[HINT] How FB uses Fingerprint to detect your blackhat ads.

Tim Mighty_M

Newbie
Joined
Jan 26, 2017
Messages
33
Reaction score
114
1531739509.png


Hi, everyone.
Perhaps some of you could see my previous threads about account farming and using FB tools to find good audience.

Since April 2017 a lot of blackhatters had big troubles with their account being blocked. Especially the ones not in Tier-1 geos;

This is mostly because of FB's fingerprint technology, FB started to use. If you want to know more about fingerprints, you are welcome to study the text below.
Also! I am the only author of this text and I find it really legal to post in on the forum. If you find this article published anywhere else - do not consider this one as the copy-paste.
If you have difficulties understanding the terms like "trust-rate" and so on - please, be kind reading the other manuals of mine published on a forum.

-----------


Until recently, there was an opinion that Facebook does not collect any data about the platform and device with which the affiliate is working, because the browser itself does not transmit such data to the network, and Facebook can collect this information only with the help of third-party services and applications.


Let me make it crystal clear: Facebook collects, accesses, processes, stores and segment the information about your device. Perhaps part of the data received by the social network hadn’t been used until recently, but the fact is: FB has the ability to extract the information about the hardware installed on the device and some of the system settings.


Since April, FB launched the trust-rate algorithms for accounts on the principle of Fingerprint (technologies that Google has been actively using for more than a year); According to the new algorithm all new accounts created using cringed or suspicious resources uncompromisingly are sent to the so-called "Selfie" checkpoint. On one hand, it's good that they are not immediately blocked. On the other hand, getting through this algorithm does not guarantee that you will not end up there again hours later. Machine learning from Facebook is ruthless: the algorithm will reset the same account over and over again if the fingerprint of the profile seems suspicious.


Let’s get to the point. There is an alternative user tracking method beside cookies. If you turn off cookies in the browser (by the way FB inserts 11 different cookies in your browser) your profile immediately ends up in the suspicious list. This significantly lowers the trust-rate, which makes it harder to protect yourself from fingerprint technology. The way it works: js-scripts consistently poll your browser for a whole heap of very platform-dependent settings. We call this technology Fingerprint-js, but Facebook uses libraries of its own development. If you want, you can debug all FB scripts and find all such requests.


Using fingerprint technology, FB recognizes not only the "stuffing" of your computer, but also indirectly learns information about installed libraries, software, drivers, etc. Each electronic device that got in facebook’s line of sight is assigned a unique digital label in the form of a hash sum. Add this to the data collected from double entry technology, data collected with cookies, and data that FB buys from third-party services. Daily FB receives roughly 1000 terabytes of information about its users, which social network engineers systematize, structure and analyze with the help of machine learning.


Not long ago we diligently tried to hide from the Network. Webrtc and flash partially blocked outgoing traffic, blocked cookies, cleaned cache and at the same time made us feel smart. Today, new registration with such parameters will directly go to the Selfie page faster than you can pronounce the name of FB owner. Previously, we were satisfied when the bunny whoer showed an honest 100% of anonymity. Now times have changed, and FB freaks out just like Google in 2015.


Today we have to be even smarter. Blocking cookies is just as good as confessing to the network - hey, look, I'm an arbitrator, I'm here. The truth is that 95% of network users do not know what cookies are and what they do. At the same time everyone who is trying to hide looks suspicious. And for FB suspicious - means guilty. This leads to either your account being “flagged” or to the good old Selfie check. You have to work really hard to convince FB that you are an average user. Bans in FB always were and remain a scoring system, but still nobody knows the variables in the trust rate calculation formula.


Back to the point: How much does Facebook know about the webmaster? A LOT! In reality it is much more than we think.


 
I received this via email from one of my CPA companies. Pretty good stuff, Folks.

Until recently, there was an opinion that Facebook does not collect any data about the platform and device with which the affiliate is working, because the browser itself does not transmit such data to the network, and Facebook can collect this information only with the help of third-party services and applications.

Let me make it crystal clear: Facebook collects, accesses, processes, stores and segment the information about your device. Perhaps part of the data received by the social network hadn’t been used until recently, but the fact is: FB has the ability to extract the information about the hardware installed on the device and some of the system settings.

Since April, FB launched the trust-rate algorithms for accounts on the principle of Fingerprint (technologies that Google has been actively using for more than a year); According to the new algorithm all new accounts created using cringed or suspicious resources uncompromisingly are sent to the so-called "Selfie" checkpoint. On one hand, it's good that they are not immediately blocked. On the other hand, getting through this algorithm does not guarantee that you will not end up there again hours later. Machine learning from Facebook is ruthless: the algorithm will reset the same account over and over again if the fingerprint of the profile seems suspicious.

Let’s get to the point. There is an alternative user tracking method beside cookies. If you turn off cookies in the browser (by the way FB inserts 11 different cookies in your browser) your profile immediately ends up in the suspicious list. This significantly lowers the trust-rate, which makes it harder to protect yourself from fingerprint technology. The way it works: js-scripts consistently poll your browser for a whole heap of very platform-dependent settings. We call this technology Fingerprint-js, but Facebook uses libraries of its own development. If you want, you can debug all FB scripts and find all such requests.

Using fingerprint technology, FB recognizes not only the "stuffing" of your computer, but also indirectly learns information about installed libraries, software, drivers, etc. Each electronic device that got in facebook’s line of sight is assigned a unique digital label in the form of a hash sum. Add this to the data collected from double entry technology, data collected with cookies, and data that FB buys from third-party services. Daily FB receives roughly 1000 terabytes of information about its users, which social network engineers systematize, structure and analyze with the help of machine learning.

Not long ago we diligently tried to hide from the Network. Webrtc and flash partially blocked outgoing traffic, blocked cookies, cleaned cache and at the same time made us feel smart. Today, new registration with such parameters will directly go to the Selfie page faster than you can pronounce the name of FB owner. Previously, we were satisfied when the bunny whoer showed an honest 100% of anonymity. Now times have changed, and FB freaks out just like Google in 2015.

Today we have to be even smarter. Blocking cookies is just as good as confessing to the network - hey, look, I'm an arbitrator, I'm here. The truth is that 95% of network users do not know what cookies are and what they do. At the same time everyone who is trying to hide looks suspicious. And for FB suspicious - means guilty. This leads to either your account being “flagged” or to the good old Selfie check. You have to work really hard to convince FB that you are an average user. Bans in FB always were and remain a scoring system, but still nobody knows the variables in the trust rate calculation formula.

Back to the point: How much does Facebook know about the webmaster? A LOT! In reality it is much more than we think.
 
That amazing write up and info thank you .

so that means turnning cookies of is a very bad idea.

flags the account and eventually have to send a selfie in.

....

the bit that worries me is the info they say from the computers they can detect like files, settings, driver's from a 3rd party , surly that aginst the law unless asked ?

they say it all done via JavaScript and can bee seen what they see ? any got any examples what they see?

also if you turn JavaScript off are you flagged stright away?

fb bot designers will have to get more Into this thread it gold dust...
 
That amazing write up and info thank you .

so that means turnning cookies ofc is a very bad idea.

flags the account and eventually have to send a selfie in.

....

the bit that worries me is the info they say from the computers they can detect like files, settings, driver's from a 3rd party , surly that aginst the law unless asked ?

they say it all done via JavaScript and .ca bee seen what they see ? any e got any examples what they see?

also if you turn JavaScript off are you flagged then stright away?

I'm not sure about all the other questions but I NEVER turn off cookies on FB with my accounts. I don't have a personal account anymore as I killed it but I have a whole bunch of accounts that work for me marketing and none of them block cookies.

I want FB to know we have been there before.
 
Yeah, I would like to know more about how they fingerprint your hardware, drivers etc.

I guess one would need to install few virtual machines on his PC.
 
Fb collects shitload of data about its users, even when they arent on facebook itself. They know better your interests than you can imagine. They achieve it with help of their so called social plugins, like buttons, share buttons, embedded fanpages etc etc. in simple words any link to facebook from external site will contain cookies with your profile id and they append that link to your history.

This isn't new, its in active use since they implemented those social plugins.

What made me mad is the fact that they process your messaging contacts and of course messages and use that for their marketing algo. So this year i decided to finally join instagram and i went on and created account. So upon creation I got suggestions to follow some friends which is fine but then i get suggestion to follow one girl i had never friended with, just chat talk. I was like seriously?

Btw facebook is very easy to trick, keep milking it. Even though they did tremendous work on fixing bugs for past 3 years I have to admit fb is still very doable just became much harder which means less competition.

Good luck fellow BH-ers.
 
Ok! But, how we can stay avoid from the Selfie block?! It's frustrating :/
 
Also, Facebook checks cookies and other data from Facebook Partner Websites. Even if you didn't visit such websites Facebook thinks that you just use a Machine for farm accounts there
 
@Tim Mighty_M

Thanks it was an interesting read even tho I'm not pushing anything on FB. I'm just a guy concerned about general privacy! :D
 
Over 50 accounts under Selficheck, i am just Lost with facebook
 
"i'm Joe, but you see me as Jane"
that's my golden rule

  1. use very good proxy/vpn
  2. use very good privacy tools like ndalang / multiloginapp
  3. do not be too vulgar / aggressive, stay under radar.
 
"i'm Joe, but you see me as Jane"
that's my golden rule

  1. use very good proxy/vpn
  2. use very good privacy tools like ndalang / multiloginapp
  3. do not be too vulgar / aggressive, stay under radar.
I understand that emulating devices with different ips is the key to avoid fingerprints, but what I have been doing is creating and cloning virtual machines in my own pc, just switching proxies each time I clone them... Can you guys see anything wrong with it other than needing a lot of resources to run them in parallel?
 
Back
Top