This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Zuckerberg photo leak exposes Facebook privacy flaw

by Shaun Nichols

08 Dec 2011

View Comments

  • Tweet this
mark-zuckerberg-at-2010-f8

The recent Facebook flaw that led to the disclosure of founder Mark Zuckerberg's personal images could signal a larger issue regarding user privacy on the social networking site.

A group of users disclosed the flaw along with a number of images pulled from the locked photo gallery of Zuckerberg.

The company has since fixed the flaw, which allowed a third party to view a user's locked and private images while reporting a public image as objectionable or offensive. Facebook has noted that only a small portion of locked images were displayed by the flawed feature.

While the incident itself was limited in scope, the underlying cause of the problem could indicate lingering problems with Facebook's approach to security.

Andrew Brandt, director of threat research for Solera Networks Research Labs, told V3 that such issues should be addressed by developers during normal quality assurance (QA) testing. In this case, Brandt believes the company never thought to check the reporting tool for such a privacy disclosure situation.

"It would be smart of Facebook to hire some people that have a strong security-focused mindset to do QA of their tools," he explained.

"It is not a reflection on their ability to write good applications, it is a failure of the imagination of whoever tested this feature."

The incident is far from the first occasion in which Facebook's privacy protections have been called into question. The company has a long history of embarrassing breaches and user revolts over its inability to properly manage and protect the personal data of its customers.

Recently, the company agreed to a settlement with the FTC over multiple charges of mishandling user data.

The company's record of privacy problems only furthered discussion on the latest issue. Brandt believes the reaction to the flaw was driven by a combination of public sentiment towards the company and the high profile of the target.

"This was a very minor flaw that got drawn into the public eye because it was the president of a social networking company," he said.

"It was somebody lashing out against Facebook in a public way. They used pictures of Zuckerberg because they knew people would react in a dramatic way."

Brandt noted that, by nature, privacy protections can seem counter-intuitive in a social networking space designed to help users display and share information about themselves with others. He recommended that users take a cautious approach in their activity, assuming that any information posted to the service will at some point be made public.

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

16%

57%

10%

9%

8%

Popular Threads

Powered by Disqus
BlackBerry Q5

BlackBerry Q5 video demo

BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

C# Developer - £35K-£40K - Bedfordshire - Support Development

C# Developer - £35K-£40K - Bedfordshire - Support Development...

C# Developer - £25K - Hampshire - C# , .NET , VB6 , Windows

C# Developer - £25K - Hampshire - C# , .NET , VB6 , SQL...

Senior C# Developer - Hampshire - £40K - C# , VB6 , Windows

Senior C# Developer - Hampshire - £40K - C# , VB6 , Windows...

C# Developer - Milton Keynes - £35K - ASP.NET , C# , SQL

C# Developer - Milton Keynes - £35K+10% Pension - C...

Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.

To send to more than one email address, simply separate each address with a comma.