Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Tuesday, 18 May 2010

Facebook: the privacy backlash

Facebook has gone rogue. Facebook has had its MySpace moment. Facebook is becoming too big for its own boots. You cannot expect your profile to be private anymore without a degree in Facebook privacy settings. It's time for an open alternative to Facebook as this Wired article proposes.

http://www.wired.com/epicenter/2010/05/facebook-rogue/

The sad truth mentioned in the article is that the reason Facebook has made so many privacy settings open by default is because you can't be online and expect things to be private anymore. Facebook founder Mark Zuckerberg said it himself to a live audience this year. His exact words were:
People have really gotten comfortable not only sharing more information and different kinds, but more openly and with more people. That social norm is just something that has evolved over time.
"We view it as our role in the system to constantly be innovating and be updating what our system is to reflect what the current social norms are."A lot of companies would be trapped by the conventions and their legacies of what they've built, doing a privacy change - doing a privacy change for 350 million users is not the kind of thing that a lot of companies would do. But we viewed that as a really important thing, to always keep a beginner's mind and what would we do if we were starting the company now and we decided that these would be the social norms now and we just went for it."
Although everything is out in the open, the excuse is misguided. These "norms" have formed, arguably, because of sites like Facebook that make it so easy for us to share information, and people don't always assume that this information can be read by anyone. They don't necessarily want these to be the "norm". Facebook has forced the norm upon us.

Monday, 16 February 2009

Facebook vigilantes publish alleged arsonist's image

This is one of the more interesting days when it comes to privacy and Facebook, as it opens whole new areas - that of internet publishing, the law, the right to a fair trial, free speech and people taking the law into their own hands.

Australia has had its worst bushfires for some time - 200 people have been killed, countless homes destroyed. The country's citizens are angry, particularly because some of the fires were deliberately lit. Who on earth could be responsible for such a horrific act?

Well, Victorian Police have arrested and named one man who is alleged to have been involved in the arson, Brendan Sokaluk. Australian publications are not allowed to publish his photo, in conjunction with court suppression orders. If they do, they could be deemed in sub judice contempt. And an 'Australian' publication means anything that is published in Australia, so it therefore extends to foreign-hosted websites.

However, as soon as he was named, vigilantes trawled his MySpace and found his photograph - a photo of a bulky, nondescript man with a small keyring digital camera aimed at a mirror. They copied the image, mirrored the page, sent it around and began setting up groups on Facebook all showing his image and sporting names such as:

"Brendan Sokaluk, the Victoian [sic] Bushfires Arsonist, must burn in hell." (Arguably such a knee-jerk reaction that they couldn't even spell Victorian correctly.)
"TOURTURE [sic] AND KILL Brendan Sokaluk GIPSLAND ARSONIST!!!" (Again, another typo as the fuming vigilante sweats over the keyboard, with caps lock down.)
"make it know [sic] Brendan Sokaluk is the man who was arrested for arson."

Some of these groups are attracting 3,000 or more members, and the descriptions of what they want to do to the alleged arsonist are quite vile. What the 'vigilantes' fail to realise is that by venting their anger in this way they could actually stop Sokaluk from receiving a trial altogether, because it would arguably mean they could not find any objective jurors. In a worst-case scenario, Sokaluk may not even go to trial, if his defence lawyers apply for a trial to be stopped for this reason.

Individuals may also be in contempt of court; as the law does not necessarily apply just to publishing companies.

The other issue the existence of these groups raise is what Facebook should be doing in terms of the content it allows on its site. As it is important to encourage free speech and debate where does one draw the line when it comes to inciting violence? At the moment Facebook is keeping quiet and the groups remain online.

Sunday, 1 February 2009

How your private photos Facebook can be made public

A few months back we discussed Facebook photo album privacy settings and how you can make sure your bosses don't see those Christmas party shots, for instance. And a few days ago we explained what content is viewable when you are logged out, including photos.

But there are still a couple of ways in which your photo albums - and your friends' pics - can be seen by people outside your immediate circle (including ones who refuse to join Facebook) regardless of privacy settings. You would think that if you set your album to be viewed only by 'friends' that no one else could see them.

This isn't necessarily true.

Unique album URL method:
When logged in and viewing your photos, there's a special album URL (web address) displayed at the bottom of the screen. It takes the form (where the Xs represent random numbers/letters):

http://www.facebook.com/album.php?aid=xxxxx&l=xxxxxx&id=YOURFACEBOOKIDNUMBER

This is a unique URL and if people don't know it they won't be able to access your album (there was a loophole last year, now fixed, that allowed people to easily circumvent this by guessing the string of characters the Xs represented). However, anyone who has the URL will be able to view the album even if they aren't on Facebook -- yes, even if you only wanted friends to view the album. So, if you email an album's address to 20 mates and they send it to all their friends, a lot more people than you intended could be viewing the album.

So, before we send that unique URL to our friends, we will consider who else might be told about it and the implications not only for ourselves, but for our friends.

Image URL method:
Go to anyone's album and click on an image thumbnail. Right-click the image and choose to copy the image's URL. You can paste the address (ctrl+V) into the address bar and view it even when logged out. You can also embed the image so it appears on other websites.

Oh, and here's a little 'Easter egg' - delete everything up to any forward slash in the image's URL, and you get this guy wearing a "Little Celtics Fan" bib. Now what's all that about?

Deleting my own content from Facebook

What irritates me about Facebook is there's:

1) no easy way to delete my own content apart from clicking Edit > Delete on every post. When you have literally hundreds and possibly thousands of posts, this is more than a chore. You might be tempted to recruit professional Facebook Deleters to do the job for you.

2) no way to track the reams of content I've posted beyond my own profile. If I make a comment on Dave's profile or on the Muppets message board that I later think is inaccurate, how can I find a list of messages I've written and delete them? And what if someone is an impressionistic 16-year-old who forms some dangerous opinions which, in hindsight, they realise are ignorant and detrimental to future employment prospects? How can they find out where they posted the content so it won't be tied to their profile?

Facebook makes it so hard to do, and there is barely any information on deleting posts. So what can we do? Any suggestions on easy ways to manage where our own content is going and where?

Tuesday, 27 January 2009

Trainee cops trawl web for knife gang evidence

Rookie cops in Scotland have been scouring Facebook and other social networking sites to find pictures of youths wielding violent weapons like knives, in a bid to cut teen violence.

Much of the time the young people, evidently unaware that their acts of bravado are available to all and sundry, are posing in a public place such as a park, which is an illegal offence. If they are at home, the cops pay a visit to the teen and their parents.

Constable Holly McGee, 18, told BBC Newsbeat: "We're looking for anyone who is brandishing offensive weapons or blades. We take the date, the time, detail of what's in the photograph, [then] a copy of the photograph is printed out and thereafter it's all sent to the gangs task force unit."

Operation Access, as the project is called, has led to the questioning of 400 teenagers and has been declared a success.

Source: BBC Newsbeat

Tuesday, 25 November 2008

Facebook notification settings reset: implications

Today I received an email which may or may not have been from Facebook. It simply read:

Unfortunately, the settings that control which email notifications get sent to you were lost. We're sorry for the inconvenience. To reset your email notification settings, go to: http://www.facebook.com/editaccount.php?notifications
Thanks,
The Facebook Team

I'm always on my guard when it comes to things like this, and feared it was a phishing scam where someone was trying to steal my details. After all, how could Facebook lose such important settings? Email notifications allow you to let Facebook send you alerts when something happens, so you don't have to constantly log into the site. But such alerts can be annoying -- you can get alerts for every tag, event or group invitation. So I've pretty much turned all of these off. Surely Facebook couldn't lose these settings?

Well, when I logged in to Facebook I got a similar message:


Logging into the notifications page, sure enough, most of my alerts had been reset so that I had to change THIRTY-TWO...(32) email alerts to "off".

Email alerts don't pose privacy problems as such; just annoying alerts (although if you use Facebook at work, such excessive alerts could be picked up by your IT/HR department so they can detect your activity). But the technical glitch does make you think of more serious scenarios, namely the loss of privacy settings. Does Facebook have these backed up? What if all privacy settings were suddenly reset and your profile was exposed to more people than you'd intended -- even though you, as a responsible and privacy-conscious Facebook user, had painstakingly set up your Facebook privacy profile?

I'm interested in hearing what Facebook has to say about it. In the meantime, I'm doing a screen shot or noting down my current privacy settings and double-checking a few things.

Monday, 24 November 2008

Teacher dismissed after Facebook faux pas

A North Carolina teacher complaining on her Facebook profile of working "in the ghetto of Charlotte" was suspended last week and risks being dismissed. The move has prompted teachers in the area to revise their policies on staff's online behaviour. The teacher did not mean for her flippant remark to be viewed by all and sundry, but it was uncovered after a search of teachers in the area.

Juror dismissed after asking friends to help make a decision!

All right, out of all the stupid things we've heard people do this week, this one takes the cake. A juror involved in a British child abduction and sexual assault case asked her Facebook friends to help make her decision!

Do these people not realise you aren't allowed to discuss these things even verbally, let alone on a public website? Geez!

Apparently, the woman said: "I don't know which way to go, so I'm holding a poll." She had not even turned on Facebook privacy settings.

Lady, check out the Facebook settings, sure, but don't risk contempt of court in the first place!

Saturday, 22 November 2008

Inviting the whole world

A girl's 16th birthday party was ruined when 60 youths gatecrashed the private event after reading about it on Facebook, The Daily Telegraph reports.

The owner of the south London Baba Foundation community centre - which doubles as a restaurant - said he was horrified when the massive gang appeared outside after reading about the party on Facebook.

Daniel Sisilu said he 'blamed himself' for the trouble last Saturday after putting only one bouncer on the door.

He said he only agreed to the party because he was friend's with the teenage girl's mother.

He said: "I blame myself and I totally regret this. But I've been totally had.

"If you put an invite on Facebook then you are inviting the whole world to come along."


Source: The Daily Telegraph

Events on Facebook are a handy way to coordinate parties and get-togethers. But many events are not made closed, meaning the details are technically readable by all and sundry. If you're a member of a network, your event may even be accessible via the network's home page!

Friday, 21 November 2008

Your friends' applications are sucking your data!

Sounds like a long-winded B-grade horror movie title, doesn't it? Your friends' applications are sucking your data! But these third-party applications are very likely siphoning personal info from your profile, if you haven't adjusted privacy settings.

Confused? It's like this: each time your friends add an application, your info could be shared with developers whose applications you haven't even installed! This even extends to things like the type of relationship you're looking for, religious views, even your Wall!

Granted, not all these are on by default. But it shows how much Facebook developers can (and I hate this term but I'm going to use it) drill down to minute detail. Think of what marketers can do with this data!

To find out what info you're sharing, go to the Application Privacy page (under Privacy), and look at What Other Users Can See via the Facebook Platform. You can see a list of things that you can or can't share:


  • Profile Picture
  • Basic Info
  • Personal info (activities, interests, etc.)
  • Current location (i.e. town, city etc)
  • Education history
  • Employment history
  • Profile status
  • Wall
  • Notes
  • Groups I belong to
  • Events I'm invited to
  • My Photos
  • Photos of me
  • Relationship status
  • Online presence
  • What type of relationship I'm looking for
  • Which gender I'm interested in
  • Who I'm in a relationship with
  • Religious views

Tick or untick as appropriate. As you can see, you have no choice but to share your name, network and list of friends.

If you want absolutely nothing shared, then underneath this box, you may see "Do not share any information about me through the Facebook API". But very likely, if you've added any applications, this will be grayed out. Click on "Why can't I see this?" and you'll see this explanation:

You are unable to fully opt out of sharing information through Facebook Platform because you are currently using applications built on Platform. To enable this option, you need to remove any applications you have added, and remove your permissions to all external applications that you may have used.

Basically, this means you'll need to uninstall all the applications in order to turn off all sharing.

Saturday, 8 November 2008

Relationship status: aargh!


On Facebook, there's a place where you can fill in profile information such as your relationship status.

By default, any change in the relationship status is relayed on the News Feed so everyone else is alerted to it. A friend was once surprised they hadn't heard about a change in relationship status because he "didn't see it appear on Facebook". This is because alerts had been turned off!

It's kind of sad that people think they can only find out about big upheavals in people's personal lives through the Facebook feeds. In a sad and recent case, which is not Facebook's fault, a man was sentenced to life after murdering his wife when she changed her status to 'single'. The man has been dubbed the 'Facebook killer', but I'm not keen on how the media portrays it as all Facebook's fault -- clearly, other dynamics were at work; the man was on drugs at the time, he was bitter, he had made threatening phone calls.

But you know, it's best to make sure those status updates aren't relayed to all and sundry (find it under Privacy > News Feed and Wall. Uncheck that box!). And if you don't get along with your ex, delete them from your friends list for goodness sake!

Bono and bikinis - another privacy warning


Cheeky pictures of U2 lead singer Bono and several bikini-clad babes made their way around Facebook after one of the girls made all the photos available to everyone in her network. What was her 'network'? Oh, only one of the biggest cities on the entire planet... New York! That's why we don't recommend being in a Facebook network at all. When you join a network, Facebook changes your settings by default so that people in that network have access to your profile. Dip into the privacy settings to make sure only your friends can see the information you're disclosing on your profile.

Airline staff sacked after Facebook insults

Thirteen staff at Virgin Atlantic were sacked for making disrespectful comments about passengers and derogatory allegations about poor safety standards on public areas of the Facebook social networking site. Less than a week later, British Airways staff were reprimanded for whingeing about "annoying" and "smelly" passengers.

The events highlight how companies are realising how powerful the web is at shaping reputations, as this Economist article, Losing Face, explains.

No doubt PR companies who specialise in mediating and monitoring how brands are represented by bloggers and denizens of social networking sites are jumping at the chance to promote their own 'damage control' services.

Clearly, companies haven't been doing more to let their staff know what is and isn't acceptable in the first place? Every workplace has an internet usage policy, but it seems that people assume it's switched off when they leave the office, or they forget that things they post online can be traced.

After the Virgin Atlantic sackings, the company posted on its official fan page:

"Virgin Atlantic has been made aware of some malicious comments that have been made on a social networking site by a small number of its staff. The airline has started an immediate disciplinary investigation. We do not tolerate any criticism of our passengers or industry-leading safety standards and we are taking this matter very seriously."

Friday, 24 October 2008

Does anyone remember Beacon Ads?

We aren't saying Facebook is bad. We use it. We're all about helping individuals make the most of it while still being aware of the level of personal information they, and their friends, are giving out.

Facebook exploded in mid-2007. It absolutely exploded. The company had to be seen as a commercial entity; one that could make money. Targeted advertising is the key!

In November 2007, there was a massive brouhaha about Facebook privacy –and rightly so. Project Beacon launched, and it broadcast certain user habits (primarily buying items) to other friends via the news feed without asking for permission. This ruined several people's Christmas shopping surprises. The Beacon feature tracked what you were doing on Facebook partner sites while still logged on to Facebook.

Initially, the Beacon feature was touted as being opt-in. That is, you would be asked if you wanted a certain action to be published to the news feed. But when Beacon launched, it was distinctly opt-out. People found their actions being broadcast to practically all and sundry – the equivalent of a camera behind your shoulder, recording your every move!

Around 44 partner sites, including ticket vendor Fandango and Coca-Cola, initially signed up to Beacon. Within days, there was a huge outcry. Without going into all the details, you can read the apology from Facebook founder Mark Zuckerberg. The company backtracked and made Beacon opt-in again, and also gave people the option to turn it off altogether.

However, the young company would not have backtracked were it not from the tens of thousands of people who caused a massive outcry –ironcically by joining a protest group on Facebook.

So, how to make sure your actions aren't being dispensed to everyone? For more of the dirt on Beacon, check out the FAQ and the Wikipedia entry ... make sure you have turned Beacon off by going to Privacy > Applications > Settings within Facebook.

It's not just Facebook... applications know you, too!

This blog, and others, focuses on Facebook settings and how to make them work for you. But there are thousands of third-party Facebook applications out there (games, quizzes, photo sharing, review sites, maps... the list goes on) that make money from you.

They'll do so mainly either via affiliate links or straight ad revenue. What does this mean? Here are some real-life examples.

Affiliate revenue: Say you've installed an application that allows you to list the books you've read. If a visitor clicks on the book title, they'll be taken to an online bookstore where they can buy a copy. If the visitor goes through with the sale, the application developer, who has set up a deal with the bookstore, will get a cut.

Ad revenue: You might see Google ads at the end of a game. Click on an ad and the app maker will get a cut. Many websites, including this one, display similar ads.

Sometimes an application has no ad links and is a brand awareness exercise. The agency will want to convince their clients that the application is helping the brand name get across.

To measure the effectiveness of these campaigns, application developers need to be able to see demographic information about the people who use their tools. They can use analysis tools from companies like Refresh Analytics, who allow developers to get stats about people who add their programs. Refresh Analytics' tool is described thusly:
The tool can be easily integrated into any Facebook app. It tracks users across 13 demographic and six interest categories: geography, gender, age, marital status, music, books, etc. The info is collected in aggregate to protect user privacy and respect Facebook rules. A daily snapshot of 1,000 users is provided, and historical reports can be generated for the past month, six months or two years.

So, although personal information about you is never revealed, if you have included information about where you're from, your age, marital status and interests, all this information can, and does, get pulled out and it's able to be broken down by app makers so they know, say, the average age of the person who plays their games.

That's why I've not listed any interests or even my gender in my profile. I don't need the advertisers to know all this information if I don't have to reveal it.

They're still out there: Facebook Applications

The new-look Facebook does away with having to endure the tedious applications that plagued traditional profile layouts. In the past, you would see, quite literally in some cases, more than a hundred icons and boxes representing various apps that your friend may have added to their profile page. Now, all this crap is hidden behind a tab called Boxes, and under this tab you can choose to display chosen Applications or just access them via the Applications menu.

In 2007, the most popular apps included Scrabulous (the unofficial online version of Scrabble), and the ability to be bitten by a vampire. Flixster, Super Walls and slideshows were also the rage.

Although you may think your Applications are now gone for good, they've just been shoved under a mat and they do pop out from time to time. You will still need to make sure Applications like games don't harangue your friends every minute to try and beat your high score, or post updates to your profile every time you play. To do so:

Click Applications, located at the bar to the bottom of your screen, then Edit, to see a list of all your applications.

Next to the Application settings you want to view, click Edit.

For Geo Challenge, I see these options:


Then there are the e-mail notifications. To adjust these, click Settings at the top of every Facebook page. Click Notifications, and right at the bottom, under Other Applications, you'll be able to select whether or not you want to be alerted on e-mail whenever something happens (whatever something is).