F ACEBOOK VS . P RIVACY A DVOCATES : A R OAD M AP F OR P EACE Joseph - - PowerPoint PPT Presentation

f acebook vs p rivacy a dvocates
SMART_READER_LITE
LIVE PREVIEW

F ACEBOOK VS . P RIVACY A DVOCATES : A R OAD M AP F OR P EACE Joseph - - PowerPoint PPT Presentation

F ACEBOOK VS . P RIVACY A DVOCATES : A R OAD M AP F OR P EACE Joseph Bonneau jcb82@cl.cam.ac.uk Computer Laboratory Facebook Palo Alto, CA, USA July 14, 2009 Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 1 / 27 The


slide-1
SLIDE 1

FACEBOOK VS. PRIVACY ADVOCATES: A ROAD MAP FOR PEACE

Joseph Bonneau jcb82@cl.cam.ac.uk

Computer Laboratory

Facebook Palo Alto, CA, USA July 14, 2009

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 1 / 27

slide-2
SLIDE 2

The Landscape

SNS Industry

Operators Developers Advertisers Tech Futurists

Privacy Advocates

Non-Profit Groups Advocates Academics

Media Government Social Reactionaries Users?

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 2 / 27

slide-3
SLIDE 3

The Landscape

SNS Industry

Operators Developers Advertisers Tech Futurists

Privacy Advocates

Non-Profit Groups Advocates Academics

Media Government Social Reactionaries Users?

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 2 / 27

slide-4
SLIDE 4

The Landscape

SNS Industry

Operators Developers Advertisers Tech Futurists

Privacy Advocates

Non-Profit Groups Advocates Academics

Media Government Social Reactionaries Users?

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 2 / 27

slide-5
SLIDE 5

The Landscape

SNS Industry

Operators Developers Advertisers Tech Futurists

Privacy Advocates

Non-Profit Groups Advocates Academics

Media Government Social Reactionaries Users?

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 2 / 27

slide-6
SLIDE 6

The Landscape

SNS Industry

Operators Developers Advertisers Tech Futurists

Privacy Advocates

Non-Profit Groups Advocates Academics

Media Government Social Reactionaries Users?

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 2 / 27

slide-7
SLIDE 7

The Landscape

SNS Industry

Operators Developers Advertisers Tech Futurists

Privacy Advocates

Non-Profit Groups Advocates Academics

Media Government Social Reactionaries Users?

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 2 / 27

slide-8
SLIDE 8

My Research

Privacy in Graphs

Sampled Graphs Inference Control Crawling Prevention

Economic Factors Usability Next-Gen Designs

Untrusted Server App Sandboxing

Hacking Facebook

Photo Serving FQL tricks App problems

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 3 / 27

slide-9
SLIDE 9

My Research

Privacy in Graphs

Sampled Graphs Inference Control Crawling Prevention

Economic Factors Usability Next-Gen Designs

Untrusted Server App Sandboxing

Hacking Facebook

Photo Serving FQL tricks App problems

0% 20% 40% 60% 80% 100% Applications/Games Blogging Privacy Controls Profile Personalisation Signup is Free Discover New People Share Videos/Music Communicate with Friends Friends Are Already Members Photo Sharing Number/Sample of Users proportion of sites featuring this promotional argument general purpose (N=29) non general purpose (N=16)

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 3 / 27

slide-10
SLIDE 10

My Research

Privacy in Graphs

Sampled Graphs Inference Control Crawling Prevention

Economic Factors Usability Next-Gen Designs

Untrusted Server App Sandboxing

Hacking Facebook

Photo Serving FQL tricks App problems

Viewing Privacy Suite: Joe's Safe Settings

Author: Joseph Bonneau Created: May 29, 2009 My settings share your photos with friends only, hide your email address from search engines, and... (more) Reviewed By: Jonathan Anderson Rating: ★★★★ I love it!!! Keeps my data out of stranger's hands, and Joe does a great job keeping it updated... (more) Reviewed By: Luke Church Rating: ★★★☆ I liked this suite, but it hid too much of my info from my university network, so I modified it into my own Used By:

  • f your friends

people in the University of Cambridge network people in the London network people overall Adopt This Suite Preview Details 24 234 457 1802

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 3 / 27

slide-11
SLIDE 11

My Research

Privacy in Graphs

Sampled Graphs Inference Control Crawling Prevention

Economic Factors Usability Next-Gen Designs

Untrusted Server App Sandboxing

Hacking Facebook

Photo Serving FQL tricks App problems

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 3 / 27

slide-12
SLIDE 12

My Research

Privacy in Graphs

Sampled Graphs Inference Control Crawling Prevention

Economic Factors Usability Next-Gen Designs

Untrusted Server App Sandboxing

Hacking Facebook

Photo Serving FQL tricks App problems

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 3 / 27

slide-13
SLIDE 13

Disclaimer

I often complain about Facebook...

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 4 / 27

slide-14
SLIDE 14

Making Peace?

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 5 / 27

slide-15
SLIDE 15

A Roadmap For Peace

Recognise common ground

ie, ignore all the non-issues

Compromise on the small points Work together on the big picture

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 6 / 27

slide-16
SLIDE 16

What is Privacy, Anyways?

Accidental

information shared unintentionally bullying/harassment

Malicious

hacks deception crawlers/aggregators

Structural

advertisers developers Facebook & affiliates

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 7 / 27

slide-17
SLIDE 17

Non-issues

Sexual predators Bullying/Harassment Social/moral decline Censorship of hate speech (not yet)

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 8 / 27

slide-18
SLIDE 18

Things Facebook is Doing Well

Spam Detection Fine-grained privacy control Refusal to share “anonymised” data

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 9 / 27

slide-19
SLIDE 19

Technical Things Facebook Can Fix

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 10 / 27

slide-20
SLIDE 20

More TLS Encryption

https://www.facebook.com

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 11 / 27

slide-21
SLIDE 21

P3P Implementation

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 12 / 27

slide-22
SLIDE 22

Encourage Responsible Disclosure

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 13 / 27

slide-23
SLIDE 23

Fix Facebook Platform

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 14 / 27

slide-24
SLIDE 24

Strengthen or Scrap Verified Application Program

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 15 / 27

slide-25
SLIDE 25

Clarify Facebook Connect

Don’t allow friends to view my memberships on other websites through Facebook Connect?

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 16 / 27

slide-26
SLIDE 26

Photo Security

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 17 / 27

slide-27
SLIDE 27

Phishing

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 18 / 27

slide-28
SLIDE 28

Clarify Privacy Policy

Enumerate specific guarantees

Email address sharing Data removal

Narrower language

Lessen legal requirements for users to provide real data Clarify “Programmatic Interaction”

Remove democratic process

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 19 / 27

slide-29
SLIDE 29

More Openness

OpenID ‘Download my data’ button Open Social RSS export

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 20 / 27

slide-30
SLIDE 30

The Tough Issues

(hopefully, things we can work on together)

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 21 / 27

slide-31
SLIDE 31

More Transparent Data Sharing

Opt Out of Targeted Ads? Reference counting to data Subject Access Request

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 22 / 27

slide-32
SLIDE 32

Usability of privacy controls

Automatic inference of context? Automatic inference of intentions? Sharable privacy? Graphical end-user programming interface?

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 23 / 27

slide-33
SLIDE 33

Forward Privacy

Ensuring new features “at least as private” as previous Enable “auto opt-out” of new features Make clear changes in data visibility with new features Privacy review process

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 24 / 27

slide-34
SLIDE 34

Limiting Inference

Protection against crawling Less-useful public views Theoretical grounding for query limits

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 25 / 27

slide-35
SLIDE 35

Conclusion

Facebook has much to gain by working with its critics

Steady stream of ideas Credibility

Researchers can gain as well

Using Facebook as a research platform?

Users will gain too

In ways that is good for Facebook...

Self-regulation is better for everybody

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 26 / 27

slide-36
SLIDE 36

Questions?

Joseph Bonneau (University of Cambridge) Facebook Talk July 14, 2009 27 / 27