# How did FB know it's me when...?

**URL:** https://discuss.privacyguides.net/t/how-did-fb-know-its-me-when/23626
**Category:** Questions
**Created:** 2025-01-01T08:29:12Z
**Posts:** 42

## Post 1 by @Banjaie — 2025-01-01T08:29:12Z

- I’m using Ubuntu.
- VPN is permanently on (set to not connect to the internet if not on).
- FB is on a dedicated browser (Mullvad with Ublock origin).
- Fb account was created with a dedicated throw away number at a public library in a different city that I have never since (or before) been to.
- Fb account has zero friends, searches for people I know, likes, shares…etc. It wasn’t shared with anyone and the name is a pseudonym. The only thing it is used for is just scrolling through recommended feeds/videos and random groups.

I searched a very particular product on [Duck.com](http://Duck.com) on another hardened FF browser and on Youtube on Brave for the first time ever and as soon as I later get on FB, that same product is recommended to me while just scrolling. Mind you I have never searched it or anything related to it on fb.

How could this have been possible?

---

## Post 2 by @anon73250778 — 2025-01-01T08:35:37Z

You are assuming that FB knows you based on displayed ads alone? The ad could be targeting privacy conscious users like us so I would not put too much stock on an instance of a specific ad.

Also, why are you suffering through the internet without using adblocks of any sort in this day and age? You should be seeing _less_ ads, unless the ads are hardcoded into the website.

---

## Post 3 by @Banjaie — 2025-01-01T08:39:29Z

> [@anon73250778](#):
>
> The ad could be targeting privacy conscious users like us

What are you talk about? The product had nothing to do with privacy.

> [@anon73250778](#):
>
> Also, why are you suffering through the internet without using adblocks of any sort in this day and age? You should be seeing _less_ ads, unless the ads are hardcoded into the website.

Isn’t Ublock an ad blocker “of some sort”?

---

## Post 4 by @ph00lt0 — 2025-01-01T09:24:02Z

There are so many ways they could know. This is not something that anyone here is going to answer for you. You should ask facebook instead.

The answer will be including something with context of you, people around you, trends, and likeliness. Facebook can also make educated guesses based on all data they have on you. If you seriously think you can avoid that with just an isolated browser you are very wrong.

Get an adblocker, take your data away from facebook.

---

## Post 5 by @anon73250778 — 2025-01-01T09:52:11Z

> [@Banjaie](#):
>
> Ublock an ad blocker “of some sort”?

My bad. You are right.

What I had in mind was something of a DNS level kind of adblock, Like PiHole.

* * *

> [@Banjaie](#):
>
> What are you talk about? The product had nothing to do with privacy.

May we know what specific ad it was?

Facebook ad has an option to do “extended reach” kind of ad serving algorithm. Maybe you fit in that category in both instances, could be by luck.

A cynical would be that if an ad campaign had no immediate target population, it might seek out others to complete its ad quota. For instance “fast food” and “florida”. You might fit into the “florida” by your location, while you may not fit into “likes fast food” it might put you into the same because it cannot fulfill the quota in time.

---

## Post 6 by @Banjaie — 2025-01-01T09:58:30Z

> [@ph00lt0](#):
>
> There are so many ways they could know.

Could you name just one?

> [@ph00lt0](#):
>
> The answer will be including something with context of you

What about me?

> [@ph00lt0](#):
>
> people around you

VPN, Also has nothing to do with what I am asking.

> [@ph00lt0](#):
>
> trends

Has nothing to do with what I am asking.

> [@ph00lt0](#):
>
> and likeliness

> [@Banjaie](#):
>
> Fb account has zero friends, searches for people I know, **likes** , shares…etc.

> [@ph00lt0](#):
>
> Facebook can also make educated guesses based on all data they have on you.

How did they make an educated guess that I searched a particular niche product 5 mins earlier (GIVEN MY PARTICULAR CIRCUMSTANCE AS OUTLINED IN THE OP)?

> [@ph00lt0](#):
>
> Get an adblocker,

> [@Banjaie](#):
>
> …(Mullvad with **Ublock origin** )

---

## Post 7 by @ignoramous — 2025-01-01T09:58:53Z

> [@Banjaie](#):
>
> How could this have been possible

I imagine you want to prevent this from happening.

If so, mirimir’s 8 part series (commissioned by iVPN) on digital anonymity is really neat:

> [@Using VPN with services that know your identity?](https://discuss.privacyguides.net/t/using-vpn-with-services-that-know-your-identity/18663/11):
>
> 100 100

(Part 1: [https://archive.is/9onZg](https://archive.is/9onZg))

---

## Post 8 by @Banjaie — 2025-01-01T10:05:20Z

I would have to know how exactly it is happening first before just throwing parts at it. You are implying the VPN is the culprit. How so, exactly? I am using one that is recommended here.

---

## Post 9 by @Banjaie — 2025-01-01T10:07:44Z

It’s a very niche product. No way it was coincidental. It was very specific and intentional.

---

## Post 10 by @anon73250778 — 2025-01-01T10:13:09Z

All the more I suspect that FB has no one to advertise that to and decided to show it to anonymous random people instead.

It could be malice from FB to the person who bought the ad to say “Hey I earned the money you’ve paid me by showing the ads to people, not necessarily your target demographic, but I’ve shown it to people”. That’s my theory.

---

## Post 11 by @Banjaie — 2025-01-01T10:14:24Z

Sorry but that makes no sense. Illogical.

---

## Post 12 by @ignoramous — 2025-01-01T10:15:59Z

> exactly what is happening

Anonymity is super hard. Most here can’t know _exactly_ what’s going on, not when they are miles away from you. And especially, when there’s so many things that could have happened.

So, you would do well to read up on what it takes to have a separate identity. I like mirimir’s guide (a link to which I posted above). After you read those, you might yourself come to understand what is and isn’t enough. Can’t think of any other easy way or magic bullet that might help answer your questions, otherwise.

---

## Post 13 by @Banjaie — 2025-01-01T10:17:46Z

> [@ignoramous](#):
>
> Most here can’t know _exactly_ what’s going on,

Looking to hear from those who do :crossed_fingers:

---

## Post 14 by @anon73250778 — 2025-01-01T10:17:49Z

The alternative is you are saying that with all the mitigations you have, FB can still identify you.

Did you use the same device? Did it use the same MAC of the wifi?

---

## Post 15 by @Banjaie — 2025-01-01T10:20:45Z

> [@anon73250778](#):
>
> Did you use the same device? Did it use the same MAC of the wifi?

Yes, same device. MAC is revealed to websites? How? Mind you, IPv6 is disabled.

---

## Post 16 by @anon73250778 — 2025-01-01T10:26:43Z

> [@Banjaie](#):
>
> MAC is revealed to websites?

Mullvad recommends you have a randomized MAC

> **[Changing your MAC address](https://mullvad.net/en/help/changing-your-mac-address)**
>
> Learn about what a MAC address is, how it can reveal your identity, and how to prevent this.

My guess is, FB can somehow see it from the wifi side somehow.

Does your device have the ability to randomize MAC addresses and did you confirm that the randomization is on at the time of connections?

---

## Post 17 by @anon80779245 — 2025-01-01T10:31:37Z

> [@Banjaie](#):
>
> The only thing it is used for is just scrolling through recommended feeds/videos and random groups.

Then, they have a very precise profile of you. Then, they just display ads based on this and it happened that it matched one of your search.

> [@Banjaie](#):
>
> I searched a very particular product on [Duck.com](http://Duck.com) on another hardened FF browser and on Youtube on Brave for the first time ever and as soon as I later get on FB, that same product is recommended to me while just scrolling. Mind you I have never searched it or anything related to it on fb.

I recommend you have a different IP for Facebook, so I would say put a proxy on [facebook.com](http://facebook.com) on the Mullvad Browser.

---

## Post 18 by @Banjaie — 2025-01-01T10:37:51Z

> [@anon73250778](#):
>
> My guess is, FB can somehow see it from the wifi side somehow.

Yeah, How is the question :thinking:

---

## Post 19 by @Banjaie — 2025-01-01T10:46:02Z

> [@anon80779245](#):
>
> Then, they have a very precise profile of you. Then, they just display ads based on this and it happened that it matched one of your search.

Has nothing to do with the subject matter.

> [@anon80779245](#):
>
> I recommend you have a different IP for Facebook, so I would say put a proxy on [facebook.com](http://facebook.com) on the Mullvad Browser.

Know of any free ones by any chance?

---

## Post 21 by @Banjaie — 2025-01-01T16:15:53Z

I hear what you are saying but please read my OP (not just skim through it) because none of what you said applies to my case.

---

## Post 23 by @anon29374801 — 2025-01-01T16:37:45Z

I think you have to accept the possibility that even though it feels like FB knew its you, it was a coincidence brought on by FB having billions of data points to serve recommendations that can make you think this.

* * *

I am also a bit confused as to why you are so surprised they might know its you. Outside of using Mullvad, nothing you mentioned is going to help keep you anonymous. For all we know (as there is not nearly enough information for anyone here to provide anything more then a guess) there was a tracking pixel from your other “hardened FF browser” that outed you.

---

## Post 24 by @Julie — 2025-01-01T20:42:17Z

You did not answer the question, How are a webserver is being able to see a user MAC adress ?

---

## Post 25 by @OnTheFenceAbtPrivacy — 2025-01-01T21:01:44Z

So the search you did for niche product was on ubuntu - and on a separate browser, on same ubuntu instance, Meta was used?

---

## Post 26 by @OnTheFenceAbtPrivacy — 2025-01-01T21:31:54Z

I respectfully disagree. Sad to say there are some workers in a number of platforms that will throw coincidences at you for the rest of their lives. I have dealt with some five years now and my husband witness. They started off with credible death threats. They threaded 8 people together to come up with ways to harass. Had stalking data through discussions with ex boyfriends and friends. One is reasonably confirmed in Google - Apple- Simplisafe. Pray you do not get on their radar.

---

## Post 27 by @Julie — 2025-01-01T21:39:56Z

Same IP adress, same time zone, same fonts list, so a partial fingerprinting ?

That"s my guess.

---

## Post 28 by @OnTheFenceAbtPrivacy — 2025-01-01T21:46:48Z

Or your curtains were open.

---

## Post 29 by @anon29374801 — 2025-01-01T22:55:45Z

I am a bit unclear on what you are disagreeing with. Are you saying there is no chance of OPs situation being a coincidence? I dont think there is nearly enough information to make a determination like that.

---

## Post 30 by @OnTheFenceAbtPrivacy — 2025-01-01T23:14:54Z

Is the glass full or empty. I have five years proof 3 companies have workers (at least) that are granted access to three systems. (Simplisafe/Apple ML/Webkit/Google Metadata at min) who cannot be trusted to explain motive/intent for severe stalking, death threats, intimidation and harassment. Every time you are not believed - it is dismissed as coincidence- there is in fact no help.

If you want to help them you have to err on the side of believing the concerned party until there is reasonable info to disbelieve.

People legitimately stalked and having privacy invasion require this. Else, we are not doing privacy- we are doing evasion. Which is fine - yet best to be honest about why we are taking the extraordinary measures and visiting this privacy specific forum to collaborate.

He wants to know how Facebook can know and I do not think we have enough information.

I can attest there are a lot of ways Facebook can know that are both technical and non-technical.

What are all of their techniques in inventory?

For me, there are physical- actual collab with people who know me, a window trick my husband and I have yet to figure out.

As well as logical- an alarm system company coordinating. Is a Facebook employee involved? Yes when I had an account they had my data takeout enabled and disabled my sisters and had edit procedures to how feeds are prioritized and presenting info. The adverts and feed modifications were based on inputs from people, interviews, metadata access to other systems, card transactions, and sms scraping. There are probably other ways too. I stopped taking inventory and closed my account w them.

Regardless of probability- if you do not want to them to continue presenting their capability to you, you have to leave them.

If you want to stick around, and try to figure out what they are doing, start with the advertising settings under account management. The data takeout logs were useful to see what IP’s had connected. Some test pages someone had built. Some messages that were likely acquired. The logs in data takeout were so good for piecing together some connection history, they wound up disabling my sisters.

I never spoke out against Zuckerberg yet I have had issues with their news of breaches and some solid review of how they are willing to mess with privacy interested parties.

Once I figured out I was dealing with one of their workers I tossed them.

---

## Post 31 by @overdrawn98901 — 2025-01-02T02:33:39Z

> [@OnTheFenceAbtPrivacy](#):
>
> Is the glass full or empty. I have five years proof 3 companies have workers (at least) that are granted access to three systems. (Simplisafe/Apple ML/Webkit/Google Metadata at min) who cannot be trusted to explain motive/intent for severe stalking, death threats, intimidation and harassment. Every time you are not believed - it is dismissed as coincidence- there is in fact no help.

Problem here is that you have the 5 years of proof, we don’t. Undocumented anecdotal evidence is tough to go on, and on an anonymous forum isn’t going to amount to much.

---

## Post 32 by @Valynor — 2025-01-02T02:40:43Z

Friendly reminder to always think of

> **[Correlation does not imply causation](https://en.wikipedia.org/wiki/Correlation_does_not_imply_causation)**
>
> The phrase "correlation does not imply causation" refers to the inability to legitimately deduce a cause-and-effect relationship between two events or variables solely on the basis of an observed association or correlation between them. The idea that "correlation implies causation" is an example of a questionable-cause logical fallacy, in which two events occurring together are taken to have established a cause-and-effect relationship. This fallacy is also known by the Latin phrase cum hoc As wi...

One time could just be a (lucky) accident, even if it _feels_ improbable.

---

## Post 33 by @OnTheFenceAbtPrivacy — 2025-01-02T14:21:06Z

When dealing with attacks from people in data analytics, science, social media, security or tech in general (which is a lot of people in the world now) - they have read this mantra publically for so long they design their attacks around it.

In terms of proof:

I have an attack where someone decided to make it quite political and span domains from legal, social, physical security, cyber, identity and access. The premise being (assumed) a wonky guy hired for security architecture had maliciously claimed to a senior exec I was part of an anonymous attack on a high profile individual. They did hundreds of tiny attacks (some have lethality involved with or without causation). In fact, to prove out most people will call you crazy or pontificate on probability/causation instead of simply believing the reports that would be made to over 30 entities. Some multiple times.

No one in the middle of a crime that would be obviously designed this way, because the behavior is so obvious (I have read correlation and causation on 20 platforms) - wants anything but to be believed and help with investigation and prosecution.

It is academic. I think every new party here should be asked why they are here as a bio. I am personally not interested in providing privacy to a person discussing correlation and causation, unless they have a plan to help fix incident response.

Honestly IC3 gov was useless and FBI came out with “did you take your meds” to a large scale incident which made me more than happy their orgs are having a regime change.

I can confirm Facebook should not be trusted- to whom am I proving it? I have no desire to prove it to anyone except someone willing to help pull together a case for prosecution.

---

## Post 37 by @overdrawn98901 — 2025-01-02T17:54:11Z

Hmmmm, I think there are a lot of different threat models being thrown around and blending together. I think the topic will be focused if we stick to the threat model of remaining anonymous to corporations and advertising.

---

## Post 38 by @anon80779245 — 2025-01-02T22:21:29Z

> [@Banjaie](#):
>
> Know of any free ones by any chance?

. I guess you could use Proton VPN extension but I don’t think there is a per site toggle.

---

## Post 39 by @Banjaie — 2025-01-05T17:15:24Z

> [@Anon47486929](#):
>
> **You don’t need to search for it**. It’s profiled to users like you.

Could you please elaborate? How so?

> [@Anon47486929](#):
>
> However much you think you haven’t ever shown affinity for the product on FB, you have.

Could you please explain how that would be possible given I didn’t know of the product’s existence (or anything related to it) during my usage of FB prior to searching it a few mins prior to seeing the ad?

---

## Post 40 by @Banjaie — 2025-01-05T17:43:03Z

> [@Valynor](#):
>
> One time could just be a (lucky) accident, even if it _feels_ improbable.

Are you saying it is impossible for it to have been a case of causation?

---

## Post 41 by @Valynor — 2025-01-05T18:25:51Z

> [@Banjaie](#):
>
> impossible

impossible ≠ improbable  
it is ≠ could be

---

## Post 42 by @win11.shading291 — 2025-01-07T18:28:52Z

I’m not sure if anyone mentioned this. Wouldn’t fingerprinting + facebook pixel tracking still be possible if you logged in with a VPN that not a lot of mullvad browser users use?

If you don’t use a popular VPN like Proton or Mullvad for users of the Mullvad Browser, you could theoretically be more finger-printable. It also depends on which server you were connected to.

I’m no expert, but to me, that could maybe be a potential explaination.
