When It Comes To Facebook Apps, Be Like Mike — Not Bill

This is Mike.

Mike works in the security industry and is concerned about his privacy.

Mike wonders why people sign up for Facebook apps so quickly.

Mike doesn’t sign up for Facebook apps without a quick read of the terms of agreement.

Mike is smart.

Be like Mike.

A few months ago, people on Facebook were up in arms over a perceived breach of their privacy (which turned out to be a hoax), so they were posting the following status:

“As of September 29, 2015 at 10:50 p.m. Eastern standard time, I do not give Facebook or any entities associated with Facebook permission to use my pictures, information, or posts, both past and future.” And so it went on for another 100 words or so. Aside from the fact that this was in response to a hoax, there was quite a lot of noise made about this supposed violation of their privacy. But my question is, how quickly do they give up their privacy when presented with a new app or new technology?

Fast forward to last week, and many people were creating posts with an app that does a cute summary of their actions or personality, accompanied by a stick figure. Now this app, Be Like Bill, has a pretty good privacy policy and terms. They clearly state, in a brief and readable format, that the information collected is only used to generate the post, will not be stored on the server, and will not be provided to other companies. The only clause that elicits any concern allows them “to use, edit your content with our service permanently, no limit and no recover.” I understand that this makes it a lot simpler to run the site without having to respond to concerns or requests to delete a post, but it does significantly reduce your options.

Many of these fun quizzes or posts go through everything that you have done on Facebook. That should raise a red flag about the potential privacy issues, but millions of people install them and trade their privacy for a brief moment of fun. Unfortunately, there’s a very fine line between an app that’s fun and one that can be damaging. Most fall in the fun category and ask for a limited set of information. However, at least one recent app asked for a bit more.

If you install that app and give permission, the developers can harvest your:

  • Name, profile picture, age, sex, birthday, and other public info
  • Entire friend list
  • Everything you have ever posted on your timeline
  • All of your photos and photos you are tagged in
  • Education history
  • Hometown and current city
  • Everything you have ever liked
  • Your IP address
  • Info about the device you are using, including browser and language

I am not saying that this particular app is malicious, but no quiz or app should need access to this level of detail. They may or may not promise in the user agreement not to store it, use it, or sell it, but either way you have lost control of your data and associated privacy. It is much better for apps not to ask for it in the first place.

Harmless Or Harmful?

As a consumer, how do you tell the difference between fun and potentially damaging? Look closely at what the app is asking for, and think about the potential risk of that data. Consumers are the big target of these apps, and where security and privacy are concerned, people are always the weakest link. This same info could be used to guess passwords, security questions, or even impersonate someone for a bit of live social engineering, all of which have serious business implications.

Now, people have not been reading terms of agreement for decades, and they are not likely to start anytime soon. What I would like to figure out is why didn’t the Facebook privacy hoax rampage provoke concern over other apps? Or more important, what do we need to do differently so that data requests by every app, device, and Web page are treated with appropriate levels of privacy concern? Because at this rate, it is only a matter of time before we might as well just publish everything and save our adversaries the trouble

View the original post on Dark Reading.

Leave a Comment

sixteen + five =