<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Artificial ignorance &#187; facebook</title>
	<atom:link href="http://www.Artificialignorance.net/blog/category/facebook/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.Artificialignorance.net/blog</link>
	<description>the anand iyer chronicles</description>
	<lastBuildDate>Tue, 07 Sep 2010 23:43:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Are Facebook&#8217;s privacy settings working?</title>
		<link>http://www.Artificialignorance.net/blog/facebook/are-facebooks-privacy-settings-working/</link>
		<comments>http://www.Artificialignorance.net/blog/facebook/are-facebooks-privacy-settings-working/#comments</comments>
		<pubDate>Sat, 20 Jun 2009 23:52:10 +0000</pubDate>
		<dc:creator>Anand Iyer</dc:creator>
				<category><![CDATA[facebook]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.artificialignorance.net/blog/facebook/are-facebooks-privacy-settings-working/</guid>
		<description><![CDATA[A couple of weeks ago I had an incident with someone I friended on Facebook. I usually just accept any facebook friend requests that come my way. But one person I added as a friend, found my sister on Facebook, befriended her (my sister accepted because she noticed this person was my friend) and from [...]]]></description>
			<content:encoded><![CDATA[<p>A couple of weeks ago I had an incident with someone I friended on Facebook. I usually just accept any facebook friend requests that come my way. But one person I added as a friend, found my sister on Facebook, befriended her (my sister accepted because she noticed this person was my friend) and from there, it got a little creepy. Apparently this person started asking some pretty pointed questions about my niece. My sister, who would trust my friends, gracefully answered these questions. Later on, my sister casually mentioned this friend’s inquisitiveness to me and the fact that this person had asked about my niece. This made me extremely suspicious. I immediately blocked this new friend and asked my sister to do the same, but I believe the damage had been done at that point. This person probably has pictures of my family in her (or his) possession now.</p>
<p>Soon after that incident, I decided to create a “notfriends” facebook list. I’m <em><u>not</u></em> one of those egotistical people – I generally add everyone as a friend, and don’t think about who can see what on my profile. But since this incident, I realized I <strong>should control</strong> who sees what on my profile. Today, after going through a few more friend requests, I decided to ensure that my <strong>privacy settings were in fact working</strong> and to my surprise, I find out <strong>they are not</strong>.<span id="more-160"></span></p>
<p>1 – I created a new list called “<strong>notfriends</strong>”</p>
<p>&#160;<a href="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb1.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="fb1" border="0" alt="fb1" src="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb1_thumb.jpg" width="197" height="244" /></a> </p>
<p>2 – I edited <a href="http://www.facebook.com/home.php#/privacy/?ref=mb">Facebook’s privacy settings</a> and added people who I didn’t know at all to the list “<strong>notfriends</strong>”. I edited my privacy settings to block ‘notfriends’ from seeing photos, videos and personal information.</p>
<p><a href="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb2.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="fb2" border="0" alt="fb2" src="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb2_thumb.jpg" width="524" height="693" /></a> </p>
<p>3 – I <strong>impersonated</strong> a member of the “<strong>notfriends</strong>” list to see what they can see (used the <strong>“View Profile As”</strong> feature). And guess what, the privacy setting didn’t take. Maybe the impersonation setting was not working? <em>(I’ve deleted the name of the person who I’m impersonating in the image below)</em></p>
<p><a href="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb3.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="fb3" border="0" alt="fb3" src="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb3_thumb.jpg" width="533" height="375" /></a> </p>
<p>4 – So, I created a new <strong>dummy profile</strong> called “<strong>Art Ignor</strong>” and added this “friend” to my “<strong>notfriends</strong>” list. This friend is NOT in any of the Facebook networks I’m in. I also used another computer to test this (to ensure there were no IP caveats or browser cache issues that could tamper with the settings).</p>
<p><a href="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb4.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="fb4" border="0" alt="fb4" src="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb4_thumb.jpg" width="529" height="164" /></a> </p>
<p>5 – Logged in as “Art Ignor” and viewed <a href="http://facebook.com/anandiyer">http://facebook.com/anandiyer</a>. Guess what, Art Ignor can see all of my profile in spite of being in the “notfriends” list.</p>
<p><a href="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb51.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="fb5-1" border="0" alt="fb5-1" src="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb51_thumb.jpg" width="543" height="231" /></a> </p>
<p><a href="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb52.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="fb5-2" border="0" alt="fb5-2" src="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb52_thumb.jpg" width="544" height="440" /></a> </p>
<p>6 – I edited the privacy settings and <strong>explicitly denied “Art Ignor”</strong> permission to see my videos.</p>
<p><a href="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb6.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="fb6" border="0" alt="fb6" src="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb6_thumb.jpg" width="323" height="465" /></a> </p>
<p>7 &#8211; Logged in as “Art Ignor” and checked out my videos. And, guess what:</p>
<p><a href="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb7.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="fb7" border="0" alt="fb7" src="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fb7_thumb.jpg" width="507" height="406" /></a> </p>
<p>I even waited several minutes (to ensure that the setting has ‘propagated’). No luck.</p>
<p><strong>Facebook, what am I doing wrong</strong>? I’ve edited complicated <a href="http://www.petri.co.il/csc_how_to_use_cisco_ios_access_lists_01.htm">ACLs using Cisco’s IOS CLI</a>, and maybe that’s part of the problem that I don’t know how to use your UI. I don’t want to be an ass and “delete” friends I’ve met on Facebook (although I may not know them). As an evangelist I want to keep my channels of communication open (<a href="http://www.davemorin.com">Dave Morin</a> would empathize), but I want to restrict what some people can see. Please, please, tell me I’m doing something wrong and that your privacy settings aren’t actually broken. </p>
</p>
</p>
</p>
</p>
</p>
<p><strong>ai</strong></p>
<p>PS: I’d twittered about this possible hole in Facebook time back when I was first tinkering with the privacy setting:</p>
<p><a href="http://twitter.com/anandiyer/status/2056541588"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="fbtwitter" border="0" alt="fbtwitter" src="http://www.artificialignorance.net/blog/wp-content/uploads/images/FacebookPrivacyFAIL_DA70/fbtwitter.jpg" width="313" height="224" /></a></p>
<p>[ad]</p>

<div class="like">
<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.Artificialignorance.net%2Fblog%2Ffacebook%2Fare-facebooks-privacy-settings-working%2F&amp;layout=standard&amp;show_faces=true&amp;width=450&amp;action=like&amp;font=segoe+ui&amp;colorscheme=dark" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px; height:62px; "></iframe>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.Artificialignorance.net/blog/facebook/are-facebooks-privacy-settings-working/feed/</wfw:commentRss>
		<slash:comments>25</slash:comments>
		</item>
	</channel>
</rss>
