Risk
5/26/2010
04:07 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Facebook Promises Less Public Information, More Control

To quell the complaints of critics, Facebook has reworked its privacy controls to make them easier to understand.

In the wake of rising doubt about Facebook's commitment to privacy, the social networking site said on Wednesday that it plans to roll out simplified privacy controls designed to offer users more control over the information they share.

Facebook CEO Mark Zuckerberg announced the changes at a press conference. "It's been a pretty intense few weeks for us," he conceded as he described how the company had gathered a term of engineers together to address a problem that has attracted the attention government regulators in the U.S. and Europe.

Zuckerberg suggested that Facebook's recent actions had been misperceived and stressed that the company remains committed to giving users control over their information.

"The number one thing we've heard is through all these changes [is that] the settings have gotten complex and it has become hard for people to use them," he said.

Facebook's simplified privacy controls offer users one menu with three settings that determine who can see shared content: friends, friends of friends, and everyone.

This meta-setting will apply to all content shared by the user: past, present, and future.

The company's more granular controls will still be available to users who wish to use them.

Facebook is also reducing the amount of information visible through connections by giving users control over who can see their friends and pages. Facebook profiles will soon show only the user's name, profile picture (if one has been uploaded), gender (optional), and networks (if any).

The company has added a way to opt-out of the Facebook Platform completely, so users don't have to worry about their information being shared with third-party application providers.

Leslie Harris, president of the Center for Democracy and Technology, a group that has supported greater privacy on Facebook, offered cautious support for the new controls.

"Facebook's users have spoken and made it clear that they want control of their information," she said in a statement. "Despite all rumors to the contrary, privacy is not dead, it is on its way to a comeback in the form of simplified controls and better policies. While more work still needs to be done, these changes are the building blocks for giving people what they want and deserve."

Josh Abraham, a security researcher with Rapid7, said it was too early to tell whether the changes would be effective in protecting users and suggested that lack of privacy is the cost of using such services.

"Web sites like Facebook and Google make money off ads and data mining their users," he said. "All those services may not cost anything, but you give up your privacy to use them."

Or as Zuckerberg put it, "We believe that people come into this wanting to share and stay connected."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: The latest security upgrade to the OPM site
Current Issue
E-Commerce Security: What Every Enterprise Needs to Know
The mainstream use of EMV smartcards in the US has experts predicting an increase in online fraud. Organizations will need to look at new tools and processes for building better breach detection and response capabilities.
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
Join Dark Reading community editor Marilyn Cohodas in a thought-provoking discussion about the evolving role of the CISO.