Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operational Security //

Big Data

// // //
3/23/2018
09:35 AM
Larry Loeb
Larry Loeb
Larry Loeb

In Facebook Debacle, More Than Zuckerberg to Blame

Facebook and CEO Mark Zuckerberg are rightly taking a lot of heat from the fallout over Cambridge Analytica and the firm's use of social media data. However, other businesses, as well as users, need to take some responsibility as well.

Facebook and its privacy practices has been at the top of this week's news cycles as the realization of what went on, starting in 2014 and continuing through the 2016 presidential election, has finally dawned on the general public.

The social media giant, along with CEO Mark Zuckerberg, has been accused of all sorts of malfeasance by the denizens of the Internet, the press and even the US government.

There's a real underlying problem here, though. It's the Facebook users themselves that let all of this happen.

It's not new news that Facebook data has been mined for political purposes before this. The Obama campaign did so quite effectively in 2012.

(Source: Wikimedia)
(Source: Wikimedia)

What sets this apart is that a third-party app was able to figure out the private data of the friends of whoever was using that app. This is something that Facebook claimed in 2011, as part of a consent order with the US Federal Trade Commission that it would not allow for commercial use.

There seems to have been an exception for academic use, which was exploited by a Russian-connected academic turned around and who sold that data to a third party -- the shell company Cambridge Analytica -- in violation of Facebook policies. (See How to Access the Voter Information Dirt Cambridge Analytica Has on You.)

Facebook has a primary business model of providing data on its users to commercial interests, who then buy advertising that is targeted to these users based on this data. It's how Facebook lives. In return, it allows users to have certain abilities on its system -- such as posting and sharing things -- but then watches what they actually do and then tells advertisers about it.

Users who are not aware that this happens have their heads buried in the sand in denial. Information of any sort they give to Facebook -- directly or indirectly -- can be exploited by Facebook for their benefit in some manner.

And it's not only Facebook that has this as a business model. Your Internet service provider (ISP) can do the same thing -- selling a list of which sites you connect to interested advertisers.

Any broadband connection you use can detail information to others about what you are doing on the Internet. Yes, I'm looking at you, cable TV.


The fundamentals of network security are being redefined -- don't get left in the dark by a DDoS attack! Join us in Austin from May 14-16 at the fifth annual Big Communications Event. There's still time to register and communications service providers get in free!

And let's not forget about Google, which has been snickering in the background while Facebook has been getting all the heat. The "Don't Be Evil" firm sort of invented the game here.

So, what can be done in a practical manner to stop Facebook from somehow spewing out things you don't want out?

Have you ever checked Facebook privacy settings? It's a menu choice under the triangle icon you use to log out.

One section is called Apps. There are choices there that allow deletion of apps that can use your information -- or the information of your friends -- for their own purposes. One might delete them all if one wanted to. This privacy granularity wasn't available in quite the same way to users in 2014, but it is now.

Attention to these settings could have stopped the Russian-linked academic in 2014. Changing them now might stop someone else who doesn't care about what Facebook policies are, but just wants the data.

In the end, you are always responsible for your own data. Don't blame Facebook for not being your data nanny. Take back control of your own digital life.

Related posts:

— Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Everything You Need to Know About DNS Attacks
It's important to understand DNS, potential attacks against it, and the tools and techniques required to defend DNS infrastructure. This report answers all the questions you were afraid to ask. Domain Name Service (DNS) is a critical part of any organization's digital infrastructure, but it's also one of the least understood. DNS is designed to be invisible to business professionals, IT stakeholders, and many security professionals, but DNS's threat surface is large and widely targeted. Attackers are causing a great deal of damage with an array of attacks such as denial of service, DNS cache poisoning, DNS hijackin, DNS tunneling, and DNS dangling. They are using DNS infrastructure to take control of inbound and outbound communications and preventing users from accessing the applications they are looking for. To stop attacks on DNS, security teams need to shore up the organization's security hygiene around DNS infrastructure, implement controls such as DNSSEC, and monitor DNS traffic
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-33196
PUBLISHED: 2023-05-26
Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.
CVE-2023-33185
PUBLISHED: 2023-05-26
Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS Simple Email Service. The library exports the `SESEventWebhookView class` intended to receive signed requests from AWS to handle email bounces, subscriptions, etc. These requests ar...
CVE-2023-33187
PUBLISHED: 2023-05-26
Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when a password html input is switched to `type="text"` via a javascript "Show Password" button. This differs from the expected behavior which always obfuscates `ty...
CVE-2023-33194
PUBLISHED: 2023-05-26
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was...
CVE-2023-2879
PUBLISHED: 2023-05-26
GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file