BOSTON--()--IT security and data protection firm Sophos today responded to Facebook’s announcement of what were declared to be “drastically simplified” privacy controls. Facebook announced these controls at an event today in Palo Alto, CA. Overall, Sophos sees any move to give users more control of how their personally identifiable information is shared as a positive step – but it must be made clear that Facebook’s privacy policies remain unchanged. As such, with the information of nearly 500 million users and a track record of “share first, ask permission later,” these moves must be analyzed critically. The points in today’s announcement that Sophos finds most interesting and telling include:
“The wild popularity of Facebook both plays to, and preys on, a willingness for people to connect and share their lives”
- Dramatically simplified control of your information. The new privacy page appears to clear up confusion about what data users share with others.
- The Facebook platform will provide full opt-out, Instant Personalization opt-out, and granular controls per application.
- There are no fundamental changes to actual privacy. Defaults remain to share with everyone and include instant personalization
- While simplification is important, not selecting secure and private defaults is equal to no meaningful privacy change.
A longer version of Sophos’ reaction can be found at Sophos Senior Security Advisor, Chet Wisniewski’s blog.
“The wild popularity of Facebook both plays to, and preys on, a willingness for people to connect and share their lives,” said Wisniewski. “In watching this drama play out, the fundamental conflicts between self defense and self promotion, as well as privacy and profit, are painfully apparent in Mark Zuckerberg’s Washington Post editorial. While he may believe Facebook was ‘moving too fast’ in terms of innovation, the maddeningly slow speed at which they reacted to user dissatisfaction is the real core issue. While we laud some of the steps that Facebook has taken today, we emphasize that the community must remain vigilant and maintain a critical eye on any change that is made, to ensure that improvements continue and that gains are not lost.”
Key Resources
- Facebook: The privacy challenge (earlier blog and podcast discussion)
- Sophos's previous recommendations for Facebook settings
- How to choose a strong password - simple tips for better security (video)
- Facebook Privacy Scanner
Additional Reading/Content
- 60% of Facebook users consider quitting over privacy
- Facebook - Promises, malware, and spam, part 1
- Facebook responds privately - Too little, too late?
- Facebook leaks more private data: déjà vu all over again
- Rumours of Facebook privacy changes - but will it be too little too late?
- Distracting Beach Babes video attack hits Facebook users
- Sophos Security Threat Report 2010
About Sophos
More than 100 million users in 150 countries rely on Sophos as the best protection against complex threats and data loss. Sophos is committed to providing security and data protection solutions that are simple to manage, deploy and use and that deliver the industry’s lowest total cost of ownership. Sophos offers award-winning encryption, endpoint security, web, email, and network access control solutions backed by SophosLabs – a global network of threat intelligence centers. With more than two decades of experience, Sophos is regarded as a leader in security and data protection by top analyst firms and has received many industry awards.
Sophos is headquartered in Boston, US and Oxford, UK. More information is available at www.sophos.com.

