Home Privacy Facebook Is Reinstating Reach Estimates In Custom Audiences After Fixing A Security Flaw

Facebook Is Reinstating Reach Estimates In Custom Audiences After Fixing A Security Flaw

SHARE:

After more than a year on ice, Facebook is bringing back reach estimates in Custom Audiences.

Facebook suspended the metric, which advertisers would use to preview reach estimates for lists uploaded to Custom Audiences, in March 2018 when academic researchers from Northeastern University discovered a vulnerability.

The exploit could have allowed someone to infer attributes related to the individuals included in an advertiser’s list.

The researchers were rewarded through Facebook’s bug bounty program and the metric was shelved pending investigation.

Facebook re-introduced it Tuesday to buyers on a randomized basis, a process that will continue through the end of the year.

What was the problem?

Simply put (sort of), researchers could determine the rounding threshold, aka, the point at which Facebook’s system would round up to create an estimate.

Having identified the threshold, one could ascertain gender or country or any one of more than 1,000 targeting attributes, by adding an email to the list, selecting an attribute and checking if the reach estimate went up or stayed the same.

Anyone diligent enough could mine the metric to build fairly detailed customer profiles.

Over the past year, Facebook worked with the researchers who uncovered the bug to patch the problem. Facebook claims that it never saw anyone take advantage of the exploit.

The solution is threefold: making the rounding logic more complex for how estimates are displayed; improving the backend detection process for potential misuse in collaboration with Facebook’s business integrity team, which investigates security issues; and limiting the number of audiences and API calls that a single account can have.

Subscribe

AdExchanger Daily

Get our editors’ roundup delivered to your inbox every weekday.

Restricting the API calls and capping the number of audiences won’t have an impact on how advertisers use the metric, but should prevent anyone from manipulating it. Multiple API calls can be a sign of potential misuse.

This isn’t the first time Custom Audiences was found to be vulnerable to possible abuse. The same Northeastern researchers who found the Custom Audience reach estimate issue unearthed a similar bug within Custom Audiences in December 2017 that would allow someone to figure out a user’s cell phone number from their email address.

A Facebook spokesperson said that advertisers have been consistently requesting to get the metric back, even though they had alternative tools when reach estimates in Custom Audiences weren’t available.

But Facebook decided not to rush things this time. “We’re doing this a little more slowly than with other products to be cautious and make sure everything is going as intended,” the spokesperson said.

Phillip Huynh, VP of paid social at 360i, said he’ll be pleased to see reach estimates back in its rightful place in Ad Manager.

“This allows us to, once again, understand the audience we’re targeting and make appropriate decisions on investment,” Huynh said, as well as keep tabs on audience sizes as upcoming changes to the platform begin to roll out, including Clear History.

Must Read

Google Rolls Out Chatbot Agents For Marketers

Google on Wednesday announced the full availability of its new agentic AI tools, called Ads Advisor and Analytics Advisor.

Amazon Ads Is All In On Simplicity

“We just constantly hear how complex it is right now,” Kelly MacLean, Amazon Ads VP of engineering, science and product, tells AdExchanger. “So that’s really where we we’ve anchored a lot on hearing their feedback, [and] figuring out how we can drive even more simplicity.”

Betrayal, business, deal, greeting, competition concept. Lie deception and corporate dishonesty illustration. Businessmen leaders entrepreneurs making agreement holding concealing knives behind backs.

How PubMatic Countered A Big DSP’s Spending Dip In Q3 (And Our Theory On Who It Was)

In July, PubMatic saw a temporary drop in ad spend from a “large” unnamed DSP partner, which contributed to Q3 revenue of $68 million, a 5% YOY decline.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

Paramount Skydance Merged Its Business – Now It’s Ready To Merge Its Tech Stack

Paramount Skydance, which officially turns 100 days old this week, released its first post-merger quarterly earnings report on Monday.

Hand Wipes Glasses illustration

EssilorLuxottica Leans Into AI To Avoid Ad Waste

AI is bringing accountability to ad tech’s murky middle, helping brands like EssilorLuxottica cut out bots, bad bids and wasted spend before a single impression runs.

The Arena Group's Stephanie Mazzamaro (left) chats with ad tech consultant Addy Atienza at AdMonsters' Sell Side Summit Austin.

For Publishers, AI Gives Monetizable Data Insight But Takes Away Traffic

Traffic-starved publishers are hopeful that their long-undervalued audience data will fuel advertising’s automated future – if only they can finally wrest control of the industry narrative away from ad tech middlemen.