Tuesday, November 23, 2010

Facebook directory - personal details for 100 million users

Facebook logo
Privacy issues have haunted Facebook since quite some time now. We can’t really say if much has changed about users being able to actually choose what data they wish to keep public and private. At least Facebook’s online directory says security specialist Ron Bowes is still very easy to amass. According to the hacker, one can lay their hands on each and every searchable user on all of Facebook.
Virtually anyone can be searched for on Facebook by name which indeed is a scary privacy issue, particularly after the SNS blabs that ‘[a]nyone can opt out of appearing here by changing their Search privacy settings.’ Showing the vulnerability of public data on Facebook, Ron was able to spider the site’s online directory and compile it into one torrent. And this neat little barrage of data could be downloaded through his site SkullSecurity.com.
Once a user’s name and URL is available, by default their picture, friends along with information and a few other details are up for grabs. In case, users have their privacy set higher, at least their name and picture can be viewed. Yes, whether non-searchable users like it or not in case they have friends who are searchable, they can be searched too.
For those enthused about downloading the torrent of Facebook’s by now very public data, Ron lists out what can be expected. It includes every searchable Facebook user’s profile URL along with the name of every searchable Facebook user comprising both unique and by count. Processed lists packing in first names with count, last names with count, potential usernames with count and the likes are also in. Moreover, the programs employed to generate all of this is also bundled.
Ron decided to dive deep in this issue after @FSLabsAdvisor posted a tweet about this very Facebook glitch last week. While we aren’t sure if simply altering user privacy settings will help, Facebook might just be able to do users good by leveraging profiles disarranged by default. And Ron does have plans to look into the fact that he could only index searchable users and not their friends.
Download here:

No comments:

Post a Comment