Skip to main content
Back to timeline
发表出处待核验Source publication:

Researchers reverse-engineer Meta Pixel configurations, finding 98.4% default-driven tracking on health sites and Core Setup covering only 34.3% while being bypassable via hashed URLs

Synopsis

The study introduces PixelConfig, a differential-analysis framework that reverse-engineers Meta Pixel configurations through code-patching replays and developer-account controlled experiments, and uses Internet Archive's Wayback Machine to longitudinally compare configurations on 18K health websites against a top-10K control group from 2017 to 2024, finding that default-enabled tracking features such as automatic events and first-party cookies reached adoption rates up to 98.4%, that health websites show tracking of potentially sensitive information tied to booking medical appointments and button clicks associated with specific conditions such as erectile dysfunction, and that restriction features like Core Setup were configured on 34.3% of health websites versus 8.

Source-provided article image: PixelConfig: Longitudinal Measurement and Reverse-Engineering of Meta Pixel Configurations
Figure 2

Figure 2: Steps depicting the process of configuring, loading, and tracking using a Meta Pixel.

· Page 4

Interpretation

The study presents PixelConfig, which maps instance.optIn, config.set, and fbq.set calls in the Meta Pixel configuration script to specific tracking behaviors, aligning configuration differences with network-traffic differences. Prior work mainly detected whether tracking pixels were present; this work shifts to how the same pixel is configured differently across websites and covers configurations not previously examined systematically, including automatic events, the Event Setup Tool, first-party cookies, AAM, UnwantedData, and Core Setup. The authors created a developer account, iteratively created pixels on a test website, and compared configuration scripts before and after changing feature settings, as well as replaying patched scripts via Chrome DevTools and comparing traffic to facebook.com, validating each configuration-to-behavior mapping.

Default-enabled tracking features are retained by the vast majority of websites: automatic events (AutomaticSetup and InferredEvents) and first-party cookies reached 98.4% adoption across both categories combined in 2022-2023. This provides longitudinal evidence from 2017 to 2024 that adoption is driven largely by Meta's default settings rather than deliberate website choices. Based on configuration scripts retrieved from the Wayback Machine, with per-year adoption proportions, 95% confidence intervals, and two-proportion z-tests; the authors also ran robustness checks using live website configurations and a stable cohort of websites present in at least 4 of 8 years.

Potentially sensitive information is tracked on health websites, including appointment booking, health-related searches, and button clicks naming specific conditions, for example healthgrades.com tracking buttons labeled "hiv," "schizophrenia," and "autism" with a ViewContent event, docasap.com tracking "erectile dysfunction" buttons with a Lead event, and equitashealth.com tracking HIV testing appointments with a CompleteRegistration event. Prior work focused largely on PII sharing from form fields; this work shows through the Event Setup Tool's estRules and rule_id that contextually sensitive content carried in button text is also linked. Derived from parsing the estRules object in configuration scripts, with specific domains and button texts given; the 2023-2024 sample comprises N=150 health websites and N=967 control websites.

Tracking restriction features have limited adoption and can be circumvented: Core Setup covered 34.3% of health websites and 8.7% of control websites in 2024, sensitive keys under UnwantedData reached 25.4% on health websites, and even under Core Setup some websites shared the SHA-256 hash of the full URL in the ud[dl] parameter to evade the restriction. This measures the practical effect of restriction mechanisms rather than merely their presence, and indicates restrictions are mostly configured by Meta rather than by websites. The authors reversed 73.8% of sensitive_keys hashes using CrackStation, yielding 4,136 unique blacklisted keys and 898 unique decrypted sensitive keys, and provide concrete bypass cases such as wexnermedical.osu.edu.

Perspective

The framework targets researchers, privacy engineers, and compliance teams who want to audit how tracking pixels are actually configured, and it applies to measurement settings where Meta Pixel is the object and configuration scripts are the evidence source; the authors open-sourced PixelConfig and the data so future work can adapt it to other tracking pixels. The longitudinal conclusions apply to website snapshots archived by the Wayback Machine between 2017 and 2024, with health websites drawn from AHA and CMS US institutions and controls from the top-10K websites.

Wayback Machine archival is incomplete: the authors report that roughly 51% of live control-site and 40% of live health-site Pixel installations did not appear in archived snapshots, and that configuration files were archived within one year for 68.3% of control versus 18.1% of health Pixels, so year-over-year comparisons do not cover the same set of websites and absolute numbers may be conservative. The authors ran robustness checks using live configurations and a stable cohort present in at least 4 of 8 years, with trends remaining consistent, but whether archival bias is fully removed remains an open question. In addition, the disappearance of AutomaticSetup after 2023 and the decline of InferredEvents on health websites are interpreted as possible platform-wide deprecation and automatic disabling under Core Setup, with the authors explicitly noting that alternative explanations such as archival bias cannot be fully ruled out; the temporal link between the post-2023 AAM decline on health websites and regulatory actions is likewise framed as the authors' speculation.

Sources