Jump to content

Facebook Private Profiles Not As Private As You Think They Are


Sidepocket

Recommended Posts

Facebook users who set their profiles to private aren't quite as hidden as they might think they are, according to security researcher Christopher Soghoian, who discovered that Facebook's advanced search features reveals people's names, pictures, religion and sexual orientation to people who don't have permission to see their profile.

Like many social networks, Facebook allows its users to mark their profile page as private, semi-private or very open.  However, even if you mark your profile to only be visible by friends, that doesn't change how you turn up in Facebook searches or whether your profile is open to indexing by search engines.

So for instance, if you are a Facebook member of your college or local area, you could run a search to see all the people who are Christian women who are lesbians, all the women interested in women or all the Muslim men into other men.  Your search results will likely include people who thought they marked their information as private, but didn't also change their search settings.

It's not as if Facebook doesn't give you the right to limit who can see your page, but common sense dictates that the vast majority of people who mark their pages as private don't want their information showing up in a public search.  Some might, but here Facebook could automatically remove "friends-only" users from search results, and let those who don't mind be found via searches yet want a private profile choose that option.

The long-and-short?  If you are a Facebook user but want it just to be a place for you and your friends to talk, get thee to to the search settings page today and turn that dial down.  Otherwise, lesbian Jewish high school sophomores who have "private profiles" will have their names and pictures displayed to any schmoo who signs up for a Facebook account and stumbles across the advanced search page.

More technical details on Soghoian's blog, where he also wonders if this 'feature' violates European data protection rules.

UPDATE: Threat Level just noticed that the advanced search lets one search for women who like men and who are looking for "random play."  Two of the private profiles displayed included the names and photos of a high school junior and a ninth grader.

http://blog.wired.com/27bstroke6/2007/06/f...ook-privat.html

Link to comment
Share on other sites

  • 1 month later...

It isn't Facebook's responsibility to make sure we're keeping our data private enough, they're not our nanny.  Still, it should be made crystal clear how to keep yourself private.

Agreed.

http://park.facebook.com/profile.php?id=618331762

Mubix, your profile is private but your name is still visible. And your name is visible to anyone who searches for your group.

Now that facebook has fixed it so that profile information that has been made private by a user, such as gender, religion, and sexual orientation, will not return a result. So unless you change your settings, I'm left guessing to your private details.

At least I can see on Facebook that Mubix is listed as one of Darren Kitchen's 63 friends - he's more open minded and hasn't set his profile to private.  :-)

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...