Facebook has done it again. Last week's round of changes to the platform's privacy settings marks the fourth major overhaul in two years, and true to form, the net effect is that more of your information is shared with more people and more third parties than it was before. At this point, calling Facebook's privacy controls "settings" feels generous. They are more like a pressure valve that Facebook periodically opens a little wider while telling you they have given you more control.

The Erosion Pattern

Let us review the trajectory. When Facebook launched, your profile was visible only to people in your network - your college, your company. In 2006, the News Feed made your activity visible to all your friends in real time, triggering the first major privacy backlash. Facebook apologized and added controls. In 2009, they changed the defaults so that much of your profile became public by default, then added a "simplified" privacy settings page that was anything but. Earlier this year, the introduction of Instant Personalization meant that partner websites could access your data without you explicitly authorizing it.

Each time the pattern is the same. Facebook expands data sharing. Users complain. Facebook adds more granular controls that most people never find or understand. The net result is always more sharing, because the defaults favor openness and the complexity of the settings ensures that the vast majority of users never change them.

The EFF published a visualization showing how Facebook's default privacy settings have changed from 2005 to 2010. The progression from "mostly private" to "mostly public" is striking and unambiguous. This is not a series of accidents. It is a business strategy.

Why This Matters Beyond Facebook

The problem extends well beyond one company. Facebook's behavior is simply the most visible example of a structural tension that exists in every ad-supported social platform. The business model depends on data. More data shared means more effective ad targeting, which means more revenue. Privacy and profitability are in direct opposition, and anyone who thinks the privacy side is going to win that fight in the long run is not paying attention to the incentive structure.

For enterprise security professionals, this has real implications. Your employees are on these platforms. They are sharing information about their work, their travel, their organizational structure, their frustrations with specific technologies. Social engineering attacks increasingly start with open-source intelligence gathered from social networks, and the default settings on these platforms are designed to make that intelligence as easy to collect as possible.

What Users Can Actually Do

The honest answer is: less than you think. You can lock down your Facebook privacy settings today, but history suggests those settings will be reshuffled within six months. You can limit what you post, but your friends' posts, tags, and check-ins reveal information about you regardless. You can delete your account, but Facebook retains your data and the accounts of people who mentioned you still reference you.

Here is my practical advice for security-conscious professionals:

Assume everything is public. If you would not put it on a billboard outside your office, do not put it on a social network. Privacy settings are a speed bump, not a wall.

Audit your presence regularly. Search for yourself. Look at what comes up. Check what your profile looks like to someone who is not your friend. Facebook has a "View As" tool for this, buried in the settings.

Be cautious with third-party applications. Every Facebook app you authorize gets access to your profile data and often your friends' data as well. The permissions model is deliberately broad.

Educate your organization. If you are responsible for security awareness at your company, social network privacy should be part of the conversation. Not in an abstract "be careful online" way, but with specific examples of how information from social networks has been used in targeted attacks.

The Bigger Picture

I do not think social network privacy is fixable within the current business model. The platforms that depend on advertising will always push toward more sharing, because that is where the money is. Regulation might help at the margins, but legislators are years behind the technology and the lobbying efforts of the major platforms are substantial.

The most honest thing Facebook could do at this point is stop pretending that privacy is a priority and let users make informed decisions based on reality rather than marketing. But that would require a level of candor that publicly traded companies rarely exhibit, especially when the gap between perception and reality is what keeps the users coming back.

SA
SecForAll Editorial
Security Analysis & Commentary
SecForAll covers enterprise security trends, policy, and technology for security professionals and decision-makers. Our analysis draws on industry research, vendor briefings, and hands-on evaluation of security products and standards.