On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

August 16th, 2007

Has Facebook abandoned privacy?

Posted by Steve O'Hear @ 5:38 am

Categories: Facebook, Social Networks

Tags: RSS Feed, Facebook, RSS, Privacy, Steve O'Hear

fb.pngYesterday I blogged about Facebook RSS feeds, where I made an assumption that the only feeds available were ones that displayed information which individual users of the social networking side had designated as public. Boy was I wrong. Fellow ZDNet blogger, Denise Howell, having taken the time to fully explore Facebook RSS feeds in relation to a user’s privacy settings, alerted me to the fact that many of the available feeds are publicly accessible regardless.

Status updates. These can be designated as only viewable by friends who are logged into Facebook. However, a second tick box (which is on by default) gives you the option to allows friends to subscribe to your updates too. If ticked, the result is a publicly accessible RSS feed of your Facebook status updates, which is viewable by anyone, not just your “friends” in the Facebook sense. This is clearly a breach of privacy waiting to happen purely through poor UI design. The word “friends” is used in two conflicting contexts.

fb_status.png

Additionally, a second RSS feed is generated which aggregates all of your friends’ updates (as long as they also have the box ticked), which is, again, publicly accessible. In both examples, information is being made public which users think they’ve only made available to authorized Facebook friends.

Notes. Despite making my notes accessible by my Facebook friends only, and ticking the box “Anyone who can see my notes can subscribe to my notes”, which is on by default, a public RSS feed exists.

fb_privacy.png

Posted items. There doesn’t appear to be any privacy options for these, and once again, a public RSS feed exists.

As Denise writes:

So where’s the data leak? Here’s where. These feeds are public. All one needs in order to view and use them is the feed’s URI. There’s no requirement that a reader or user of the feed be the “friend” of individuals whose data is in the feed, or even that the person be logged into Facebook.

Whilst there is nothing wrong with giving users the option to generate publicly accessible feeds for any of these items, it needs to be better designed in such a way that privacy is still an option.

Steve O'Hear is a London-based consultant, educator, and journalist, focussing on the Internet and all aspects of digital technology. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 4 Talkback(s)
RE: Has Facebook abandoned privacy?
I agree with you.

I actually found this (I know it's dated almost a year and a half ago) [which makes this worse because they are still yet to change this, as far as I know] by searching for th... (Read the rest)
Posted by: dxpsteve@... Posted on: 02/25/09 You are currently: a Guest | | Terms of Use
URLs are not publicly accessible  cmkelly | 08/16/07
Encoded URL  paul.juska@... | 08/16/07
RE: Has Facebook abandoned privacy?  BigHeadShark | 12/16/07
RE: Has Facebook abandoned privacy?  dxpsteve@... | 02/25/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads