Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operational Security //

Big Data

3/23/2018
09:35 AM
Larry Loeb
Larry Loeb
Larry Loeb
50%
50%

In Facebook Debacle, More Than Zuckerberg to Blame

Facebook and CEO Mark Zuckerberg are rightly taking a lot of heat from the fallout over Cambridge Analytica and the firm's use of social media data. However, other businesses, as well as users, need to take some responsibility as well.

Facebook and its privacy practices has been at the top of this week's news cycles as the realization of what went on, starting in 2014 and continuing through the 2016 presidential election, has finally dawned on the general public.

The social media giant, along with CEO Mark Zuckerberg, has been accused of all sorts of malfeasance by the denizens of the Internet, the press and even the US government.

There's a real underlying problem here, though. It's the Facebook users themselves that let all of this happen.

It's not new news that Facebook data has been mined for political purposes before this. The Obama campaign did so quite effectively in 2012.

What sets this apart is that a third-party app was able to figure out the private data of the friends of whoever was using that app. This is something that Facebook claimed in 2011, as part of a consent order with the US Federal Trade Commission that it would not allow for commercial use.

There seems to have been an exception for academic use, which was exploited by a Russian-connected academic turned around and who sold that data to a third party -- the shell company Cambridge Analytica -- in violation of Facebook policies. (See How to Access the Voter Information Dirt Cambridge Analytica Has on You.)

Facebook has a primary business model of providing data on its users to commercial interests, who then buy advertising that is targeted to these users based on this data. It's how Facebook lives. In return, it allows users to have certain abilities on its system -- such as posting and sharing things -- but then watches what they actually do and then tells advertisers about it.

Users who are not aware that this happens have their heads buried in the sand in denial. Information of any sort they give to Facebook -- directly or indirectly -- can be exploited by Facebook for their benefit in some manner.

And it's not only Facebook that has this as a business model. Your Internet service provider (ISP) can do the same thing -- selling a list of which sites you connect to interested advertisers.

Any broadband connection you use can detail information to others about what you are doing on the Internet. Yes, I'm looking at you, cable TV.


The fundamentals of network security are being redefined -- don't get left in the dark by a DDoS attack! Join us in Austin from May 14-16 at the fifth annual Big Communications Event. There's still time to register and communications service providers get in free!

And let's not forget about Google, which has been snickering in the background while Facebook has been getting all the heat. The "Don't Be Evil" firm sort of invented the game here.

So, what can be done in a practical manner to stop Facebook from somehow spewing out things you don't want out?

Have you ever checked Facebook privacy settings? It's a menu choice under the triangle icon you use to log out.

One section is called Apps. There are choices there that allow deletion of apps that can use your information -- or the information of your friends -- for their own purposes. One might delete them all if one wanted to. This privacy granularity wasn't available in quite the same way to users in 2014, but it is now.

Attention to these settings could have stopped the Russian-linked academic in 2014. Changing them now might stop someone else who doesn't care about what Facebook policies are, but just wants the data.

In the end, you are always responsible for your own data. Don't blame Facebook for not being your data nanny. Take back control of your own digital life.

Related posts:

— Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
COVID-19: Latest Security News & Commentary
Dark Reading Staff 10/27/2020
6 Ways Passwords Fail Basic Security Tests
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/28/2020
'Act of War' Clause Could Nix Cyber Insurance Payouts
Robert Lemos, Contributing Writer,  10/29/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How to Measure and Reduce Cybersecurity Risk in Your Organization
In this Tech Digest, we examine the difficult practice of measuring cyber-risk that has long been an elusive target for enterprises. Download it today!
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27885
PUBLISHED: 2020-10-29
Cross-Site Scripting (XSS) vulnerability on WSO2 API Manager 3.1.0. By exploiting a Cross-site scripting vulnerability the attacker can hijack a logged-in user’s session by stealing cookies which means that a malicious hacker can change the logged-in user’s pass...
CVE-2020-25646
PUBLISHED: 2020-10-29
A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality
CVE-2020-26205
PUBLISHED: 2020-10-29
Sal is a multi-tenanted reporting dashboard for Munki with the ability to display information from Facter. In Sal through version 4.1.6 there is an XSS vulnerability on the machine_list view.
CVE-2020-14323
PUBLISHED: 2020-10-29
A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.
CVE-2020-27886
PUBLISHED: 2020-10-29
An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to exploit the username_available function of the includes/functions.php file (which is called by login.php).