Risk
7/31/2013
11:26 AM
50%
50%

U.K. Online Dating Sites Catch Heat On Privacy

Government and BBC investigations raise alarms about the industry's personal data handling practices, social media identity theft.

In the same week the BBC claims to have uncovered the way unscrupulous U.K. online dating agencies "are preying on those looking for love," the country's privacy watchdog has separately warned four of the biggest local players to better police the way they handle client data.

In "Tainted Love: Secrets of the Dating Game," the state broadcaster's flagship current affairs program, Panorama, claimed to have uncovered a wide range of questionable practices by the online dating industry.

These include deliberate use of millions of photos and private details taken from social media sites without consent and reused to set up fake profiles of imaginary potential partners to, in the program's words, "tempt the lovelorn."

[ Want to learn more about data security? Read Record-Setting Data Breach Highlights Corporate Security Risks. ]

The documentary featured interviews with former online dating agency staffers who admitted on camera how they'd used such data to create fake profiles and adopt multiple personas to reel in those looking for love -- and to boost profits.

The report also claimed the sources of this illegally obtained personal material ranged from British celebrities, politicians and even children. On camera, one former employee said that other European countries (notably Spain) were the main target, with easy pickings apparently coming from platforms such as MySpace.

As part of the investigation, reporters posing as prospective dating agency business openers were able to buy 10,000 people's details, including birthdates and sexual preferences. That dataset included a member of the House of Lords, academics and BBC staff, all of whom told the BBC they had never signed up for such services.

At the same time, British privacy czar the Information Commissioner's Office (ICO) carried out its own investigation of dating sites. The ICO wrote to the U.K. branches of OKCupid, eHarmony, Match.com and Global Personals, plus the industry trade body, the Association of British Introduction Agencies, to alert it to similar concerns.

Letters have been sent warning the bodies that they could be in breach of the Data Protection Act over poor handling of personal details.

Specifically, the ICO is worried about poor visibility of terms and conditions about the use of personal information on these sites. They expressed concern that users must provide personal details to the companies before those terms and conditions are disclosed, as well as the companies' claims to take no responsibility about the loss of personal data. In addition, the regulator is unhappy about the fact that once signed up, daters seemingly have to agree to the sites having "perpetual" or "irrevocable" license to use their data.

Simon Entwisle, ICO director of operations, said, "The evidence we’re being presented with by the media suggests quite concerning business practices by some dating websites, and there are particular questions around how people’s information is being used that need to be answered. It’s concerning to see that there appear to be sites which, as a matter of course, are falling far short of the legal standards for ensuring information is accurate and up to date."

However, "the number of complaints we’re getting from the public is not very high. That could be because this is only an issue with a small minority of websites, or it could be because people are reluctant to come forward," the ICO conceded.

In any case, the body says it will now probe further to try and determine the scale of the issue. It has asked anyone concerned about possible misuse of their personal information to contact its investigators.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Elite Dating
50%
50%
Elite Dating,
User Rank: Apprentice
8/4/2013 | 12:21:41 AM
re: U.K. Online Dating Sites Catch Heat On Privacy
Very glad that things will be tightened up regarding online dating. Too much underhand tactics when dealing with one of the most important aspects of a persons life. www.elanlondon.co.uk
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1421
Published: 2014-11-25
mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

CVE-2014-3605
Published: 2014-11-25
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6407. Reason: This candidate is a reservation duplicate of CVE-2014-6407. Notes: All CVE users should reference CVE-2014-6407 instead of this candidate. All references and descriptions in this candidate have been removed to pre...

CVE-2014-7839
Published: 2014-11-25
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.

CVE-2014-8001
Published: 2014-11-25
Buffer overflow in decode.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded media file.

CVE-2014-8002
Published: 2014-11-25
Use-after-free vulnerability in decode_slice.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded media file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?