Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

12/19/2018
01:15 PM
Kelly Sheridan
Kelly Sheridan
Quick Hits
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Facebook Data Deals Extend to Microsoft, Amazon, Netflix

An explosive new report sheds light on data-sharing deals that benefited 150 companies as Facebook handed over unknowing users' information.

If you shared data with Facebook over the past few years, there's a high chance Facebook handed it to Microsoft, Amazon, Spotify, or any of the other 150 companies that benefited from extensive data-sharing deals with the social media giant, The New York Times reports.

Internal Facebook records provide a more detailed look at data-sharing practices intended to help Facebook and its partners at the expense of users' privacy. For example, Facebook let Microsoft's Bing search engine view the names of "virtually all Facebook users' friends without consent," the report states. Netflix and Spotify could read account holders' private messages.

Documents show the partnerships primarily benefited tech businesses but were also done with online retailers, entertainment sites, automakers, and media outlets, all of which had applications seeking data of hundreds of millions of people a month. The oldest deals were done in 2010; all were still active in 2017, and some continue to be in effect this year.

Facebook says it's fading many of these partnerships and there is no evidence of data abuse by partner companies. It did admit to managing some deals poorly and letting companies continue accessing users' data after they had disabled application features that needed it.

The findings have prompted inquiries about an agreement Facebook made with the Federal Trade Commission in 2011. As part of the deal, Facebook was prohibited from sharing user data without permission. Steve Satterfield, director of privacy and public policy at Facebook, said to the Times that none of the company's deals dishonored the agreement or users' privacy.

Facebook holds that it was not required to obtain user consent as part of these data-sharing deals because it considers partner organizations "extensions of itself." Data privacy experts argue against this, and FTC employees say Facebook's partnerships broke their 2011 deal.

You can read more details in the full NYT report here.

Facebook has since responded to the article. In a blog post published Dec. 18, Konstantinos Papamiltiadis, director of developer platforms and programs, explains how there were two purposes to granting major tech companies access to user data: to help people access Facebook accounts and features on outside devices and platforms, and to build "more social experiences" – for example, to view recommendations from Facebook friends on Pandora and Spotify.

People want to use Facebook features on devices and products the company doesn't support, he says. Integration partnerships with Amazon, Apple, Microsoft, and Yahoo aim to enable use of Facebook features across services. However, as former Facebook CISO Alex Stamos points out, there's a big difference between integration partnerships and sending secret data.

The former can be good: allowing for third-party clients, he says, is a positive move among dominant tech platforms. As an example, he points to Gmail: Limiting usage of Gmail to Android would be wrong. However, integrations that permit the transfer of illicit data to other companies' servers "really is wrong." Stamos calls for Facebook to build a table listing partner companies, the type of integration used, which data was accessible, steps needed to activate integration, and if/when the integration was shut down.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
7 Old IT Things Every New InfoSec Pro Should Know
Joan Goodchild, Staff Editor,  4/20/2021
News
Cloud-Native Businesses Struggle With Security
Robert Lemos, Contributing Writer,  5/6/2021
Commentary
Defending Against Web Scraping Attacks
Rob Simon, Principal Security Consultant at TrustedSec,  5/7/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-31922
PUBLISHED: 2021-05-14
An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.
CVE-2021-32051
PUBLISHED: 2021-05-14
Hexagon G!nius Auskunftsportal before 5.0.0.0 allows SQL injection via the GiPWorkflow/Service/DownloadPublicFile id parameter.
CVE-2021-32615
PUBLISHED: 2021-05-13
Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.
CVE-2021-33026
PUBLISHED: 2021-05-13
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g., filesystem, Memcached, Redis, etc.), they can construct a crafted payload, poison the ca...
CVE-2021-31876
PUBLISHED: 2021-05-13
Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes it easier for attackers to trigger a loss of funds, or a denial of service attack against downstream projects such as Lightning network nodes. An unconfirmed child transaction with ...