The “social networking” community is buzzing this morning with the Facebook Terms of Service shakeup. What users of any social networking site must realize, however, are the potential dangers of the “information lifecycle”. As Bill Brenner wrote in his Network World article titled “Slapped in the Facebook: Social Networking Dangers Exposed,” there are significant threats to personal information security present, through information engineering attacks, among other threats. Today, we are examining the under-appreciated power of what I call the Information Lifecycle. The principle is simple, whatever information is posted publicly, or even privately , is fair game for permanent archival and future use by any third-party. Today in the 21st century, we have literally become the ‘share-all’ society, where concerns about personal identity and private details have gone out the window. I wrote an article back in 2005, when Facebook was still in its infancy, and would like to include a few thoughts that have become even more evident since then:
Let’s start here. You login to Facebook from your home computer. Instantly, Facebook has a record in their database of exactly who logged in, at what time, and exactly from where. This isn’t uncommon – most sites do track this, such as Hotmail. Legally, it may even be required that they do. Now, the real danger begins to appear. Every single Facebook page you browse, every personal message you send, every poke, every photo uploaded, tagged… gets tied to your identity. On the average Facebook session of 10 minutes, there may be hundreds of rows created in relational databases, which you have absolutely no control over. None. You have no control over how that data is stored, where it is stored, how it is replicated, archived, transported, or even sold to others. Think of all the information stored in your Facebook profile. -Full name -Address -Birthday -Phone Numbers -Email Addresses -Gender -Sexual Orientation -Locational history (e.g. where you went to high school) …and the list goes on. In any information security operation, the rule is this: expose any two critical pieces of a value (a person), and you have a serious threat against that value’s identity. From my view, it isn’t the “live” information that poses a threat. You and I could simply change our birthdays to something fake, or remove our phone numbers or addresses, right? If it were only that simple… Every piece of information that you have ever entered into Facebook, whether you’ve removed it, changed it, or even deleted your account, is potentially still there. It’s in the same relational database it always has been, sitting right next to your current or “live-set” information. However, a simple boolean flag defines whether the data is actively displayed or not. But it’s OK because Facebook has privacy controls, right? Only certain friends can see certain things? Sure, but we’re forgetting about the bigger problem. It’s the fact that we’re trusting our lives, our identities, everything we’ve ever written, said, or clicked on within Facebook, is sitting somewhere in a database that may not have adequate protection against malicious hackers, data mining bots, rootkits… and the list goes on. So you ask, isn’t our information already out there, with credit card companies, Amazon.com, and other sites and companies databases? Sure it is. However, there’s one huge difference. These companies run well-funded, well-executed, and highly-monitored information assurance and security operations that employ thousands of people to protect our information. They have a responsibility to maintain with the customer – if they fail, they lose paying customers. Facebook doesn’t generate revenue off of its users, so they aren’t going to lose “paying customers” if a pool of databases is exposed. What’s the incentive? Do you think that today’s youth appreciates the lifecycle of information? Do they understand its permanency ? Why or why not?




