Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

October 18th, 2010, 07:55 GMT · By

Top Apps Breached Facebook's Privacy Policies

SHARE:

Adjust text size:


Facebook apps shared user IDs with advertisers
Enlarge picture
All of the top ten applications on Facebook, and probably thousands others, were caught transmitting unique user IDs (UIDs) to advertising and data gathering companies.

The new Facebook privacy mess was uncovered by the Wall Street Journal and is an expansion of the "referer" header problems the social network had earlier this year.

The referer [misspelling intentional] field in HTTP headers sent by browsers to a website, contains the URL of a page a user came from. A webmaster can use it to tell which visitors came from where.

Earlier this year, following a website upgrade, Facebook started leaking user IDs via referrer headers.

These unique numbers can easily be used to track down a user's Facebook profile, which at the least, contains their name.

The Wall Street Journal found that the ten most popular Facebook applications, were exposing UIDs to advertising partners and other companies in a similar way.

In addition, three of them, including Zynga's FarmVille, which has 59 million users, also transmitted information about people's friends.

San Francisco-based RapLeaf, which builds dossiers on users from publicly available information and sells them for targeted advertising purposes, was one of the companies receiving user IDs from Facebook apps.

RapLeaf shared the user IDs with twelve other firms involved in advertising or data collection, but the company claims that this was completely unintentional.

"When we discovered that Facebook ids were being passed to ad networks by applications that we work with, we immediately researched the cause and implemented a solution to cease the transmissions," Jeremy Lizt, RapLeaf's VP of engineering, wrote on the company's blog.

Meanwhile, Facebook acknowledged that sharing UIDs with advertisers is a violation of its policies and several of the applications reported by the Wall Street Journal were suspended.

"We have experience addressing this sort of issue previously, although the technical challenges here are greater.

We are talking with our key partners and the broader Web community about possible solutions. We will have more details over the course of the next few days
," explained Mike Vernal, on Facebook's developer blog.

Facebook is clearly having a hard time keeping the over 550,000 registered applications in check and making sure their don't break policy.

The social network was recently sued for its own UID misstep from earlier this year and it wouldn't be surprising if similar lawsuits are filed over this new incident too.

TELL US WHAT YOU THINK:

2,250 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Facebook Sued for Exposing People's Names to Advertisers

Security Experts Not Buying into Facebook's OTP Idea

New Opt-Out-Only Facebook Groups Feature Invites Abuse

Facebook Misguided Feature Can Enhance Phishing Attacks

Public Facebook Profiles Can Be Matched to Leaked Stolen Passwords

READER COMMENTS:


Comment #1 by: Spike on 18 Oct 2010, 09:26 UTC reply to this comment

Hence why I don't use Facebook.


Comment #2 by: Mr Mark 1977 on 18 Oct 2010, 09:28 UTC reply to this comment

This is just the start. For all of you that internet companies will never share your ids and information - be very aware that they will.

And afterwards, they'll just say 'sorry'.

And it'll be too late.

Wake up, facebook doesn't care about your privacy. If you join that site, you may as well accept that at some point, they will give away your private info.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM