Yash Vekaria's Avatar

Yash Vekaria

@yash-vekaria

phd ‪@ucdavis | web privacy and security researcher https//www.yashvekaria.com/

30
Followers
50
Following
13
Posts
12.06.2025
Joined
Posts Following

Latest posts by Yash Vekaria @yash-vekaria

8/

📄 Find more interesting details on extent of tracking deployed on health and control websites in our paper: 🔗https://arxiv.org/pdf/2603.09380

🌐 We’ve also open-sourced PixelConfig and the dataset to support future research on tracking technologies: 🔗https://github.com/Yash-Vekaria/pixel-config

11.03.2026 05:21 👍 0 🔁 0 💬 0 📌 0
Post image Post image

7/ Blacklisted and sensitive keys (left) reflect filtering of URL & custom parameters, while Core Setup (right) reflects restriction on data collection by Meta Pixel. These protections show higher adoption on health, but we still find them to be ineffective and prone to circumvention.

11.03.2026 05:21 👍 0 🔁 0 💬 1 📌 0
Post image Post image

6/ Across health+control, the adoption of FP cookies remained over 98% from 2021-2024 as Meta turned it on by default. Automatic Advanced Matching for all 11 attributes showed continual increase for control but a decrease for health websites post 2022, likely due to HHS+FTC's regulatory actions.

11.03.2026 05:21 👍 0 🔁 0 💬 1 📌 0
Post image Post image

5/ AutomaticSetup enabled Microdata event, while presence of AutomaticSetup/InferredEvents enabled SubscribedButtonClick, auto-sharing page metadata & button click details, respectively. This allowed sites with Meta pixel to track conditions: hiv, autism, birth control pills, menstrual products, etc

11.03.2026 05:21 👍 0 🔁 0 💬 1 📌 0
Post image

4/ We study 3 Meta pixel features:

➊ Activity tracking — what users do on a website (e.g., button clicks, page metadata)

➋ Identity tracking — who the user or device is (e.g., cookies, form data)

➌ Tracking restrictions — mechanisms intended to limit sharing of sensitive data

11.03.2026 05:21 👍 0 🔁 0 💬 1 📌 0
Post image

3/ Prior research has merely studied the presence of tracking pixels on websites, completely ignoring: what those pixels are actually configured to track?

We propose: PixelConfig, a reverse-engineering approach to infer tracking pixel configurations on websites via static and dynamic analysis.

11.03.2026 05:21 👍 0 🔁 0 💬 1 📌 0
Post image Post image

2/ Meta pixel has tracked users over a decade, with heightened regulatory scrutiny over the recent years from its use on health websites.

Using the Internet Archive’s Wayback Machine, we study Meta Pixel deployments from 2017–2024 on:
➔ 18K health websites
➔ 10K top websites

11.03.2026 05:21 👍 0 🔁 0 💬 1 📌 0
Post image Post image

The same tracking pixel on two websites can be configured completely differently to track varying user details.

🚨In our @acm-imc.bsky.social 2026 paper (w/ @zubair-shafiq.bsky.social), we perform longitudinal measurement of Meta pixel to study its tracking configurations employed by websites.

11.03.2026 05:21 👍 0 🔁 0 💬 1 📌 0

Excited to share that my research (w/ @zubair-shafiq.bsky.social, @kollnig.net, Nurullah) on "Understanding Data Collection, Brokerage, and Spam in the Lead Marketing Ecosystem" has been accepted for presentation at the 3rd FTC Conference on Marketing and Public Policy 2026 in Washington D.C.

05.02.2026 23:22 👍 2 🔁 1 💬 0 📌 0
Preview
Generative AI | 2025 | The Web Almanac by HTTP Archive Generative AI chapter of the 2025 Web Almanac covering the transition to local browser-based AI, the adoption of WebNN and Built-in AI, new discoverability standards like llms.txt, and the emergence of AI fingerprints on the web.

Generative AI, by @christianliebel@mastodon.cloud and @yash-vekaria.bsky.social and others (@httparchive.org):

https://almanac.httparchive.org/en/2025/generative-ai

#webalmanac #studies #research #metrics #ai

22.01.2026 20:30 👍 2 🔁 1 💬 0 📌 0
Preview
Attorney General Paxton Sues Five Major TV Companies, Including Some with Ties to the CCP, for Spying on Texans Attorney General Ken Paxton has filed suit against five major television companies for spying on Texans by secretly recording what consumers watch in their own homes.

My research (w/ @zubair-shafiq.bsky.social) on Automatic Content Recognition (ACR) was cited in complaints filed today by Attorney General Ken Paxton against 5 major smart TV brands—LG, Samsung, Sony, TCL, and Hisense—alleged for spying on Texans via ACR.
texasattorneygeneral.gov/news/release...

16.12.2025 09:32 👍 2 🔁 1 💬 0 📌 0
Post image

Honored to have received "Distinguished Reviewer Award" at USENIX Security Symposium 2025 🎉

www.usenix.org/sites/defaul...

23.09.2025 05:53 👍 1 🔁 0 💬 0 📌 0
Preview
Big Help or Big Brother? UC Davis Study Reveals Alarming Browser Tracking A new UC Davis-led study reveals that GenAI browser assistants collect and share sensitive data without users’ knowledge, calling for stronger safeguards, transparency and awareness to protect user pr...

@yash-vekaria.bsky.social is presenting his research "Big Help or Big Brother?" at the 2025 USENIX Security Symposium this week. The paper shows tracking and profiling risks in GenAI browser assistants. #USENIXSecurity

engineering.ucdavis.edu/news/big-hel...

13.08.2025 19:13 👍 3 🔁 1 💬 0 📌 0
Video thumbnail

Worth a watch:

Head of Signal, Meredith Whittaker, on so-called "agentic AI" and the difference between how it's described in the marketing and what access and control it would actually require to work as advertised.

26.06.2025 16:28 👍 11008 🔁 4407 💬 203 📌 725
Preview
Yes, Your TV Is Probably Spying on You. Your Fridge, Too. Here’s What They Know.

@yash-vekaria.bsky.social's research on ACR-tracking by Smart TVs featured in @nytimes.com @nytwirecutter.bsky.social.

Checkout the article: nytimes.com/wirecutter/r...

25.06.2025 09:39 👍 1 🔁 1 💬 0 📌 0
Your TV Is Spying On You and Taking Screenshots
Your TV Is Spying On You and Taking Screenshots YouTube video by Naomi Brockwell TV

.@yash-vekaria.bsky.social describing privacy risks of ACR-based smart TV tracking
www.youtube.com/watch?v=jeq2...

21.06.2025 17:18 👍 1 🔁 1 💬 0 📌 0

w/ Yohan Beugin @shaoormunir.bsky.social, Gunes Acar, Nataliia Bielova, @englehardt.bsky.social, @umariqbal.bsky.social, @kapravelos.com, @rockpartridge.bsky.social, Nick Nikiforakis, Jason Polakis, @franziroesner.bsky.social, @zubair-shafiq.bsky.social, Sebastian Zimmeck

18.06.2025 12:15 👍 1 🔁 0 💬 0 📌 0
Post image

We systematize developments in web tracking and identify open problems in the field in our new work: arxiv.org/abs/2506.14057

18.06.2025 12:15 👍 5 🔁 2 💬 1 📌 0