Risk

12/17/2009
04:15 PM
50%
50%

Facebook Hit With FTC Complaint

Electronic Privacy Information Center files formal objection against social networking site's privacy changes.

A group that advocates Internet privacy has filed a formal complaint with the Federal Trade Commission over Facebook's decision to open more of its members' information to public view unless they actively take steps to limit their data's exposure.

"More than 100 million people in the United States subscribe to the Facebook service. The company should not be allowed to turn down the privacy dial on so many American consumers," said Marc Rotenberg, executive director of the Electronic Privacy Information Center, in a statement.

Rotenberg said the changes will make too much user information available to the public, and also to third-party application developers that create games, contests, and other programs for Facebook.

In filing the case, EPIC said it received support from the American Library Association, the Center for Digital Democracy, the Consumer Federation of America, Patient Privacy Rights, and other advocacy groups.

Users' biggest complaint about the changes is that the default privacy setting on Facebook now opens their status updates to the entire Web, unless they proactively takes steps to modify the settings.

Facebook claimed Wednesday that it's implementing the changes in an effort to make it easier for members to control who can see which pieces of information they post.

"Facebook is transforming the world's ability to control its information online by empowering more than 350 million people to personalize the audience for each piece of content they share," said Facebook communications VP Elliot Schrage, in a statement.

Facebook added a tool that lets users select privacy settings for literally each post they place on the social networking site. Via a new dropdown menu, users can specify whether the post should be made to the general public, all their Facebook friends, or a list of particular friends, family members, or work colleagues.

Facebook also launched a "transition tool" to guide members through the new settings.

Additionally, Facebook is eliminating regional networks—user groups that allow members within a given geographical region to automatically share content with other network members. Facebook operates such networks around the world, including far-flung areas like India and China.

Facebook founder Mark Zuckerberg has said the regional networks are becoming too large to ensure members' privacy.

For Further Reading:

Facebook Privacy Changes Draw Flak

Facebook Revamp Draws Mixed Reactions

Facebook Revamps Privacy Tools

InformationWeek has published an in-depth report on the public cloud, digging into the gritty details of cloud computing services from a dozen vendors. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
1.9 Billion Data Records Exposed in First Half of 2017
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/20/2017
Get Serious about IoT Security
Derek Manky, Global Security Strategist, Fortinet,  9/20/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.