Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

12/19/2018
01:15 PM
Kelly Sheridan
Kelly Sheridan
Quick Hits
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Facebook Data Deals Extend to Microsoft, Amazon, Netflix

An explosive new report sheds light on data-sharing deals that benefited 150 companies as Facebook handed over unknowing users' information.

If you shared data with Facebook over the past few years, there's a high chance Facebook handed it to Microsoft, Amazon, Spotify, or any of the other 150 companies that benefited from extensive data-sharing deals with the social media giant, The New York Times reports.

Internal Facebook records provide a more detailed look at data-sharing practices intended to help Facebook and its partners at the expense of users' privacy. For example, Facebook let Microsoft's Bing search engine view the names of "virtually all Facebook users' friends without consent," the report states. Netflix and Spotify could read account holders' private messages.

Documents show the partnerships primarily benefited tech businesses but were also done with online retailers, entertainment sites, automakers, and media outlets, all of which had applications seeking data of hundreds of millions of people a month. The oldest deals were done in 2010; all were still active in 2017, and some continue to be in effect this year.

Facebook says it's fading many of these partnerships and there is no evidence of data abuse by partner companies. It did admit to managing some deals poorly and letting companies continue accessing users' data after they had disabled application features that needed it.

The findings have prompted inquiries about an agreement Facebook made with the Federal Trade Commission in 2011. As part of the deal, Facebook was prohibited from sharing user data without permission. Steve Satterfield, director of privacy and public policy at Facebook, said to the Times that none of the company's deals dishonored the agreement or users' privacy.

Facebook holds that it was not required to obtain user consent as part of these data-sharing deals because it considers partner organizations "extensions of itself." Data privacy experts argue against this, and FTC employees say Facebook's partnerships broke their 2011 deal.

You can read more details in the full NYT report here.

Facebook has since responded to the article. In a blog post published Dec. 18, Konstantinos Papamiltiadis, director of developer platforms and programs, explains how there were two purposes to granting major tech companies access to user data: to help people access Facebook accounts and features on outside devices and platforms, and to build "more social experiences" – for example, to view recommendations from Facebook friends on Pandora and Spotify.

People want to use Facebook features on devices and products the company doesn't support, he says. Integration partnerships with Amazon, Apple, Microsoft, and Yahoo aim to enable use of Facebook features across services. However, as former Facebook CISO Alex Stamos points out, there's a big difference between integration partnerships and sending secret data.

The former can be good: allowing for third-party clients, he says, is a positive move among dominant tech platforms. As an example, he points to Gmail: Limiting usage of Gmail to Android would be wrong. However, integrations that permit the transfer of illicit data to other companies' servers "really is wrong." Stamos calls for Facebook to build a table listing partner companies, the type of integration used, which data was accessible, steps needed to activate integration, and if/when the integration was shut down.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
7 Old IT Things Every New InfoSec Pro Should Know
Joan Goodchild, Staff Editor,  4/20/2021
News
Cloud-Native Businesses Struggle With Security
Robert Lemos, Contributing Writer,  5/6/2021
Commentary
Defending Against Web Scraping Attacks
Rob Simon, Principal Security Consultant at TrustedSec,  5/7/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Take me to your BISO 
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-32053
PUBLISHED: 2021-05-10
JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database after the attack stops) via history requests. This occurs because of a SELECT COUNT statement that requires a full index scan, with an accompanying large amount of server resources if there are m...
CVE-2020-18102
PUBLISHED: 2021-05-10
Cross Site Scripting (XSS) in Hotels_Server v1.0 allows remote attackers to execute arbitrary code by injecting crafted commands the data fields in the component "/controller/publishHotel.php".
CVE-2020-27232
PUBLISHED: 2021-05-10
An exploitable SQL injection vulnerability exists in ‘manageServiceStocks.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
CVE-2020-28600
PUBLISHED: 2021-05-10
An out-of-bounds write vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially crafted STL file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2021-21430
PUBLISHED: 2021-05-10
OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Using `File.createTempFile` in JDK will result in creating and using insecure temporary files that can leave application and system data vu...