• DocumentCode
    2525159
  • Title

    Design and Development of a Facebook Application to Raise Privacy Awareness

  • Author

    Costantino, Gianpiero ; Sgandurra, Daniele

  • Author_Institution
    Ist. di Inf. e Telematica, Pisa, Italy
  • fYear
    2015
  • fDate
    4-6 March 2015
  • Firstpage
    583
  • Lastpage
    586
  • Abstract
    Everyday people upload a large number of private pictures on online social networks (OSNs). Users trust OSNs to keep their pictures private, e.g. by making them available to their social friends only. Unfortunately, OSN security controls are not always strong enough and malicious people may exploit these weaknesses to potentially see any user´s private pictures. It might even possible to access private photos posted on an OSN without circumventing its security policies. In fact, users sometimes add to their social circles acquaintances, recently met people, which might not be completely trusted. Furthermore, they occasionally allow third-party applications to access their pictures. These conditions imply that, to keep their photos private, users must trust all the security controls implemented by OSNs and all of their social friends (and how they interact with third-party applications). Actually, there are some situations in which these assumptions are not met and some data that users believed to be private might also be accessed by unknown people. The goal of this paper is to raise awareness on the problem of privacy of online pictures and to have OSN users think more carefully about how they use third-party applications and how they choose their friends online. To this end, we discuss a use-case of a Facebook application, which we have developed, that exploits some weaknesses and users´ assumptions to gather a huge amount of private pictures.
  • Keywords
    Internet; data privacy; social networking (online); Facebook application; OSN security controls; access private photos; online pictures; online social networks; private pictures; raise privacy awareness; security policies; social circles; social friends; Authorization; Facebook; Privacy; Servers; Big Data; CDN; Privacy; Social Network;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel, Distributed and Network-Based Processing (PDP), 2015 23rd Euromicro International Conference on
  • Conference_Location
    Turku
  • ISSN
    1066-6192
  • Type

    conf

  • DOI
    10.1109/PDP.2015.23
  • Filename
    7092778