Close Menu
GeekFenceGeekFence
    Facebook Instagram
    Facebook Instagram
    GeekFenceGeekFence
    • Home
    • Contact Geekfence
    • Computing

      Apple kerfuffles, praise groups, and media layoffs

      2019-03-17

      Podcasts, smart speakers soar as social media stalls, based on new survey

      2019-03-07

      Security token offerings aren’t looking much better in 2019

      2019-03-04

      How far are you willing to go for growth?

      2019-03-03

      Can we ever evaluate technical debt?

      2019-02-28
    • Business

      Top 10 Tech Companies in the World

      2024-01-04

      Soar into the New Year: Inspirational Quotes to Elevate Your Spirit

      2023-12-31

      Non-invasive glucose monitor EasyGlucose takes home Microsoft’s Imagine Cup and $100K

      2019-05-12

      Google opens Android Automotive OS to Spotify, other media app developers

      2019-05-02

      Kiwi’s food delivery bots are rolling out to 12 more colleges

      2019-04-30
    • Entrepreneur

      Decade in review: Trends in seed- and early-stage funding

      2019-03-18

      Apple kerfuffles, praise groups, and media layoffs

      2019-03-17

      NVIDIA and OpenAI’s capped returns

      2019-03-13

      Can we ever evaluate technical debt?

      2019-02-28

      #LetYourBrandReign SME Business Networking Series Inauguration Successfully Kicks Off

      2019-02-12
    • Electronics

      Disc-free Xbox One S could land on May 7th

      2019-04-24

      TP-Link EAP225-Outdoor Review

      2019-04-23

      Flying taxis could be more efficient than gas and electric cars on long-distance trips

      2019-04-10

      GPS Rollover is today. Here’s why devices might get wacky

      2019-04-08

      Tonal raises $45 million to bring strength training to more living rooms

      2019-04-07
    • Mini-Stories

      Non-invasive glucose monitor EasyGlucose takes home Microsoft’s Imagine Cup and $100K

      2019-05-12

      LEGO Braille bricks are the best, nicest and, in retrospect, most obvious idea ever

      2019-04-29

      Resurgent HappyFresh raises $20M for its online grocery service in Southeast Asia

      2019-04-22

      Tonal raises $45 million to bring strength training to more living rooms

      2019-04-07

      Alcatraz AI is building Face ID for corporate badges

      2019-04-03
    • Mustreads

      Is this the vertical-folding Motorola Razr?

      2019-05-01

      LEGO Braille bricks are the best, nicest and, in retrospect, most obvious idea ever

      2019-04-29

      Avengers Endgame – A Love letter to the MCU

      2019-04-28

      Flying taxis could be more efficient than gas and electric cars on long-distance trips

      2019-04-10

      Camera maker Insta360 raises $30M as it eyes 2020 IPO

      2019-03-21
    GeekFenceGeekFence
    Home»Computers»The Cambridge Analytica Debacle is not a Facebook “Data Breach.” Maybe It Should Be.
    Computers

    The Cambridge Analytica Debacle is not a Facebook “Data Breach.” Maybe It Should Be.

    geekfencebloggerBy geekfenceblogger2018-03-17No Comments5 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    On March 16, we learned that Facebook will be suspending Strategic Communications Laboratories (SCL) and its offshoot Cambridge Analytica. According to Facebook, a University of Cambridge professor Aleksandr Kogan was using Facebook Login in his “research app,” collecting data about its users, and passing it on to Cambridge Analytica, a third party. Cambridge Analytica, in turn, obtained personal information belonging to as many as 50 million Facebook users, through Kogan’s app, and without any express authorization from Facebook. This personal information was subsequently used to target voters and sway public opinion, in ways that benefited the then presidential candidate Trump.

    In response to accusations that this constituted a data breach, Paul Grewal, Deputy General Counsel for Facebook claimed that –

    “The claim that this is a data breach is completely false. Aleksandr Kogan requested and gained access to information from users who chose to sign up to his app, and everyone involved gave their consent. People knowingly provided their information, no systems were infiltrated, and no passwords or sensitive pieces of information were stolen or hacked.”

    Technically speaking, this assessment is probably correct. There was no unauthorized external hacking involved, meaning that Facebook databases were not breached by an outside malicious actor. At the same time, this approach misses the point entirely in terms of user privacy and security. It should not matter for a company like Facebook whether their users’ personal information was forcefully obtained through brute-force, or whether Facebook’s personnel were manipulated to hand in that information to malicious and untrustworthy party.

    Image: Bryce Durbin/TechCrunch

    The cliché goes that humans are the weakest link in cybersecurity, and potentially even the leading cause for the majority of cybersecurity incidents in recent years. This debacle demonstrates that cliché to its full extent. But there is a deeper question here – why are our current data breach notification laws creating this dichotomy between active breaches, where hackers penetrate a database and obtain valuable data, and passive breaches, where humans are being tricked into passing that data into unauthorized hands? After all, the result is the same – users’ private data is compromised.

    Other than empowering State Attorney Generals to investigate and pursue legal action against violating companies, the primary purpose of data breach notification laws is to ensure that if personal information belonging to platform users and service consumers is compromised, then the target of the breach is under obligation to duly notify any person whose data has been leaked. But our current data breach notification system is broken. A good analogy is to say that tn the case of Facebook, these laws only take into account the cybersecurity “walls” surrounding Facebook’s databases, because they only recognize the security perimeter above the surface. What these laws fail to understand, is that there are tunnels underneath the surface accessing Facebook’s databases, where personal information is being extracted from almost unrestrictedly. If our current laws are unable to characterize similar incidents as data breaches, then they are missing their purpose.

    There should be no material difference if the personal information was obtained through a breach or through manipulating and exploiting Facebook’s data ecosystem. The result is the same – user personal information in unauthorized hands. The users should have the right to know, and potentially pursue legal action against Facebook and other involved parties. The distinction currently drawn by data breach notification laws between active and passive breaches should be abandoned, because it provides an incentive for malicious actors to obtain personal data through social engineering, rather than through hacking.

    Just as we expect from companies to invest in cybersecurity to prevent future breaches, we should also expect that they ensure that personal information is shared with thoroughly vetted and trusted parties. The best way to achieve this goal is through direct regulation – amending any data breach related laws to accommodate that. Unfortunately, the tech industry has long resisted such regulation, and created the appearance that its own self-regulation would solve the problem. This has not been effective, since tech companies do not have the incentive to follow their own regulations, and these self-regulations only come after a crises of the Cambridge Analytica sort have already occurred. This creates a reality where users’ data is vulnerable, and companies do not seem to take any preventative measures in response.

    This is a call to amend our current data breach notification laws to encompass personal data obtained through social engineering as a recognized form of data breach. That would not necessarily mean that companies would be under obligation report every personal data leak, but that they will have to employ measures to prevent manipulation techniques from gaining access to personal information, and if such techniques are occasionally successful, that they notify users and consumers in due course, and that appropriate legal action is authorized to ensure compliance. It is up to states to make this happen, because the boilerplate corporate “we care about your privacy” announcements are not working.

    Powered by WPeMatico

    gadgets tech tech crunch
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    geekfenceblogger

    Related Posts

    Top 10 Tech Companies in the World

    2024-01-04

    Exploring the Year: 5 Tech Trends in 2023

    2023-12-30

    Disc-free Xbox One S could land on May 7th

    2019-04-24

    TP-Link EAP225-Outdoor Review

    2019-04-23

    Flying taxis could be more efficient than gas and electric cars on long-distance trips

    2019-04-10

    GPS Rollover is today. Here’s why devices might get wacky

    2019-04-08

    Comments are closed.

    Latest Post

    Unveiling the Architecture Behind OpenAI’s Language Models: The Power of GPT-3

    2024-01-05

    Top 10 Tech Companies in the World

    2024-01-04

    Wanna Lose Weight: Your How to Lose Weight Guide

    2024-01-02

    How to make new year resolutions last?

    2024-01-02
    Stay In Touch
    • Facebook
    • Instagram

    Unveiling the Architecture Behind OpenAI’s Language Models: The Power of GPT-3

    2024-01-05

    In the ever-evolving landscape of artificial intelligence, OpenAI has been at the forefront of cutting-edge…

    Top 10 Tech Companies in the World

    2024-01-04

    Here’s a more inspirational perspective on some of the leading tech companies that are shaping…

    Wanna Lose Weight: Your How to Lose Weight Guide

    2024-01-02

    Losing weight is not just about changing your appearance; it’s about transforming your life and…

    How to make new year resolutions last?

    2024-01-02

    Embarking on a journey of self-improvement through New Year’s resolutions is a powerful and transformative…

    GeekFence
    Facebook Instagram
    © 2025 Geekfence. All Right Reserved

    Type above and press Enter to search. Press Esc to cancel.