1 Introduction
2 Background
2.1 Social Networking and Facebook
2.2 Information that Facebook stores
3 Previous Work
4 Principles and Methods of Research
4.1 Usage patterns of interest
4.2 User surveys
4.3 Direct data collection
4.4 Obscuring personal data
4.5 A brief technical description of Facebook from a user perspective
4.6 Statistical significance
5 End-Users’ Interaction with Facebook
5.1 Major trends
5.2 Facebook is ubiquitous
5.3 Users put time and effort into profiles
5.4 Students join Facebook before arriving on campus
5.5 A substantial proportion of students share identifiable information
5.6 The most active users disclose the most
5.7 Undergraduates share the most, and classes keep sharing more
5.8 Differences among universities
5.9 Even more students share commercially valuable information
5.10 Users are not guarded about who sees their information
5.11 Users Are Not Fully Informed About Privacy
5.12 As Facebook Expands, More Risks Are Presented
5.13 Women self-censor their data
5.14 Men talk less about themselves
5.15 General Conclusions
6 Facebook and “Fair Information Practices”
6.1 Overview
6.2 Notice
6.3 Choice
6.4 Access
6.5 Security
6.6 Redress
7 Threat Model
7.1 Security Breach
7.2 Commercial Datamining
7.3 Database Reverse-Engineering
7.4 Password Interception
7.5 Incomplete Access Controls
7.6 University Surveillance
7.7 Disclosure to Advertisers
7.8 Lack of User Control of Information
7.9 Summary and Conclusion
8 Conclusion
8.1 Postscript: What the Facebook does right
8.2 Final Thoughts
A Facebook Privacy Policy
B Facebook Terms Of Service
C Facebook “Spider” Code: Acquisition and Processing
C.1 Data Downloading BASH Shell Script
C.2 Facebook Profile to Tab Separated Variable Python Script
C.3 Data Analysis Scripts
D Supplemental Data
E Selected Survey Comments
E.1 User Feedback
F Paper Survey
2458 Facebook Threats to Privacy

