![]() |
Facebook admits its third-party developers have mishandled private data
http://www.betanews.com/article/Face...ata/1287428665
In what could be potentially damaging to a company already being criticized over its privacy issues, Facebook admitted late Sunday that it had knowledge of developers passing information called user IDs within applications. The user ID is a unique set of numbers that identify users on the site. Facebook engineer Mike Vernal said in a blog post that in most cases the company believed developers were doing this unintentionally, but regardless it was a violation of the social networking site's privacy policy. Vernal did however say the press was overblowing the situation. "Knowledge of a UID does not enable anyone to access private user information without explicit user consent," he claimed. "Nevertheless, we are committed to ensuring that even the inadvertent passing of UIDs is prevented and all applications are in compliance with our policy." The Wall Street Journal said that the issue may affect "tens of millions" of application users, even those who have their privacy settings as strict as is currently possible. Zynga's popular apps Farmville, Frontierville, and Texas Hold 'Em all have the issue, it found, among others. In fact, all ten of the most popular applications on Facebook had the issue, so it may be likely that significant percentage of all apps were sharing the so-called user ID -- meaning that Facebook itself could share some culpability in not educating its developers on how to keep their apps sufficiently secure. Making matters worse, it seems clear that the site doesn't quite know how to fix the issue just yet, causing consternation among its users. "The technical challenges here are greater," Vernal said. "We are talking with our key partners and the broader Web community about possible solutions." That wasn't enough for some of the commenters to his blog post. "Everything on FB is trust first; act later, including new settings when rolling out platform enhancements," one wrote. "In other words, there's no enforcement of their policies, no consequences for violating them, just an excuse on their part. Gee thanks," another wrote on Facebook's claims that the breach was for the most part inadvertent. |
How damaging has this stuff really been to Facebook anyways? Doesn't seem like they slow much if at all in growth regardless what "bad news" there is about them.
|
a) who gives a shit?
b) who gives a shit? Not sure what is so precious about Facebook user IDs and anyway the site is full of people who haven't got a clue about privacy so it doesn't matter. |
user 14319846: farm not profitable, played texas hold em, bet farm
user 198764: crops died and so on |
I had a look into the apps side of FB a couple of months ago. Looks like it's pretty easy to get information not just about one person (after they grant explicit access permission to the app), but also basic information about their friends (without any permission)
The ToS says you're not supposed to retain any profile data for more than 24 hours, but how would FB ever know about this? |
Quote:
|
All times are GMT -7. The time now is 05:59 AM. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123