Web

Facebook Personal Data a Security Risk

Making more user information public has both privacy and security dangers, experts warn.

  • Tuesday, May 18, 2010
  • By Robert Lemos

Last month, Facebook finally crossed a line. The company announced that it would make certain user information--including a user's name, hometown, education, work, and "likes" and "dislikes"--permanently public.

Facebook's default privacy policy has gradually shifted to expose more user data to the wider Web, but the reaction to this latest change has been significant. Last week, a collection of European data-protection authorities known as the Article 29 Working Group sent Facebook a letter chastising the company for not allowing users to limit access to their social data. The letter follows a similar criticism of Facebook by several members of congress, such as Sen. Charles Schumer, D-NY, over the past month. The reaction from privacy advocacy groups, and from many of Facebook's users, has also been vocal.

Some experts also say that the increase in information disclosure could have a serious side-effect--opening up new opportunities for hackers. Kevin Johnson, a senior researcher with security firm InGuardians, uses Facebook as a starting point for his job: testing companies' network security. Many times, he says, the most significant vulnerabilities are not in hardware or software, but in a users' use of social networks. The information leaked on social networking sites can be used to impersonate a legitimate person, in order to recover a password, for example; or to trick users into opening a malicious file by making it appear to come from a friend or a colleague.

"As a penetration tester--as an attacker--Facebook's privacy settings have made my job easier," Johnson says. "In the past, before two years ago, we had to trick people into running a [rogue] application [to collect data]. Now, the majority of people out there--the bulk of Facebook--run under default privacy settings."

Advertisement

Pushed by a need to monetize the data entered by users, Facebook has increasingly loosened its privacy policies. In 2005, the company's original policy stated that no information would be shared with people "who [do] not belong to at least one of the groups specified by you in your privacy settings." By 2010, the policy had changed to one that focuses on sharing much more information, stating that applications and Web sites "will have access to General Information about you." The text of the company's privacy policy has grown nearly 500 percent and users are now required to navigate some 50 different privacy settings.

"Facebook says that they are introducing more privacy settings because they want to give users more control, but what they have done is make things more confusing," says Fred Stutzman, a privacy researcher and PhD candidate at the University of North Carolina at Chapel Hill. "Over time they have made changes that make people's information more open, because that is how they drive the use of the network."

"This is something that is different from how Facebook had been operating," says Kurt Opsahl, a senior staff attorney with the Electronic Frontier Foundation. "In the past, they encouraged sharing that information, but now they have taken information that many people consider private and made it public, and they did so in a very heavy-handed way."

Print

Related Articles

Scrutinizing Facebook Spam

Researchers downloaded 3.5 million profiles to see how accounts are used to send out spam.

A Private Social Network for Cell Phones

Users can share information, but the network only sees encrypted data.

The Changing Nature of Privacy on Facebook

Microsoft's Danah Boyd on social networking.

Close Comments

To comment, please sign in or register

Forgot my password

hotrao

4 Comments

  • 629 Days Ago
  • 05/18/2010

Facebook options are too much

What really makes me think is the amount of options available and possible security implications.

For me is one of the cases where, trying to cover every aspect of the problem, then major security problems happen.

While I understand, but don’t like, the need that is invading everybody to have customizable and personalized solutions, I also understand that having a thousand of options is like having no options.

On the other side, defining and maintaining all those options available is really effort consuming, especially if compared to the average Facebook user that really doesn’t know a half of these.

I think that Facebook should understand at full extent that is no more a “geeky lab” allowed to think of everything that comes in mind

Reply

  • 628 Days Ago
  • 05/19/2010

A longer view

I am in agreement that most users probably dont know what to do re privacy and how it works and that facebook is thinking from a "techo" perspective.
I have four kids that use facebook and they have no idea about privacy risks (despite my attemps to educate)nor would all of their friends. They understand "stranger danger" but would not think about the longer term implications of what they are doing as teens now, and how organisations in future may use this knowledge.
We all do things when we are young we regret later and this can equally apply to what happens in Facebook today.
This is a dilemma that needs to be addressed by society, and individuals, not companies.
Perhaps the "tribal elders" of our communities need to be sharing more wisdom with the youth.
Does anyone else worry about the longer term implications of social technologies on our next generations?

Reply

Advertisement

MAGAZINE

Can We Build Tomorrow's Breakthroughs?

Manufacturing in the United States is in trouble. That's bad news not just for the country's economy but for the future of innovation.

Videos

A Social-Media Decoder

More

Advertisement

Technology Review Lists

TR50

Our list of the 50 most innovative companies, including the following:

Apple

American Superconductor

Nissan

Suntech

More

Advertisement

Facebook

Advertisement