Facebook vows to fix a flaw in data privacy

Advertisement
By Miguel Helft, New York Times | Updated: 5 June 2012 02:23 IST
Highlights
  • When you sign up for Facebook, you enter into a bargain. You share personal information with the site, and Facebook agrees to obey your wishes when it comes to who can see what you post. It is a complicated deal that many people enter into without perhaps
When you sign up for Facebook, you enter into a bargain. You share personal information with the site, and Facebook agrees to obey your wishes when it comes to who can see what you post.

At the same time, you agree that Facebook can use that data to decide what ads to show you.

It is a complicated deal that many people enter into without perhaps fully understanding what will happen to their information. It also involves some trust -- which is why any hint that Facebook may not be holding up its end of the bargain is sure to kick up plenty of controversy.

The latest challenge to that trust came on Monday, when Facebook acknowledged that some applications on its site, including the popular game FarmVille, had improperly shared identifying information about users, and in some cases their friends, with advertisers and Web tracking companies. The company said it was talking to application developers about how they handled personal information, and was looking at ways to prevent this from happening again.

Facebook's acknowledgment came in response to an article in The Wall Street Journal that said several popular applications were passing a piece of data known as a user ID to outside companies, in violation of Facebook's privacy policy.

Having a user ID allows someone to look up that user's name and any data posted on that person's public profile, like a college or favorite movies, but not information that the user had set to be visible only to friends.

Privacy advocates and technology experts were split on the significance of the issue.

"That is extremely serious," said Peter Eckersley, a senior staff technologist at the Electronic Frontier Foundation, an online liberties group.

Eckersley said advertisers could use the user IDs to link individuals with information they had collected anonymously about them on the Web. "Facebook, perhaps inadvertently, is leaking the magic key to tracking you online," he said.

At the same time, Eckersley said there was no evidence that anyone who had access to this data had actually misused it.

Zynga, the maker of FarmVille and other games on Facebook that have a combined 219 million users, did not respond to requests for comment.

Several technology pundits and bloggers minimized the issue, with some saying that credit card companies and magazines have access to far more detailed information about customers than any Facebook application.

Facebook also sought to play down the importance of the leak, saying the sending of user IDs appeared to have been inadvertent. "Press reports have exaggerated the implications of sharing" a user ID, Mike Vernal, a Facebook engineer, wrote on a company blog for application developers. "Knowledge of a UID does not enable anyone to access private user information without explicit user consent."

In a statement, Facebook said that while it would be a challenge to do so, it planned to introduce "new technical systems that will dramatically limit the sharing of user IDs," and would continue to enforce its policies on outside applications, shutting them down when necessary. It added that the companies that had received the user IDs said they had not made use of them.

Regardless, the problem underscores another challenge facing the company: Facebook has grown so rapidly, in both users and in technical complexity, that it finds it increasingly difficult to control everything that happens on its site. In addition to more than 500 million Facebook users, there are more than one million third-party applications running on the site.

The latest information leak was made possible by a quirk in a long-established technical standard used by Web browsers. The standard allows Web sites to record the address of the page a user clicked on to arrive there, a bit of information known as a referrer.

Facebook has been including user IDs in these referrers for some time, and last year technology experts pointed out that user IDs had leaked to advertisers that way. Facebook fixed that this year, but apparently never addressed the problem when it came to referrers used by applications on its site.

"Facebook isn't benefiting from it, and Facebook is not intentionally leaking this data," said Christopher Soghoian, a privacy advocate and research fellow at the Center for Applied Cybersecurity Research at Indiana University. "But it is not a trivial thing to re-engineer their systems."

This year he filed a complaint with the Federal Trade Commission, claiming Google was leaking personal information because search terms appeared in its referrers.

The latest issue may have had particular resonance with Facebook users because the company has been reeling from a series of privacy controversies, in part because it has been subtly pushing users to share data more publicly.

This year, for example, many users complained when Facebook changed the way in which users expressed preferences for certain movies or bands, essentially making it more difficult to keep that information private.

And in May, after a series of complaints from some users and privacy advocates, the company made wholesale changes to its privacy settings.

Mark Zuckerberg, the company's chief executive, apologized to users, saying the settings were often too complicated for people to understand. Despite the changes, the privacy issue has continued to dog Facebook.

"This is one more straw on the camel's back that suggests that Facebook needs to think holistically not just about its privacy policies, but also about baking privacy into their technical design," said Deirdre Mulligan, a privacy expert and professor at the School of Information at the University of California, Berkeley.



For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Moto Book 60 Pro With Up to Intel Core Ultra 7 CPU Launched in India
  2. Lenovo Unveils Second-Gen Legion Go Handheld With Big Upgrades, Bigger Price
  3. OnePlus 15 Will Swap Hasselblad-Tuned Cameras for This New Image Engine
  4. Amazon Great Indian Festival 2025: Smartphone Deals Teased Ahead of Sale
  5. Nothing Ear 3 Teaser Drops Ahead of Imminent Launch
  6. Amazon Great Indian Festival Sale 2025: Deals on Laptops, Tablets Teased
  7. IFA 2025: Motorola Edge 60 Neo Unveiled Alongside Moto G06, Moto G06 Power
  8. Samsung Galaxy S26 Series Leaked Dummies Hint at iPhone-Like Design
  1. Who Is Amit Kshatriya: Indian-Origin Appointed as NASA’s Associate Administrator
  2. Astronomers Discover Stellar Graveyard Filled With Black Hole and Neutron Star Collisions
  3. Scientists Visualize New Gold Quantum Needles at Nanoscale
  4. NASA and NOAA Set to Launch Solar Probes for Space Weather Forecasting
  5. Qualcomm Partners BMW to Bring New Automated Driving System to BMW iX3 SUV
  6. James Webb Spots Bizarre Planet-Forming Disk Full of Carbon Dioxide
  7. IFA 2025: Lenovo Legion Pro 7 (2025) With Nvidia RTX 5080 GPU Unveiled Alongside ThinkBook VertiFlex Concept
  8. Google Reportedly Lists New Outdoor and Indoor Nest Cam Models Alongside Nest Doorbell in Google Home App
  9. Samsung Galaxy Tab S11, Galaxy Tab S11 Ultra Price in India Announced; Pre-Orders Open Ahead of Sale
  10. Nubia Air Launched at IFA 2025 With Sleek 5.9mm Profile and 5,000mAh Battery: Price, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.