Information Revelation and Privacy in Online SocialNetworks(The Facebook case)
Pre-proceedings version. ACM Workshop on Privacy in the Electronic Society (WPES), 2005
Ralph Gross
Data Privacy LaboratorySchool of Computer ScienceCarnegie Mellon UniversityPittsburgh, PA 15213
rgross@cs.cmu.eduAlessandro Acquisti
H. John Heinz IIISchool of Public Policy and ManagementCarnegie Mellon UniversityPittsburgh, PA 15213
acquisti@andrew.cmu.edu
ABSTRACT
Participation in social networking sites has dramatically in-creased in recent years. Services such as Friendster, Tribe,or the Facebook allow millions of individuals to create onlineprofiles and share personal information with vast networksof friends - and, often, unknown numbers of strangers. Inthis paper we study patterns of information revelation inonline social networks and their privacy implications. Weanalyze the online behavior of more than 4,000 CarnegieMellon University students who have joined a popular so-cial networking site catered to colleges. We evaluate theamount of information they disclose and study their usageof the site’s privacy settings. We highlight potential attackson various aspects of their privacy, and we show that onlya minimal percentage of users changes the highly permeableprivacy preferences.
Categories and Subject Descriptors
K.4.1 [
Computer and Society
]: Public Policy Issues—
Privacy
General Terms
Human Factors
Keywords
Facebok, Online privacy, information revelation, social net-working sites
1. EVOLUTION OF ONLINENETWORKING
Permission to make digital or hard copies of all or part of this work forpersonal or classroom use is granted without fee provided that copies arenot made or distributed for profit or commercial advantage and that copiesbear this notice and the full citation on the first page. To copy otherwise, torepublish, to post on servers or to redistribute to lists, requires prior specificpermission and/or a fee.
WPES’05,
November 7, 2005, Alexandria, Virginia, USA.Copyright 2005 ACM X-XXXXX-XX-X/XX/XX ...
$
5.00.
In recent years online social networking has moved fromniche phenomenon to mass adoption. Although the conceptdates back to the 1960s (with University of Illinois Platocomputer-based education tool, see [16]), viral growth andcommercial interest only arose well after the advent of theInternet.
1
The rapid increase in participation in very recentyears has been accompanied by a progressive diversificationand sophistication of purposes and usage patterns across amultitude of different sites. The Social Software Weblog
2
now groups hundreds of social networking sites in nine cat-egories, including business, common interests, dating, face-to-face facilitation, friends, pets, and photos.While boundaries are blurred, most online networkingsites share a core of features: through the site an individ-ual offers a “profile” - a representation of their sel[ves] (and,often, of their own social networks) - to others to peruse,with the intention of contacting or being contacted by oth-ers, to meet new friends or dates (Friendster,
3
Orkut
4
), findnew jobs (LinkedIn
5
), receive or provide recommendations(Tribe
6
), and much more.It is not unusual for successful social networking sites toexperience periods of viral growth with participation ex-panding at rates topping 20% a month. Liu and Maes es-timate in [18] that “well over a million self-descriptive per-sonal profiles are available across different web-based socialnetworks” in the United States, and Leonard, already in2004, reported in [16] that world-wide “[s]even million peo-ple have accounts on Friendster. [...] Two million are regis-tered to MySpace. A whopping 16 million are supposed tohave registered on Tickle for a chance to take a personalitytest.”The success of these sites has attracted the attention of the media (e.g., [23], [3], [16], [4], [26]) and researchers. Thelatter have often built upon the existing literature on socialnetwork theory (e.g., [20], [21], [11], [12], [32]) to discuss
1
One of the first networking sites, SixDegrees.com, waslaunched in 1997 but shut down in 2000 after “strugglingto find a purpose for [its] concept” [5].
2
Http://www.socialsoftware.weblogsinc.com/
.
3
Http://www.friendster.com/
.
4
Http://www.orkut.com/
.
5
Http://www.linkedin.com/
.
6
Http://www.tribe.net/
.
Add a Comment