Risk
1/11/2010
05:34 PM
Connect Directly
RSS
E-Mail
50%
50%

Facebook CEO: Less Privacy Is Social Norm

Mark Zuckerberg says the social network's approach to privacy reflects the comfort people have with sharing personal information online.

Mark Zuckerberg, chief executive of Facebook, has defended the social network's approach to user privacy as keeping up with the "social norm" of sharing an increasing amount of personal information on the Web.

Zuckerberg's comments during an interview with TechCrunch's Michael Arrington followed about a month after Facebook drew criticism for making changes that opened users' status updates to the entire Web, unless the user proactively changed the default setting.

While not discussing the criticisms directly, Zuckerberg explained that Facebook was driven by evolving social norms in determining how to handle privacy on the site.

"People have really gotten comfortable not only sharing more information and different kinds, but more openly and with more people," Zuckerberg said during the interview at last week's Crunchie awards presentation. "And that social norm is just something that has evolved over time, and we view it as our role in the system to constantly be innovating and updating what our system is to reflect what the current social norms are."

Facebook's reading of the social norms of the day has not been met favorably with at least one Internet privacy group. The Electronic Privacy Information Center last month filed a formal complaint with the Federal Trade Commission, saying Facebook shouldn't be allowed to "turn down the privacy dial" on its site. Facebook has more than 350 million users worldwide, including more than 100 million in the United States.

Facebook has taken the opposite view of its recent changes, saying they make it easier for members to control who can see which pieces of information. Indeed, Facebook added a tool that lets users select privacy settings for each post they place on the site. They can choose whether to make the information available to the general public, all their Facebook friends, or a list of particular friends, family members, or work colleagues.

But some users complained that setting privacy wasn't easy. "I have spent the last 20 minutes trying to find the option to not allow this (making posts generally available), what a joke," Haem Guy said on the unofficial blog AllFacebook.com. "I thought the new privacy settings were to make it stricter not more open."

Facebook walks a fine line with privacy on the site. The company's value as a business lies in the data it stores on user activity and making it available to others, including advertisers. The more willing users are to share information, then the more valuable the data Facebook holds.

Therefore, Zuckerberg's comments could be viewed as self-serving, particularly in arguing that people are getting used to sharing more information on the Web.

"In the last five or six years, blogging has taken off in a huge way and all these different services that have people sharing more information," he said. "People have really gotten comfortable not only sharing more information and different kinds, but more openly and with more people."

However, Internet privacy and the protection of personal information is a growing concern among advocacy groups. In September, a coalition of 10 consumer and privacy groups urged Congress to draft legislation to preserve consumer privacy online by limiting behavioral advertising and establishing new ground rules for information collection and use.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3341
Published: 2014-08-19
The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616.

CVE-2014-3464
Published: 2014-08-19
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers ...

CVE-2014-3472
Published: 2014-08-19
The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors.

CVE-2014-3490
Published: 2014-08-19
RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have...

CVE-2014-3504
Published: 2014-08-19
The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Dark Reading continuing coverage of the Black Hat 2014 conference brings interviews and commentary to Dark Reading listeners.