Risk
7/31/2013
11:26 AM
Connect Directly
RSS
E-Mail
50%
50%

U.K. Online Dating Sites Catch Heat On Privacy

Government and BBC investigations raise alarms about the industry's personal data handling practices, social media identity theft.

In the same week the BBC claims to have uncovered the way unscrupulous U.K. online dating agencies "are preying on those looking for love," the country's privacy watchdog has separately warned four of the biggest local players to better police the way they handle client data.

In "Tainted Love: Secrets of the Dating Game," the state broadcaster's flagship current affairs program, Panorama, claimed to have uncovered a wide range of questionable practices by the online dating industry.

These include deliberate use of millions of photos and private details taken from social media sites without consent and reused to set up fake profiles of imaginary potential partners to, in the program's words, "tempt the lovelorn."

[ Want to learn more about data security? Read Record-Setting Data Breach Highlights Corporate Security Risks. ]

The documentary featured interviews with former online dating agency staffers who admitted on camera how they'd used such data to create fake profiles and adopt multiple personas to reel in those looking for love -- and to boost profits.

The report also claimed the sources of this illegally obtained personal material ranged from British celebrities, politicians and even children. On camera, one former employee said that other European countries (notably Spain) were the main target, with easy pickings apparently coming from platforms such as MySpace.

As part of the investigation, reporters posing as prospective dating agency business openers were able to buy 10,000 people's details, including birthdates and sexual preferences. That dataset included a member of the House of Lords, academics and BBC staff, all of whom told the BBC they had never signed up for such services.

At the same time, British privacy czar the Information Commissioner's Office (ICO) carried out its own investigation of dating sites. The ICO wrote to the U.K. branches of OKCupid, eHarmony, Match.com and Global Personals, plus the industry trade body, the Association of British Introduction Agencies, to alert it to similar concerns.

Letters have been sent warning the bodies that they could be in breach of the Data Protection Act over poor handling of personal details.

Specifically, the ICO is worried about poor visibility of terms and conditions about the use of personal information on these sites. They expressed concern that users must provide personal details to the companies before those terms and conditions are disclosed, as well as the companies' claims to take no responsibility about the loss of personal data. In addition, the regulator is unhappy about the fact that once signed up, daters seemingly have to agree to the sites having "perpetual" or "irrevocable" license to use their data.

Simon Entwisle, ICO director of operations, said, "The evidence we’re being presented with by the media suggests quite concerning business practices by some dating websites, and there are particular questions around how people’s information is being used that need to be answered. It’s concerning to see that there appear to be sites which, as a matter of course, are falling far short of the legal standards for ensuring information is accurate and up to date."

However, "the number of complaints we’re getting from the public is not very high. That could be because this is only an issue with a small minority of websites, or it could be because people are reluctant to come forward," the ICO conceded.

In any case, the body says it will now probe further to try and determine the scale of the issue. It has asked anyone concerned about possible misuse of their personal information to contact its investigators.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Elite Dating
50%
50%
Elite Dating,
User Rank: Apprentice
8/4/2013 | 12:21:41 AM
re: U.K. Online Dating Sites Catch Heat On Privacy
Very glad that things will be tightened up regarding online dating. Too much underhand tactics when dealing with one of the most important aspects of a persons life. www.elanlondon.co.uk
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2010-5110
Published: 2014-08-29
DCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

CVE-2012-1503
Published: 2014-08-29
Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.

CVE-2013-5467
Published: 2014-08-29
Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM)...

CVE-2014-0600
Published: 2014-08-29
FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.

CVE-2014-0888
Published: 2014-08-29
IBM Worklight Foundation 5.x and 6.x before 6.2.0.0, as used in Worklight and Mobile Foundation, allows remote authenticated users to bypass the application-authenticity feature via unspecified vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.