{"id":3913,"date":"2010-10-24T20:19:50","date_gmt":"2010-10-25T00:19:50","guid":{"rendered":"http:\/\/rbach.net\/blog\/index.php\/"},"modified":"2022-12-30T15:43:26","modified_gmt":"2022-12-30T20:43:26","slug":"facebook-privacy-fail-again","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/facebook-privacy-fail-again\/","title":{"rendered":"Facebook Privacy Fail Again"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-101923 size-medium\" title=\"Facebook Privacy Fail Again\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft1-6.jpg?resize=150%2C112&#038;ssl=1\" alt=\"Facebook Privacy Fail Again\" width=\"150\" height=\"112\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft1-6.jpg?resize=150%2C112&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft1-6.jpg?resize=75%2C56&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft1-6.jpg?w=224&amp;ssl=1 224w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/>\u00a0<strong>-Updated 11-01-10- <\/strong><a href=\"https:\/\/www.facebook.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a> has completed its internal investigation into <a href=\"https:\/\/web.archive.org\/web\/20131012200610\/http:\/\/online.wsj.com\/article\/SB10001424052702304772804575558484075236968.html\" target=\"_blank\" rel=\"noopener noreferrer\">reports<\/a> from <a href=\"https:\/\/www.wsj.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>The Wall Street Journal<\/em><\/a> that Facebook applications were violating its user privacy. The WSJ says FB is sharing unique user IDs with advertising agencies and data collection companies. According to the firm&#8217;s <a href=\"https:\/\/developers.facebook.com\/blog\/post\/422\" target=\"_blank\" rel=\"noopener noreferrer\">blog<\/a>, some developers were sharing Facebook UIDs with data brokers for a fee, &#8220;this violation of our policy is something we take seriously,&#8221; Facebook engineer Mike Vernal wrote in the corporate response.<\/p>\n<p>The Social Networker is reportedly taking action against developers who violated the Facebook policies by &#8220;instituting a 6-month full moratorium on their access to Facebook communication channels, and we will require these developers to submit their data practices to an audit in the future to confirm that they are in compliance with our policies&#8221; according to the corporate blog.<\/p>\n<p style=\"text-align: left;\">The blog also states that Facebook has struck a deal with <a title=\"Rapleaf\" href=\"https:\/\/www.crunchbase.com\/company\/rapleaf\" target=\"_blank\" rel=\"crunchbase noopener noreferrer\">Rapleaf<\/a> (<em>Which I wrote about <a title=\"rbach.net\" href=\"http:\/\/rbachnet.wwwmi3-ss40.a2hosted.com\/index.php\/banks-and-bosses-using-social-media-to-assess-risk\/\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a><\/em>), the data-mining firm that has tied Facebook ID information collected by Facebook applications to a database of Internet users it sold. &#8220;<em>Rapleaf has agreed to delete all UIDs in its possession, and they have agreed not to conduct any activities on the Facebook Platform (either directly or indirectly) going forward<\/em>.&#8221;<\/p>\n<p style=\"text-align: center;\"><strong>&#8212;<\/strong><\/p>\n<p>Last May <a href=\"https:\/\/www.facebook.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a> was <a href=\"https:\/\/web.archive.org\/web\/20130914202901\/http:\/\/online.wsj.com\/article\/SB10001424052748704513104575256701215465596.html\" target=\"_blank\" rel=\"noopener noreferrer\">caught<\/a> using &#8220;referrers&#8221; to send users&#8217; ID information to advertising agencies every time the users click on ads. In response, the social networker changed some of the code that allowed this and issued a half-hearted apology. Now, the <a href=\"https:\/\/www.wsj.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Wall Street Journal<\/em><\/a> has <a title=\"WSJ\" href=\"https:\/\/web.archive.org\/web\/20131012200610\/http:\/\/online.wsj.com\/article\/SB10001424052702304772804575558484075236968.html\" target=\"_blank\" rel=\"noopener noreferrer\">found<\/a> that third-party applications or &#8220;apps&#8221; on Facebook have been guilty of the same thing.\u00a0 The <em>WSJ<\/em> says the privacy breach affects tens of millions of Facebook app users, including people who set their profiles to Facebook&#8217;s strictest privacy settings.<\/p>\n<p><a href=\"https:\/\/www.facebook.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101926 size-medium\" title=\"Facebook logo\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/facebook_logo-2-e1566779725602-150x44.gif?resize=150%2C44&#038;ssl=1\" alt=\"Facebook logo\" width=\"150\" height=\"44\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/facebook_logo-2-e1566779725602.gif?resize=150%2C44&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/facebook_logo-2-e1566779725602.gif?resize=75%2C22&amp;ssl=1 75w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a>&#8220;Apps&#8221; are pieces of software that let Facebook&#8217;s 500 million users play games or share common interests with one another. The company says 70% of users use apps each month. The <em>WSJ<\/em> found that all the 10 most popular apps on Facebook were transmitting users&#8217; IDs to outside companies including:<\/p>\n<ul>\n<li><a title=\"FarmVille\" href=\"https:\/\/www.technobuffalo.com\/zyngas-games-losing-users-fast-on-pace-to-lose-150-million-in-2015\" target=\"_blank\" rel=\"crunchbase noopener noreferrer\">FarmVille<\/a>,<\/li>\n<li>Phrases,<\/li>\n<li>Texas HoldEm,<\/li>\n<li><a title=\"FrontierVille\" href=\"https:\/\/web.archive.org\/web\/20160411003636\/https:\/\/apps.facebook.com\/frontierville\/\" target=\"_blank\" rel=\"homepage noopener noreferrer\">FrontierVille<\/a>,<\/li>\n<li>Causes,<\/li>\n<li>Cafe World,<\/li>\n<li>Mafia Wars,<\/li>\n<li>QUiz Planet,<\/li>\n<li>Treasure Isle<\/li>\n<li>IHeart.<\/li>\n<\/ul>\n<p>The <em>WSJ<\/em> says that <a href=\"https:\/\/zyngagames.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Zynga Game Network Inc.&#8217;s<\/a>\u00a0(<a href=\"https:\/\/www.hollywoodreporter.com\/business\/business-news\/take-two-zynga-acquisition-1235152410\/\" target=\"_blank\" rel=\"noopener noreferrer\">ZNGA<\/a>) FarmVille, with 59 million users has also been transmitting personal information about a user&#8217;s friends to outside companies.<\/p>\n<p>The information being transmitted includes the unique &#8220;Facebook ID&#8221; number assigned to every user on the site. Since a Facebook user ID is a public part of any Facebook profile, anyone can use an ID number to look up a person&#8217;s name even if that person has set all of his or her Facebook information to be private. For other users, the Facebook ID reveals information they have set to share with &#8220;everyone,&#8221; including age, residence, occupation, and photos. The apps reviewed by the <em>WSJ<\/em> were sending Facebook ID numbers to at least 25 advertising and data firms, several of which build profiles of Internet users by tracking their online activities.<\/p>\n<p>The <em>Journal<\/em> found that data-gathering firm, <a title=\"Rapleaf\" href=\"https:\/\/www.towerdata.com\/news-events\/towerdata-acquires-rapleaf-press-release\" target=\"_blank\" rel=\"homepage noopener noreferrer\">RapLeaf<\/a> Inc., (<em>Which I wrote about <a title=\"rbach.net\" href=\"..\/index.php\/banks-and-bosses-using-social-media-to-assess-risk\/\" target=\"_blank\" rel=\"noopener noreferrer\">earlier<\/a><\/em>) had linked Facebook user ID information obtained from apps to its own database of Internet users, which it sells. RapLeaf also transmitted the Facebook IDs it obtained to a dozen other firms including Google&#8217;s Invite Media, the Journal found.\u00a0 &#8220;We didn&#8217;t do it on purpose,&#8221; said Joel Jewitt, vice president of business development for RapLeaf to the <em>WSJ<\/em>.<\/p>\n<p>Facebook has again issued a <a title=\"Facebook\" href=\"https:\/\/web.archive.org\/web\/20190124130528\/https:\/\/developers.facebook.com\/blog\/post\/418\/?_fb_noscript=1\" target=\"_blank\" rel=\"noopener noreferrer\">statement<\/a> that it will look into the matter and correct the code and has in the meantime disabled thousands of applications. According to the <em>WSJ<\/em>, the applications transmitting Facebook IDs may have breached their own privacy policies. <a href=\"https:\/\/arstechnica.com\/business\/2013\/09\/how-zynga-went-from-social-gaming-powerhouse-to-has-been\/\" target=\"_blank\" rel=\"noopener noreferrer\">Zynga<\/a>, for example, says in its privacy policy that it &#8220;<em>does not provide any <a title=\"Personally identifiable information\" href=\"http:\/\/en.wikipedia.org\/wiki\/Personally_identifiable_information\" target=\"_blank\" rel=\"wikipedia noopener noreferrer\">Personally Identifiable Information<\/a> to third-party advertising companies<\/em>.&#8221; A <a href=\"https:\/\/medium.com\/halting-problem\/zyngas-offices-now-worth-more-than-zynga-the-company-47a704d48249\" target=\"_blank\" rel=\"noopener noreferrer\">Zynga<\/a> spokeswoman told the <em>WSJ<\/em>, &#8220;<em>Zynga has a strict policy of not passing personally identifiable information to any third parties. We look forward to working with Facebook to refine how web technologies work to keep people in control of their information.<\/em>&#8221;<\/p>\n<p><strong><em>rb-<\/em><\/strong><\/p>\n<p><em><a href=\"https:\/\/secure.wikimedia.org\/wikipedia\/en\/wiki\/Mark_Zuckerberg\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101928 size-medium\" title=\"Mark Zuckerberg\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Mark-Zuckerberg-e1566779781279-150x127.jpg?resize=150%2C127&#038;ssl=1\" alt=\"Mark Zuckerberg\" width=\"150\" height=\"127\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Mark-Zuckerberg-e1566779781279.jpg?resize=150%2C127&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Mark-Zuckerberg-e1566779781279.jpg?resize=75%2C64&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Mark-Zuckerberg-e1566779781279.jpg?w=432&amp;ssl=1 432w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a>Once again, Facebook has a user privacy breach on its hands. The social networker keeps promising to protect its customers&#8217; personally identifiable information but never seems to get it right. <\/em><\/p>\n<p><em>Perhaps the question Facebook users should be asking is does Facebook really want to protect their user&#8217;s privacy?<\/em><\/p>\n<p style=\"text-align: center;\"><em>\u00a0<\/em><\/p>\n<h6>Related articles<\/h6>\n<ul>\n<li><a href=\"http:\/\/go.theregister.com\/feed\/www.theregister.co.uk\/2011\/08\/04\/germany_no_to_facebook_facial_recognition\/\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook facial recognition tech &#8216;violates&#8217; German privacy law<\/a> (go.theregister.com)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>WSJ found that third-party apps have caused privacy breaches for millions of FB users even with the strictest security settings<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,295],"tags":[3240,104,503,1096,504,505,185,260,4,564,2904,424],"class_list":["post-3913","post","type-post","status-publish","format-standard","hentry","category-security","category-social-networking","tag-3240","tag-facebook","tag-farmville","tag-fb","tag-frontierville","tag-personally-identifiable-information","tag-privacy","tag-rapleaf","tag-security","tag-social-media","tag-znga","tag-zynga"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/3913","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=3913"}],"version-history":[{"count":17,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/3913\/revisions"}],"predecessor-version":[{"id":132770,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/3913\/revisions\/132770"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=3913"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=3913"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=3913"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}