to use for GP consultations.

I don't believe any explicit health data was sent (there was no intent to do so, and I’m not sure if that would even be possible), but merely the fact that I'm talking to a doctor (and the current time, location, device fingerprint, etc) is not something I'd like Facebook to know.

I know breaching the GDPR is basically the norm in any tech company but I thought that being involved in healthcare would make them super risk-averse and make an extra effort to comply.

They were not alone in this - PatientAccess and a bunch of other sites - that you can use to book GP consultations (including through the NHS - UK’s socialised healthcare system) had a shit ton of such trackers too, obviously loaded before any GDPR consent could even be obtained.

I don't know as much about the app SDK, but from the pixel it used to auto detect things like form fill ins, clicks, url params, urls etc. So there is potential it incidentally collected something bad!