Facebook's 'man in the middle' attack on our data

Is Facebook secretly using your data for nefarious purposes? Privacy advocate Eben Moglen says yes.

By Dan Tynan  2 comments

  Sign me up for ITworld's FREE daily newsletter!
Email: 
 

Eben Moglen

flickr/aigarius

A few days ago I wrote a post asking whether Facebook was actively helping law enforcement track down bad guys using facial recognition technology. (The answer: Not really.)

I had to publish it before I got a response from Eben Moglen, the Columbia law professor and privacy advocate who inspired the post in the first place by telling New York Observer reporter Adrianne Jeffries that Facebook’s PhotoDNA technology was used “to find people for whom any law enforcement agency in the world is looking.”

Two things. First, I misspelled Moglen’s name (with an i instead of an e). So that’s embarrassing. Second: Moglen did get back to me after my post appeared and offered the following statement as a response.

I presented [that information] there as a rapid illustration of the underlying principle that Facebook causes people to do *ecological* harm by collaboratively destroying one another's privacy.  The point is that by sharing with our actual friends through a web intermediary who can store and mine everything, we *harm* people by destroying their privacy *for* them. It's not the sharing that's bad, it's the technological design of giving it all to someone in the middle. That is at once outstandingly stupid and overwhelmingly dangerous.

Moglen likens Facebook to a hacker who launches a “man in the middle” (MITM) attack -- intercepting an apparently private communication between two parties and using that information for his own nefarious purposes.

For example: Let’s say you have an insecure WiFi connection. You log onto your bank and decide to transfer money between your checking and savings account. Unbeknownst to you, an attacker is sitting in an unmarked van outside your house sniffing your WiFi traffic. He could then redirect you to a site he controls that looks just like your bank’s Web site, and act like an invisible phone operator – capture your log ins, access your account at the bank, perform the transactions you request, and relay back information that your transaction has been completed.

As far as you and the bank know, everything went as it should. But now Mr. MITM has all of your information and can log back in later to drain your account.

Moglen is saying that this is essentially how Facebook operates. But is it really? I have a few problems with this metaphor. For starters:

* A true MITM attack happens without either party knowing about it. When’s the last time you used Facebook without knowing about it, or been forced to use it against your will?

* The attacker has a nefarious purpose in mind for your data. Moglen may argue that Facebook’s purposes are nefarious, but to me they’re pretty clear: They want to monetize your data by sending you targeted ads. Not quite the same as draining your bank account. 

* You have no control over the data the MITM attacker collects. You have some controls over what Facebook collects.

Where Moglen and I agree is when he talks about how other people can do you harm by sharing too much about you on Facebook. The clearest example is indiscriminate photo tagging, which ties into the whole face recognition question.

The fact is, anybody can add your name to a photo on Facebook and there’s nothing you can do about it. All you can do is keep these pictures off your own personal timeline and tell Facebook to not “suggest” that your friends tag you when it recognizes your mugshot.

Is this quite the same as cooperating with the secret police or acting as a Man in the Middle? Not hardly. But it’s something Facebook needs to fix.

Got a question about privacy and/or social media? TY4NS blogger Dan Tynan may have the answer (and if not, he’ll make something up). Visit his snarky, occasionally NSFW blog eSarcasm or follow him on Twitter:@tynan_on_tech. For the latest IT news, analysis and how-to’s, follow ITworld on Twitter and Facebook.

Follow Dan on Google+

Author Dan Tynan has been writing about Internet privacy for the last 3,247 years. He wrote a book on the topic for O'Reilly Media (Computer Privacy Annoyances, now available for only $15.56 at Amazon -- order yours today) and edited a series of articles on Net privacy for PC World that were finalists for a National Magazine Award. During his spare time he is part of the dynamic duo behind eSarcasm, the not-yet-award-winning geek humor site he tends along with JR Raphael.

ITworld LIVE

IT Management/StrategyWhite Papers & Webcasts

White Paper

The Cloud: Reinventing Enterprise Collaboration

Collaboration and content sharing are not, of course, new concepts. But cloud computing has changed the nature of collaboration, content sharing, document storage and project management to enable more efficient, faster-acting and cost-effective enterprises. According to a new study by IDG Research, the vast majority of knowledge workers (86%) placed a very high level of importance on collaborating with internal coworkers and external stakeholders, and having access to the most up-to-date corporate information. Read how organizations are realizing massive productivity gains by transitioning their content management solutions to cloud-based models.

White Paper

Empowering Your Mobile Worker

Today's most productive employees are mobile, and your company's IT strategy must be ready to support them with 24/7 access to the business information they need across a range of mobile devices.See how corporations are meeting the many needs of their mobile workers with the help of Box.

White Paper

Market Landscape Report: Online File Sharing and Collaboration in the Enterprise

The trend toward "consumerization" marches onward in IT; more and more end-users are choosing their own hardware plaforms and software applications in lieu of the IT-sanctioned business tools provided by their companies. These end-users are looking to tackle issues like data sharing, portability, and access from multiple intelligent endpoint devices, creating a conundrum for IT as it needs to balance business enablement, ease of access, and collaborative capacity with the need to maintain control and security of information assets. This need for balance is one of the drivers of the fast growing online file sharing and collaboration segment of the SaaS market. This paper examines the market drivers, inhibitors, and top vendors in this segment, including Box, Citrix Sharefile, Dropbox, Egnyte, Nomadesk, Sugarsync, Syncplicity and YouSendIt.

White Paper

Sharing Simplified - Consolidating File-sharing Technologies

Employees need to share content with colleagues within their organization and outside. Yet, ECMs make it hard to share content within a business and impossible between organizations. Read how one company consolidated multiple file sharing technologies to increase productivity and reduce complexity.

White Paper

Content Sharing 2.0: The Road Ahead

A growing number of companies are taking advantage of the natural synergies that exist between cloud-based IT services and content access and sharing. Legacy content management and collaboration systems simply weren't designed to meet the evolving requirements of today's IT and business managers, as well as the needs of content users. Box provides cloud-based content storage, access and collaboration services that require virtually no user training and supports file access and delivery on almost all popular PC and mobile devices. Read how Box let companies rapidly implement a cost-effective and secure content storage and sharing system that can easily expand to accommodate any size and number of files.

See more White Papers | Webcasts

Ask a question

Ask a Question