← Back to context

Comment by jasonthorsness

7 days ago

"The Meta Pixel script sends the _fbp cookie to the native Instagram or Facebook app via WebRTC (STUN) SDP Munging."

Crazy to deploy a hack like this at the scale of Meta.

Shouldn't a sensible CORS policy by the webserver block these access attempts?

Of course the website owner wants the tracking, but I think they should also be a guilty party here next to Facebook, even if they just bought the service.

yeah...how does this get approved?

  • "approved?" In a company where ads are the lifeblood and where the targeting specificity of ads determines their value, whichever engineers put this together are guaranteed to have gotten fantastic promo packets.