{"id":{"repo_id":"calgary","oai_identifier":"oai:ucalgary.scholaris.ca:1880/124826"},"canonical_url":"https://search.dev.ndltd.org/etd/calgary/oai:ucalgary.scholaris.ca:1880/124826","repository":{"repo_id":"calgary","name":"University of Calgary","base_url":"https://ucalgary.scholaris.ca/server/oai/request"},"display":{"title":"Transmissions of Hashed Personally Identifiable Information to Third Parties Across Websites","abstract":"Many websites share users’ personal information with third-party trackers in hashed form, often claiming that hash functions provide privacy protection. Previous literature has shown this to be false by successfully re-identifying hashes of common personally identifiable information (PII). Despite this, websites continue to share hashed PII while making claims that understate the privacy risks for users. To investigate the prevalence of this practice, we present Hem and Haw, a browser extension that detects and logs transmissions of hashed PII. Employing this tool, we conduct a field study with over 100 participants and observe widespread sharing of hashed PII—including email addresses, phone numbers, and demographic information—from hundreds of websites to third-party domains. Our results show that hashed PII is frequently shared with trackers across the Internet. We present case studies where email hashes are exposed publicly in profile pictures and where PII is associated with sensitive browsing history. Moreover, we find previously undocumented evidence that Meta collects PII encoding formats alongside hashes, facilitating re-identification of users’ PII. We further analyze privacy policies of websites found in our results and develop a taxonomy to classify claims about hashing. Our analysis reveals that many policies mentioning hash functions contain misleading statements, including claims of anonymization or de-identification. Even though hashing PII does not offer any security or privacy, websites and companies continue to reinforce a “noble lie” by presenting it as a safeguard for user data.","abstract_html":"Many websites share users’ personal information with third-party trackers in hashed form, often claiming that hash functions provide privacy protection. Previous literature has shown this to be false by successfully re-identifying hashes of common personally identifiable information (PII). Despite this, websites continue to share hashed PII while making claims that understate the privacy risks for users. To investigate the prevalence of this practice, we present Hem and Haw, a browser extension that detects and logs transmissions of hashed PII. Employing this tool, we conduct a field study with over 100 participants and observe widespread sharing of hashed PII—including email addresses, phone numbers, and demographic information—from hundreds of websites to third-party domains. Our results show that hashed PII is frequently shared with trackers across the Internet. We present case studies where email hashes are exposed publicly in profile pictures and where PII is associated with sensitive browsing history. Moreover, we find previously undocumented evidence that Meta collects PII encoding formats alongside hashes, facilitating re-identification of users’ PII. We further analyze privacy policies of websites found in our results and develop a taxonomy to classify claims about hashing. Our analysis reveals that many policies mentioning hash functions contain misleading statements, including claims of anonymization or de-identification. Even though hashing PII does not offer any security or privacy, websites and companies continue to reinforce a “noble lie” by presenting it as a safeguard for user data.","abstract_has_math":false,"creators":["Le, Nguyen Huu Tin"],"institution":"Science","degree_name":"Master of Science (MSc)","degree_level":null,"degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":[],"advisors":["Reardon, Joel"],"committee_chairs":[],"committee_members":["Reardon, Joel","Mazmudar, Miti","Hagen, Gregory"],"year":2026,"date_issued":"2026-05-02","date_published":"2026-05-02","updated_at":"2026-07-24T01:30:22Z","subjects":["Privacy","Hash Functions","Personally Identifiable Information","Web Tracking"],"languages":["en"],"rights":["Unless otherwise indicated, this material is protected by copyright and has been made available with authorization from the copyright owner. You may use this material in any way that is permitted by the Copyright Act or through licensing that has been assigned to the document. For uses that are not allowable under copyright legislation or licensing, you are required to seek permission."],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier.doi","label":"DOI","values":["https://dx.doi.org/10.11575/PRISM/51400"],"render_values":[{"text":"https://dx.doi.org/10.11575/PRISM/51400","href":"https://dx.doi.org/10.11575/PRISM/51400","code":true}]}]},"links":{"outbound_url":"https://hdl.handle.net/1880/124826","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Reardon, Joel"]},{"key":"dc:contributor.committeemember","label":"Committee Member","values":["Reardon, Joel","Mazmudar, Miti","Hagen, Gregory"]},{"key":"dc:creator","label":"Author","values":["Le, Nguyen Huu Tin"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2026-06"]},{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2026-05-04T21:05:56Z"]},{"key":"dc:date.issued","label":"Date","values":["2026-05-02"]},{"key":"dc:type","label":"Dc Type","values":["master thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science (MSc)"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Calgary"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Privacy","Hash Functions","Personally Identifiable Information","Web Tracking"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Unless otherwise indicated, this material is protected by copyright and has been made available with authorization from the copyright owner. You may use this material in any way that is permitted by the Copyright Act or through licensing that has been assigned to the document. For uses that are not allowable under copyright legislation or licensing, you are required to seek permission."]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.doi","label":"DOI","values":["https://dx.doi.org/10.11575/PRISM/51400"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/1880/124826"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Many websites share users’ personal information with third-party trackers in hashed form, often claiming that hash functions provide privacy protection. Previous literature has shown this to be false by successfully re-identifying hashes of common personally identifiable information (PII). Despite this, websites continue to share hashed PII while making claims that understate the privacy risks for users. To investigate the prevalence of this practice, we present Hem and Haw, a browser extension that detects and logs transmissions of hashed PII. Employing this tool, we conduct a field study with over 100 participants and observe widespread sharing of hashed PII—including email addresses, phone numbers, and demographic information—from hundreds of websites to third-party domains. Our results show that hashed PII is frequently shared with trackers across the Internet. We present case studies where email hashes are exposed publicly in profile pictures and where PII is associated with sensitive browsing history. Moreover, we find previously undocumented evidence that Meta collects PII encoding formats alongside hashes, facilitating re-identification of users’ PII. We further analyze privacy policies of websites found in our results and develop a taxonomy to classify claims about hashing. Our analysis reveals that many policies mentioning hash functions contain misleading statements, including claims of anonymization or de-identification. Even though hashing PII does not offer any security or privacy, websites and companies continue to reinforce a “noble lie” by presenting it as a safeguard for user data."]},{"key":"dc:title","label":"Title","values":["Transmissions of Hashed Personally Identifiable Information to Third Parties Across Websites"]}]}],"canonical_facts":{"dc:contributor.advisor":["Reardon, Joel"],"dc:contributor.committeemember":["Reardon, Joel","Mazmudar, Miti","Hagen, Gregory"],"dc:creator":["Le, Nguyen Huu Tin"],"dc:date":["2026-06"],"dc:date.accessioned":["2026-05-04T21:05:56Z"],"dc:date.issued":["2026-05-02"],"dc:description.abstract":["Many websites share users’ personal information with third-party trackers in hashed form, often claiming that hash functions provide privacy protection. Previous literature has shown this to be false by successfully re-identifying hashes of common personally identifiable information (PII). Despite this, websites continue to share hashed PII while making claims that understate the privacy risks for users. To investigate the prevalence of this practice, we present Hem and Haw, a browser extension that detects and logs transmissions of hashed PII. Employing this tool, we conduct a field study with over 100 participants and observe widespread sharing of hashed PII—including email addresses, phone numbers, and demographic information—from hundreds of websites to third-party domains. Our results show that hashed PII is frequently shared with trackers across the Internet. We present case studies where email hashes are exposed publicly in profile pictures and where PII is associated with sensitive browsing history. Moreover, we find previously undocumented evidence that Meta collects PII encoding formats alongside hashes, facilitating re-identification of users’ PII. We further analyze privacy policies of websites found in our results and develop a taxonomy to classify claims about hashing. Our analysis reveals that many policies mentioning hash functions contain misleading statements, including claims of anonymization or de-identification. Even though hashing PII does not offer any security or privacy, websites and companies continue to reinforce a “noble lie” by presenting it as a safeguard for user data."],"dc:identifier.doi":["https://dx.doi.org/10.11575/PRISM/51400"],"dc:identifier.uri":["https://hdl.handle.net/1880/124826"],"dc:language.iso":["en"],"dc:rights":["Unless otherwise indicated, this material is protected by copyright and has been made available with authorization from the copyright owner. You may use this material in any way that is permitted by the Copyright Act or through licensing that has been assigned to the document. For uses that are not allowable under copyright legislation or licensing, you are required to seek permission."],"dc:subject":["Privacy","Hash Functions","Personally Identifiable Information","Web Tracking"],"dc:title":["Transmissions of Hashed Personally Identifiable Information to Third Parties Across Websites"],"dc:type":["master thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_name":["Master of Science (MSc)"],"thesis:institution_name":["University of Calgary"]},"updated_at":"2026-07-24T01:30:22Z"}