Study finds widespread privacy failings in online social networks

July 21, 2009

(PhysOrg.com) -- Furious competition between social networking sites is compromising the protection of users' data, a Cambridge University study has concluded.

The survey covered 45 global social networks, ranging from popular sites such as MySpace and Facebook through to lesser-known foreign networks. Its authors report "serious concerns" about the extent to which these sites fail to keep users' personal information private.

It is the first detailed analysis to examine the security provisions of a large number of social networks. The report, by researchers in the University's Computer Laboratory, is being made freely available online.

While the problems it identifies - such as misleading privacy policies and inaccessible privacy guidelines - have long been suspected, the report provides new numerical data to confirm their scope.

Some 90% of sites, for example, needlessly required a full name or date of birth for permission to join. 80% failed to use standard encryption protocols to protect sensitive user data from . And 71% reserved the right to share user data with third parties in their privacy policies.

The study also argues that privacy is being compromised by rigorous competition for users. Researchers argue that open discussion of privacy on puts off the average user, which discourages the owners from producing explicit or accessible privacy guidelines.

"Sites want users to be relaxed and having fun, but when privacy is mentioned users feel less comfortable sharing data," Co-researcher Joseph Bonneau said. "Even sites with good privacy feel that they can't promote it, so users have no idea of what they're getting."

The researchers only covered sites which are available in English, signing up to each using a Yahoo! Email account and the pseudonym "Upton Sinclair".

In each case, Bonneau and his fellow researcher, Sören Preibusch, recorded the amount of personal information that they had to hand over in order to sign up to the site and how much they were told about its privacy policy and settings in the process. They also analysed how much they could see about the site's existing members before they joined.

Once they were signed up, the researchers tested each site's privacy controls against 260 criteria, examining features such as log-in arrangements and the site's privacy policy and configuration controls.

They found what the report calls "pervasive problems", including poor web security practices, confusing user-interfaces and misleading privacy policies.

All but three of the general purpose sites they examined left new profiles completely visible to at least all the other members of the site by default. As previous studies have suggested that between 80% and 99% of users never alter their privacy settings, this means that in most cases their profiles will remain visible.

The researchers also produced privacy scores for each of the networks assessed. Bebo and LinkedIn were ranked the highest for their privacy settings, while the British site Badoo earned the wooden spoon. Facebook and , frequently the targets of privacy critics, finished slightly above average. In general, the researchers found that the larger, more popular and older sites maintained better privacy practices and adopted higher privacy standards.

"The popular sites are just the tip of the iceberg," Preibusch said. "Niche sites implement significantly less favourable privacy practices and offer fewer controls to their users to configure the sharing of personal information."

Overall, the report also found that sites which promoted their privacy controls as a selling point tended to be those with fewer users joining the site. It suggests that this may be because the vast majority of people, while they may claim to be concerned about privacy, tend to forget about or ignore the possibility that this may be jeopardised when offered an attractive service.

Since the sites depend on acquiring as many users as possible, the researchers argue that most social networks opt to set up long and complicated privacy measures which, in most cases, it is difficult to access or even find. At the same time, they show off how many users they have and how easy it is to make friends, or share photos, videos and music - all features which it would be harder to sell with stricter privacy controls.

The privacy policies remain in place, the researchers suggest, to placate a vocal minority of "privacy fundamentalists", who might otherwise expose the lack of policy to the wider majority, prompting a discussion which, through its very existence alone, might dissuade prospective new members from joining.

The report calls for an "opt-out" approach to privacy, in which users' details are kept private until otherwise stated. It also calls for stronger across-the-board regulation, and suggests that sites could offer "premium" membership schemes which allow users to handle their privacy settings in greater detail if they so wish, a scheme known as "privacy negotiations".

The full report along with the original dataset can be downloaded at: http://preibusch.de/publ/privacy_jungle

Provided by University of Cambridge (news : web)


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - not rated yet

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • AMMBD - Jul 22, 2009
    • Rank: not rated yet
    ". . .the vast majority of people, while they may claim to be concerned about privacy, tend to forget about or ignore the possibility that this may be jeopardised when offered an attractive social networking service."

    privacy, particularly online, has been a hot topic for YEARS. if people refuse to listen, remember & act as needed to protect their privacy - then they are fools.

July 21, 2009 all stories

Comments: 1

not rated yet
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Facebook plans to simplify privacy settings
    created Jul 01, 2009 | popularity not rated yet | comments 0
  • Watchdog: Facebook violates Canadian privacy law
    created Jul 16, 2009 | popularity not rated yet | comments 0
  • Report: Widespread data sharing, 'Web bugs'
    created Jun 02, 2009 | popularity not rated yet | comments 0
  • Online shoppers will pay extra to protect privacy, study shows
    created Jun 06, 2007 | popularity not rated yet | comments 0
  • Internet users give up privacy in exchange for trust
    created Nov 22, 2007 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Aspiring Engineering major looking for general answers
    created Nov 19, 2009
  • Calculating max load of square tube (steel)
    created Nov 19, 2009
  • Passive Chemical Heating
    created Nov 19, 2009
  • Shortening Boat Trailer
    created Nov 18, 2009
  • Strain Gage Test Advice
    created Nov 17, 2009
  • How Could I do This? Motor to open and close doors on a timer??
    created Nov 17, 2009
  • More from Physics Forums - General Engineering

Other News

China is the world's largest emitter of the greenhouse gases blamed for global warming

China harnesses mountain wind power

Technology / Energy

created 2 hours ago | popularity not rated yet | comments 0

In the mountains above the southwestern Chinese town of Dali, dozens of new wind turbines dot the landscape -- a symbol of the country's sky-high ambitions for clean, green energy.


Ubisoft steps up videogame fitness with virtual coach

Technology / Software

created 2 hours ago | popularity not rated yet | comments 0

French videogame powerhouse Ubisoft will have a virtual fitness coach whipping Wii users into shape starting Tuesday.


Hackers leak e-mails, stoke climate debate

Technology / Internet

created 13 hours ago | popularity 4.3 / 5 (18) | comments 12

(AP) -- Computer hackers have broken into a server at a well-respected climate change research center in Britain and posted hundreds of private e-mails and documents online - stoking debate over whether some scientists have ...


plug-in hybrid electric vehicle

Pulling the plug on hybrid myths

Technology / Energy

created Nov 19, 2009 | popularity 3.8 / 5 (12) | comments 17

(PhysOrg.com) -- Whether you call them myths, urban legends, fables or old wives' tales, there's a lot of misinformation out there about plug-in electric hybrid vehicles. These vehicles, abbreviated PHEVs, ...


UK police make 2 Trojan computer virus arrests

Technology / Internet

created Nov 18, 2009 | popularity 5 / 5 (1) | comments 10

(AP) -- A couple suspected of helping spread some of the Internet's most aggressive computer viruses has been arrested in the English city of Manchester, police said Wednesday.