The Macrosite for News, Analysis and Opinion about the Future of the Internet
Mary Madden

Securing Private Data From Network 'Zombies'

Written by Mary Madden
4/30/2008 8 comments
no ratings
DISCUSS   Digg   Del.icio.us   Reddit   Email This   TWEET THIS

As more of us integrate social networking into our daily lives online, the layered privacy choices we make through our in-network interactions are becoming increasingly complex.

In the process of creating accounts on social networking sites, many users embrace the "fix it and forget it" approach -- either choosing to accept the default privacy settings or making deliberate choices to customize those settings to their own preferences. And while these initial choices might serve us well for some interactions online, the process of managing our privacy preferences on these networks often requires us to have a dynamic, evolving conversation with the applications we use.

Beyond the basic decisions we make about restricting access to our profile through settings, users are faced with a myriad of choices about what we share and who we share it with each time we post new content, add an application, accept a new friend, or join a new group.

As noted in an Associated Press article, "Social Networking Applications Can Pose Security Risks," the implications of these privacy choices are often not fully understood. Of particular interest in the article is the rising popularity of Facebook applications, programs that are designed by third parties to provide added services and games to users.

Every time users agree to start interacting with a new application, they agree to share their names, networks, and lists of friends with the Facebook Platform applications. In addition, those who read the "Platform Application Terms of Use" will see that they also give their consent to share "any information provided by you and visible to you on the Facebook Site, excluding any of your Contact Information."

So, what happens to all of the excess data we routinely entrust to the kind folks who created the "Zombies" application or "What Kind of Dog Would You Be?" Do the Zombies really need to see the photos of my cat to know best how to attack me?

How this information -- which can include things like your birthday, your dating interests, or your photos -- ultimately gets used by these third parties is a bit of a mystery. Clearly, some applications, such as the popular online word game Scrabulous, use basic demographic information to serve up relevant ads while a user engages with the interface.

Yet, as enterprising young researcher Adrienne Felt has shown along with her colleagues at the University of Virginia, developers are often granted access to much more data than they actually need to ensure that the application functions properly.

As Dan Solove points out in a recent post to his Concurring Opinions blog, even the most conservative users who refuse to add any applications to their profiles still end up sharing many of those same details with third parties via their friends. (The default settings on Facebook permit the sharing of profile information with applications your friends choose to add.)

CNET writer Chris Soghoian emphasizes the challenge this presents to users: "To restate -- if you set your profile to private, and one of your friends adds an application, most of your profile information that is visible to your friend is also available to the application developer -- even if you yourself have not installed the application."

Fortunately, the user can easily change these default settings with a few clicks. But those who are sensitive about the information they share may be surprised to find that their friends have inadvertently disclosed their personal details to third parties -- especially if it turns out that they're also Zombies.

— Mary Madden, Senior Research Specialist, Pew Internet & American Life Project

DISCUSS   Digg   Del.icio.us   Reddit   Email This
Current display:       newest comments first       display in chronological order
teddyb109
Rank: Cave Painter
Sunday May 11, 2008 6:23:17 AM
no ratings
I wonder how many of us actually take sufficient care of our privacy online--and how much we unwittingly give up when we accept a site's terms of service. Probably too much--imagine if we could create our own terms of service? A collective, accessible user-driven terms of service that a website could accept, that addressed varying levels of privacy?
Mary Madden
Thinkernetter
Thursday May 1, 2008 4:56:22 PM
no ratings

Thanks so much to everyone who has contributed thoughtful feedback to this post.

Regarding resources for parents who are hoping to talk with their kids about privacy choices online, there are fortunately many great websites out there. One good place to start is GetNetWise.

Those who are interested in finding out more about adults' attitudes toward privacy online and their information sharing practices might be interested in a report from the Pew Internet Project called "Digital Footprints."

Some of the more surprising findings from the report: 60% of adult internet users say they are not worried about how much information is available about them online, and just 47% have searched for their own name online.

RPR
IQ Crew
Thursday May 1, 2008 4:20:29 PM
no ratings

When wanting to secure private data from network zombies: Can sharing make you more secure? Can karma save you from crimeware? Can a community protect your company? These kaspersky.com questions you may have seen in an advertisement, for example on this page. Perhaps it is a reasonable and worthy thing to expect to see continual work on developing sound principles, on promoting adherence to such principles, on elevating a common mindset for ethics, legal activity, and other forms of goodness. Perhaps positive energy will lead to continued improvements to behavior-based mechanisms and overall collective intelligence.

Mashka
Researcher
Thursday May 1, 2008 4:09:42 PM
no ratings
Hi, Mary!
At least, you CAN control your privacy at Facebook!There is one social network in Russia, that could be translated as classmates.ru, so you can't even set your privacy level-anybody could look at your profile, your pictures(more over, to evaluate them), and there is a special application for monitoring anybody who watches your  profile.
So, when I found out that my school teacher who hated me,looked at my photos, I just deleted my profile and never came back again.
But what I have heard, that bank security uses that network for searching people who don't pay their loans.  I don't know how exactly they use it, but the conclusion is obvious. Be VERY!!! careful and think twice before filling out the registration form.
Paul Whyte
Researcher
Thursday May 1, 2008 1:36:59 PM
no ratings

Hi Mary,

 Securing private data in the internet age now seems an exerxise in futility. It's something we've to live with that as long as we are online, there is no way you can be assured that your privacy is well and truly secured.

Back to the issue of facebook these applications violating the principle  of least privelege? 

Do they actually need the user data they are requesting?  

The problem with the Facebook Platform

 

RPR
IQ Crew
Thursday May 1, 2008 11:34:07 AM
no ratings

The technological way of life will increase and likely often raise ethical implications, for example relative to worms, zombies, botnets and so on. Perhaps collective optimism from pros and public (before, by and beyond 2020) will somehow help to achieve giant leaps and miracles. Perhaps the world’s foundation for ethics and goodness needs to be elevated and more common. If zombies are an issue, the root cause fix may be a change in the mindset of the zombies' creators.

Tim Bell
IQ Crew
Wednesday April 30, 2008 10:15:03 PM
no ratings
I'm surprised that someone hasn't created a parenting guide on how to approach their kids on things to avoid while on the net, plus an introduction on ones internet footprint.
Murugan
IQ Crew
Wednesday April 30, 2008 4:31:49 PM
no ratings

Thank you for sharing with us the interesting information regarding the prowling Zombies at social network sites such as Facebook.

Is keeping one’s information private even possible at such sites? 

It seems as if one needs to realize that one way or another, a zombie is going to invade your profile somehow and obtain the information it was seeking.

The only level of privacy I see at such sites is the ability to prevent another user from viewing portions of your profile. 

However, the zombies spawned by a particular third party service obviously have the back stage pass to all the profiles.

The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
previous posts from Mary Madden
Mary Madden
Mary Madden   3/3/2008   8 comments
As the title of a recent New York Times article (“Sorry, Boys, This Is Our Domain”) suggests, teen girls have already laid their claim to the farthest-reaching corners of the creative Web. The one glaring exception to that trend is the way boys have embraced online video; when compared with teen girls, boys are twice as likely to have posted videos online.  
IETV: the thinkerNet on film
5
of
2pm EST
Tue
Dec 1st
an IBM information resource
sponsored content
big blue blog
Todd Watson
Todd Watson   11/20/2009   Post a comment
While Google introduces its new Chrome OS (which I'm hearing will be widely available in one year?  Did I mishear that?), IBM announced 10 new products today to help companies using IBM System z mainframe technology.
white papers & case studies
an IBM information resource
sponsored content
Smarter Collaboration: How to Thrive in a Challenging Business Environment
Market conditions are changing faster than ever, and organizations need to improve their agility and adaptability in order to provide better service and improve processes. The ability to work with customers, business partners, and employees as effectively as possible - while at the same time holding down costs - is a key to success.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Copyright © 2009 United Business Media Limited - All rights reserved.      About Us  |  Privacy Policy and Terms of Use  |  Contact Us
CMP Media LLC
Internet Evolution – not for thickies
what.the.ferraro
Facebook Lacks Social Skills

11|20|09   |   1:53   |   No comments


Facebook's 'Suggestions' for users demonstrate how little social networking sites understand about true social relationships.
Singer at C-Level
Smart Grid Opportunities

11|20|09   |   2:49   |   No comments


Industry initiatives and government stimulus funds are giving enterprise software vendors a great opportunity to help build out and manage smart grid technologies.
Tom Nolle
Total Telephony Transcends Telepresence

11|20|09   |   2:11   |   2 comments


The problem with telepresence is that it's not universally accepted, because video calling isn't. While we can all do video calling, we also apparently worry too much about how we look. If we want HD telepresence in our future, we have to dress down, mess up our hair, and dive into our online life.
what.the.ferraro
ThinkerNet Wins Min's Award for Best Blogs!

11|19|09   |   1:13   |   4 comments


ThinkerNet wins the Min's award for 'Best Blogs' – Internet Evolution's fifth award this year!
Full Nelson
SanFran.gov

11|19|09   |   8:51   |   No comments


Fritz has an exclusive talk with the mayor and CTO of San Francisco about that city's latest e-government efforts.
Robert D. Atkinson
America Has Much to Learn About Digital Piracy

11|18|09   |   2:09   |   No comments


The US loses about $20 billion a year on pirated software, movies, and music. But public policy can help stem the tide of digital theft. For example, France has recently passed a 'three strikes and you’re out' law, whereby if after two warning letters an individual continues to download pirated software then his Internet access will be cut off. US policy makers should consider adopting similar policies.
Singer at C-Level
Connecting Stakeholders: Part 3

Part 3 of 3   |  
See complete series
11|18|09   |   2:09   |   No comments


Financial management planning does not need to include Voodoo economics, but it does help to tap into the knowledge base of your team through some sort of real-time system. We explore your options.
Reiter's Block
Tweeting for Customer Support

11|18|09   |   2:20   |   No comments


When Reiter gets incensed over incompetent Verizon FiOS order-taking and support, he broadcasts it via Twitter. Did it do any good? How should your company offer Twitter support? Watch this for all the answers.
what.the.ferraro
Dogster.com More Popular Than Gov 2.0

11|17|09   |   2:05   |   1 comment


A lot of attention is being paid to launching Gov 2.0 Websites, but these sites aren't attracting a lot of visitors.
Reiter's Block
Is the BlackBerry 9700 'Bold' Enough?

11|17|09   |   3:07   |   4 comments


The successor to the BlackBerry Bold 9000 – the Bold 9700 – will be available soon in the US. Is it worth upgrading? Reiter's got one, and offers advice.
TechWeb The Global Leader In Technology Media