Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

12/19/2018
01:15 PM
Kelly Sheridan
Kelly Sheridan
Quick Hits
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Facebook Data Deals Extend to Microsoft, Amazon, Netflix

An explosive new report sheds light on data-sharing deals that benefited 150 companies as Facebook handed over unknowing users' information.

If you shared data with Facebook over the past few years, there's a high chance Facebook handed it to Microsoft, Amazon, Spotify, or any of the other 150 companies that benefited from extensive data-sharing deals with the social media giant, The New York Times reports.

Internal Facebook records provide a more detailed look at data-sharing practices intended to help Facebook and its partners at the expense of users' privacy. For example, Facebook let Microsoft's Bing search engine view the names of "virtually all Facebook users' friends without consent," the report states. Netflix and Spotify could read account holders' private messages.

Documents show the partnerships primarily benefited tech businesses but were also done with online retailers, entertainment sites, automakers, and media outlets, all of which had applications seeking data of hundreds of millions of people a month. The oldest deals were done in 2010; all were still active in 2017, and some continue to be in effect this year.

Facebook says it's fading many of these partnerships and there is no evidence of data abuse by partner companies. It did admit to managing some deals poorly and letting companies continue accessing users' data after they had disabled application features that needed it.

The findings have prompted inquiries about an agreement Facebook made with the Federal Trade Commission in 2011. As part of the deal, Facebook was prohibited from sharing user data without permission. Steve Satterfield, director of privacy and public policy at Facebook, said to the Times that none of the company's deals dishonored the agreement or users' privacy.

Facebook holds that it was not required to obtain user consent as part of these data-sharing deals because it considers partner organizations "extensions of itself." Data privacy experts argue against this, and FTC employees say Facebook's partnerships broke their 2011 deal.

You can read more details in the full NYT report here.

Facebook has since responded to the article. In a blog post published Dec. 18, Konstantinos Papamiltiadis, director of developer platforms and programs, explains how there were two purposes to granting major tech companies access to user data: to help people access Facebook accounts and features on outside devices and platforms, and to build "more social experiences" – for example, to view recommendations from Facebook friends on Pandora and Spotify.

People want to use Facebook features on devices and products the company doesn't support, he says. Integration partnerships with Amazon, Apple, Microsoft, and Yahoo aim to enable use of Facebook features across services. However, as former Facebook CISO Alex Stamos points out, there's a big difference between integration partnerships and sending secret data.

The former can be good: allowing for third-party clients, he says, is a positive move among dominant tech platforms. As an example, he points to Gmail: Limiting usage of Gmail to Android would be wrong. However, integrations that permit the transfer of illicit data to other companies' servers "really is wrong." Stamos calls for Facebook to build a table listing partner companies, the type of integration used, which data was accessible, steps needed to activate integration, and if/when the integration was shut down.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
The Problem with Proprietary Testing: NSS Labs vs. CrowdStrike
Brian Monkman, Executive Director at NetSecOPEN,  7/19/2019
How Attackers Infiltrate the Supply Chain & What to Do About It
Shay Nahari, Head of Red-Team Services at CyberArk,  7/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-10102
PUBLISHED: 2019-07-22
The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation. The impact is: The attacker can remotely execute any commands by sending malicious http request to the controller. The component is: Method runJavaCompiler in YangLiveCompilerManager.java. The attack vector is: ne...
CVE-2019-10102
PUBLISHED: 2019-07-22
Frog CMS 1.1 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing, Alert pop-up on page, Redirecting to another phishing site, Executing browser exploits. The component is: Snippets.
CVE-2019-10102
PUBLISHED: 2019-07-22
Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stored XSS (or Persistent). The impact is: Execute code in the victim's browser. The component is: Assessment / TestQuestionPool. The attack vector is: Cloze Test Text gap (attacker) / Corrections ...
CVE-2019-9959
PUBLISHED: 2019-07-22
The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo.
CVE-2019-4236
PUBLISHED: 2019-07-22
A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Access Control List (ACL) entries from backup or archive if there are more than twelve ACL entries associated with the object in total. As a result, it could allow a local attacker to ...