Facebook To Encrypt User IDs After Privacy Concerns

Facebook is reacting to the data exposure incident reported earlier this week when some of the site’s most popular apps, including games such as FarmVille and Texas HoldEm Poker, were found to be sharing user IDs via the HTTP Referrer Header.

In a blog post, Facebook engineer Mike Vernal announced that the company plans to address the issue by encrypting the parameters it passes to iframe-based applications.

Encryption Proposal

“The proposal builds on our recent support for a parameter called signed request which is inspired by our discussions in the OAuth community,” he wrote. “We will start encrypting this parameter as well, using the application’s secret key, so that only the application will be able to read this information. This will prevent the accidental disclosure of this information via HTTP headers.”

“Our plan is to enable parameter encryption as an option over the next few weeks and to then work with the community to add support for this option to the various Facebook SDKs,” he continued. “Once the design is finalised, we will work with our developers to ensure a speedy transition to encrypted parameters.”

Facebook has made technical details of the proposal available here.

Privacy Fallout

The fallout from the revelations has already led to a lawsuit against Facebook app developer Zynga – the creator of some of the site’s most popular games, including FarmVille and Mafia Wars – as well as an inquiry from two Congressmen seeking answers from Facebook CEO Mark Zuckerberg.

While he said the problem had been exaggerated, Vernal noted that user ID numbers can be used to identify Facebook users and “link actions at other websites to a Facebook identity.”

“When a Facebook user requests a web page with images or other resources, the user’s browser may send HTTP header information that includes the URL of the web page,” he wrote. “For a particular type of Facebook Platform application, an iframe-based canvas application that includes a third-party iframe or resource, the HTTP Referrer header may include the user’s UID number once the user has authorized the application…[The User ID number is] what allows web pages to include information about one’s friends. Unfortunately, it can also compromise user privacy, particularly if the user is not aware that his or her UID is being shared.”

While the encryption proposal will address the inadvertent sharing of this information on Facebook, it will not fix the underlying issue of data sharing via HTTP headers, which is a web-wide problem, he added.

“We look forward to working with the web standards community and browser vendors over the coming months to help address this issue,” Vernal blogged.

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Hate Speech Watchdog CCDH To Quit Musk’s X

Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…

15 hours ago

Meta Fined €798m Over Alleged Facebook Marketplace Violations

Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…

17 hours ago

Elon Musk Rebuked By Italian President Over Migration Tweets

Elon Musk continues to provoke the ire of various leaders around the world with his…

18 hours ago

VW, Rivian Launch Joint Venture, As Investment Rises To $5.8 Billion

Volkswagen and Rivian officially launch their joint venture, as German car giant ups investment to…

19 hours ago

AMD Axes 4 Percent Of Staff, Amid AI Chip Focus

Merry Christmas staff. AMD hands marching orders to 1,000 employees in the led up to…

22 hours ago

Tesla Recalls 2,431 Cybertrucks Over Propulsion Issue

Recall number six in 2024 for Tesla Cybertruck, and this time the fault cannot be…

23 hours ago