Privacy Issues with Social Networking Sites Ai Ho, Abdou Maiga, Esma Aïmeur Département d'informatique et de recherche opérationnelle Université de Montréal Montreal, Canada Shruthi Rajegowda
Social Networking Sites (SNS) Information Build Network NSBA Survey Report : Nine-to-17-year-olds – spend about 9 hours per week on social networking activities NSBA - National School Boards Association Expect Change in Education System Social Media for Education
Most Visited Web Sites – 7 out of top 20 Potential Privacy threats – Identity theft – Disclosure of sensitive information. Social Networking
Privacy Issues Problem 1: Lack of user education/awareness about – Settings defaulted to share users’ personal information – Privacy warnings or privacy settings provided by SNS
Privacy Issues Problem 2: Lack of Privacy Tools to protect user data – Only basic access control – Profile public or private – Privacy setting interface is Complex
Privacy Issues Problem 3: Users cannot control what others may reveal about them – Cannot control Friends’ profile – Risks from third party application Just for FUN!!
Weak Privacy Policy Privacy policy – a disclaimer about using user‘s personal information – Do Social Sites respect its privacy policy? – Policies can change anytime! – Uploaded content is property of users or the site!! – Can you really delete your profile?
Privacy Framework Role: Foundation to address privacy issues – Categorize user data, user privacy concerns and profile viewers – Adapt privacy levels - based on these categorizations – Adapt Tracking level
User data Categorize user profile information into the following groups: – Identity - determine physically who is the user – Demographic profile- age, gender, weight, race, political view…. – Activity - lists all the activities that users perform Adding new friends Commenting on profile Change in personal information – Social Network Relationship status – User friends – User subscribed groups – Added content - blog, photos, music or video clips
User privacy concern Classify data to be shared as a privacy concern – Healthy data – General information about users – Nick name – Hobbies, – Landscape photos – Harmless data - User’s demographic profile – Harmful data – Inappropriate photos Blog entry that may damage the user’s reputation – Poisonous data - Sensitive information that may cause Security risks
Profile Viewers Best Friends – Trustworthy, can share all information Good Friends – Real life friends, can share more information Casual Friends - Based on s imilar interest, limited information share Visitors - could be users or non-users of the SNS, not in friend’s List Group people who can see the profile based on intimacy and trust
Privacy levels Based on Profile Viewers, four levels of privacy
Tracking levels Strong tracking - User does not mind being tracked on SNS Weak tracking – User minds if his/her profile is tagged to friends profile No tracking – No name, no tags, no photos in friends list
Privacy Protection based on User Type
Conclusions Existing solutions do not protect user privacy totally Lack of user awareness Privacy comes with a price Need for Privacy tools – strong and easy to use Need for Legal Law Enforcement to protect privacy
Privacy Protection Work In Progress
References Ai Ho, Abdou Maiga, Esma Aimeur, "Privacy protection issues in social networking sites,", The 7th ACS IEEE International Conference on Computer Systems and Applications,2009 D. Rosenblum, What Anyone Can Know: The Privacy Risks of Social Networking Sites. IEEE Security and Privacy, networking/social-networking-in-education-survey-on-new-generations-social- creative-and-interconnected-lifestyles-NSBA htm hints-at-more-location-features/ dyn/content/article/2010/04/27/AR html