Facebook, privacy and IT data

Facebook is getting a lot of flak in the press (latest in the Register) about reports on a gossip blog about some pretty serious privacy holes:

1. anyone that works there can look at anyone’s private profile

2. anyone who works there can look at logs of what other profiles any user has seen.

If Facebook wants to turn their act around, or any other social networking site wants to avoid being in their position, they’d better pay attention to some best practices around securing and reviewing IT data.

Here’s what best practice would say about Facebook’s two problems.

The first problem - anyone can look at any customer’s data - is classically the kind of thing that has brought on regulations in other industries, such as PCI-DSS, which was introduced by VISA to ensure that merchants processing credit cards keep consumer financial info private. Like credit cards, a lot of the information people post to their private profiles is a goldmine for identity thieves - Information Week made this argument about Faceboook even before the latest flap. If I know your birthdate and mother’s name I’m a lot further along in social engineering an unwitting customer support rep into believing I’m you. And yes, identity thieves do have insiders - ask Ford Motor Credit.

A major measure that organizations who are following best practices for privacy are supposed to take is to lock down this private information to only insiders with a need-to-know - obviously Facebook’s not doing that. But once they do put the right access controls in place, they’re going to need to put in a review procedure to watch privileged employees. Facebook’ security or privacy staff should be reviewing logs of who has accessed private info and ensuring that there was a valid business reason for each access. The review should include:

  • logs generated by Facebook’s application itself to see employees with admin access coming in the front door
  • audit tables for the back end databases to be sure that the database admins who manage the database back-end aren’t bypassing the application’s permissions and doing manual queries to see what they shouldn’t
  • filesystem audit logs, to be sure that server or storage admins aren’t bypassing both the database and the app to look at the data on the filesystem itself

The second problem - that any employee can look at logs of what users have done - is a bit less well understood privacy issue. It’s probably particularly bad on a social networking site - do you really want your ex knowing you’re watching their profile? But you may not want every Amazon employee being able to see what items you’re browsing, so it’s an issue that affects almost any site to some degree.

To address the second issue, logs themselves need to be securely captured into a system that provides appropriate access controls to the logs themselves as well as an audit trail of who’s looked at the logs - which the security team should be reviewing proactively. Unfortunately, access logs are hardly ever considered to have privacy implications inside large sites. As evidenced by last year’s infamous publication of AOL search records.

Keeping these logs around that show who looked at what is going to be important too - law enforcement could subpoena Facebook for logs if unauthorized access by their employees is suspected to be a part of a criminal act. Facebook won’t want to be in a position where they can’t produce the logs.

The biggest reason Facebook should take this seriously? An overzealous plaintiff’s attorney somewhere is probably salivating over all the cash they raked in from Microsoft and figuring out how to sue Facebook for cash damages if a Facebook privacy breach leads to financial losses or serious personal harm, using the argument that by not following the same standard as other sites they’ve not met their “duty of care.” Think they can’t do it? TJ Maxx is getting sued right now on similar grounds.

6 Responses to “Facebook, privacy and IT data”

  1. Why Facebook employees are profiling users [Your Privacy Is An Illusion]  »TechAddress Says:

    [...] The second part, that access to sensitive data is “restricted” is meaninglessly vague. Restricted how? And to whom? Customer service employees, for example, obviously must have access to profiles and activity on the site in order to investigate complaints. What’s to stop them from idly viewing other profiles while they’re passing the time? And programmers and system administrators need to have deep access to the company’s software. Even if access is restricted, has Facebook restricted it to people who deserve that trust? Has Facebook, say, conducted background checks on those employees? Does it log their every access to the system, and examine those logs? These are not idle questions: Retailer TJ Maxx is getting sued for taking a lax attitude to data security. [...]

  2. Max Levchin has more money, less sleep than you [Jackpot]  »TechAddress Says:

    [...] The second part, that access to sensitive data is “restricted” is meaninglessly vague. Restricted how? And to whom? Customer service employees, for example, obviously must have access to profiles and activity on the site in order to investigate complaints. What’s to stop them from idly viewing other profiles while they’re passing the time? And programmers and system administrators need to have deep access to the company’s software. Even if access is restricted, has Facebook restricted it to people who deserve that trust? Has Facebook, say, conducted background checks on those employees? Does it log their every access to the system, and examine those logs? These are not idle questions: Retailer TJ Maxx is getting sued for taking a lax attitude to data security. [...]

  3. Gary Williams Says:

    Many people would not give out random personal data yet they are happy to post it all up of the web for anyone to see. Social networking sites have a responsibility to handle sensitive data carefully yet Facebook make a mockery of data protection and teach people to be careless.

  4. Janessa Says:

    All this ranting is absolutely silly. If i own a store because i made it any paperwork that is submitted by a client CAN be read by my employees that work on that paperwork. If these people OWN a website then any employee that works there must OF COURSE be able to look at all the info that goes through this site. Don’t join facebook if you don’t want a few selected people to look at you’re page. Simple as that. Don’t ruin for the masterminds behind the page because you and i both know you’re addicted to facebook so shut up deal with it and drop it so you don’t screw it up for everyone else that is addicted..

    Thanks.

  5. alex Says:

    social network sites and privacy dont go together! I guess its not really facebooks fault, its more likely the user being stupid enough to write this much info about themselves in the first place!!

  6. jack parler Says:

    Thanks for this. Just subscribed.

Leave a Reply