Back to results

Science

Transmissions of Hashed Personally Identifiable Information to Third Parties Across Websites

Abstract

dc:description.abstract

Many websites share users’ personal information with third-party trackers in hashed form, often claiming that hash functions provide privacy protection. Previous literature has shown this to be false by successfully re-identifying hashes of common personally identifiable information (PII). Despite this, websites continue to share hashed PII while making claims that understate the privacy risks for users. To investigate the prevalence of this practice, we present Hem and Haw, a browser extension that detects and logs transmissions of hashed PII. Employing this tool, we conduct a field study with over 100 participants and observe widespread sharing of hashed PII—including email addresses, phone numbers, and demographic information—from hundreds of websites to third-party domains. Our results show that hashed PII is frequently shared with trackers across the Internet. We present case studies where email hashes are exposed publicly in profile pictures and where PII is associated with sensitive browsing history. Moreover, we find previously undocumented evidence that Meta collects PII encoding formats alongside hashes, facilitating re-identification of users’ PII. We further analyze privacy policies of websites found in our results and develop a taxonomy to classify claims about hashing. Our analysis reveals that many policies mentioning hash functions contain misleading statements, including claims of anonymization or de-identification. Even though hashing PII does not offer any security or privacy, websites and companies continue to reinforce a “noble lie” by presenting it as a safeguard for user data.

Degree

thesis:*
Name thesis:degree_name
Master of Science (MSc)
Discipline thesis:degree_discipline
Computer Science
Grantor
Science
Year dc:date.issued
2026

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Le, Nguyen Huu Tin
Advisor dc:contributor.advisor
  • Reardon, Joel
Committee members dc:contributor.committeemember
  • Reardon, Joel
  • Mazmudar, Miti
  • Hagen, Gregory

Subjects

dc:subject × 4

Rights

dc:rights
Statement dc:rights
  • Unless otherwise indicated, this material is protected by copyright and has been made available with authorization from the copyright owner. You may use this material in any way that is permitted by the Copyright Act or through licensing that has been assigned to the document. For uses that are not allowable under copyright legislation or licensing, you are required to seek permission.
Language dc:language.iso
en

Identifiers

dc:identifier.*
OAI identifier oai:identifier
oai:ucalgary.scholaris.ca:1880/124826

Chain of custody

source
Harvested from
University of Calgary
Base URL
ucalgary.scholaris.ca/server/oai/request
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Le, Nguyen Huu Tin. Transmissions of Hashed Personally Identifiable Information to Third Parties Across Websites. Science, 2026. https://hdl.handle.net/1880/124826