• Subscribe

    Subscribe to This Week In Panospace by eMail.
    Subscribe in a reader
  • License

    Creative Commons License
    This work is © 2008-2012
    by Yuval Levy
    and licensed under a
    Creative Commons License.
  • Entries

    September 2012
    M T W T F S S
    « Aug   Dec »
  • Archives


Peer pressure to join Facebook has never been stronger.  Much of social life at law school happens through Facebook, but the pressure is not only from students:  friends and colleagues from previous lives are touting Facebook as the promised land of social networking.  While I generally agree that social networking tools can add to one’s personal and professional life, it does not have to be Facebook.  I am using, amongst others, LinkedIn, Vimeo, and this blog.  There are many reasons why I don’t use Facebook.  A few of them are below, excerpt from an online conversation with a fellow photographer.

Q: Facebook is so great, you do not know what you are missing!  Why don’t you join us?

A: If it works for you, good for you.  I tried it in the past and it did not work for me.  My attitude to Facebook is: join it if you like it, but do not force others to join it.  By publishing your content exclusively on Facebook you make a conscious decision to exclude people like me who, for whatever reason, have decided not to use Facebook.  It is your right and I am at peace with your choice, just do not expect me to join Facebook for you, no matter how cool you think your Facebook presence is.  If Facebook is the only way to join, then I am not meant to join.  I am not singling out Facebook:  if Youtube is the only way to join, I won’t join that either.  On the other hand, if you cater to users of many different social networks, I might consider joining.  Ultimately it is you who decide to limit yourself when you choose to ignore that there are other tools out there, some of which offer better interoperability enabling you to reach a wider audience.

Q: You are missing on plenty of opportunities such as potential jobs and customer!

A: If I was looking to source a service, I would be stupid to limit myself to Facebook.  The same applies for the sourcing of a product from other sites such as eBay or Amazon.  The appeal of clusters — markets, industry associations, social networking sites — is undeniable, but restricting the choice to one single cluster is not smart and audience size is not the only factor to consider when selecting which clusters to address.  While at the time of this writing Facebook can boast the largest audience,  it is not necessarily the most relevant audience for every situation.  For jobs I would rather post and search on LinkedIn and Monsters.com; and for more specific visual art skills I will rather use sites such as DeviantArt, Behance, and Flickr.  Facebook can actually have a negative impact on business opportunities since it exposes aspects of a person’s life that have no place in a professional environment and are more likely to harm the person’s prospects of landing a contract or a job than helping those prospects.  Facebook is not the golf club.

Q: Why such hostility toward Facebook?

A: It is not so much hostility as it is indifference.  Given my previous experience with it I consider Facebook to be at best a waste of time.  Given its track record I do not expect it to contribute anything meaningful to my life.  Personally I would not trust any information, not even public information, to an outfit that

  1. has a privacy policy that is longer to read than the US declaration of independence and yet does not respect basic privacy tenets such as allowing users to easily close and delete their account;
  2. has such a dismal record when it comes to respect for its users;
  3. was born and is still driven by and built on the evil intent of taking advantage of ordinary people’s personal information even in situation when this use results in a significant material disadvantage for the concerned people.

Q: Why do you think that Facebook is intrinsically more evil than Google, Apple, Yahoo, Microsoft, your bank, credit cards, phone company, internet service provider, government, big business, etc.?

A: The fact that I use other suppliers and not Facebook does not mean that I think that Facebook is intrinsically more evil than them, just that they serve my needs better than Facebook.  That said, I see a significant difference between Facebook and the other entities mentioned above: the interest alignment between users and customers.  For most of the above businesses, the users are also the customers or at least an important customers class.  Facebook’s customers are the marketers and others with an interest in spying on its users.  Faced with a trade-off between the interests of its paying customers against the interests of its non-paying users, Facebook naturally aligns itself with the interests of its paying customers.  The users are simply the cattle that Facebook delivers to its customers.  Where the other businesses have other sources of income than those conflicting with the users’ interests, Facebook has not and consequently has little to lose in behaving the way it does.

Q: Do you really think that Facebook can somehow extract your personal information other than that which you provide it, the required name, email and date of birth which you have most likely already provided to all of the businesses mentioned in the previous question?

A:  You might have provided the information yourself, but was it voluntary?  Read this short ZDNet blog post for a basic explanation of how Facebook collects a lot of data from you and a pointer to a solution by highly reputed German technology publishing house Heise.  For a more detailed understanding, let me guide you step by step in the process of how your information leaks to Facebook:

  1. You enter the URL of a website you want to visit into your browser.
  2. Your browser sends a request to the server associated with that URL.  The request includes your IP address (which can be associated with a geographic location and other information that pieced together generates a unique fingerprint to identify you.  If you are using a mobile browser, the GPS coordinates are likely to be sent too.
  3. The server sends back instructions to your browser how to build the requested page for display.  Unless the website does what is described in the above ZDNet blog post (most websites do not), those instructions usually include fetching content such as images and scripts, or Facebook’s “like”-button, from third-party servers.
  4. If your web browser is not protected with tools like RequestPolicy and NoScript (most browsers are not) it will request these third-party images and script.  In the process it will leak your IP address, web browser fingerprint, GPS coordinates and the website that you are visiting to the third party, i.e. to Facebook if the request is for a “like”-button.
  5. With enough sites enrolled in the scheme, i.e. enough sites displaying a Facebook “like”-button (or a Google+ button, they are all the same), the third party server that sends you the “like”-button will record your browsers visits many times per day and record a complete and extensive breadcrumbs trail for your online activity over an extended period of time.  You don’t need to be logged into any account for this to happen, but when you do log in, personal data gets associated with the trail.  IP addresses do not change often, unless you are using The Onion Router (very few users do).  Even if you set the do-not-track header (which Microsoft, kudos to them, has set by default in Internet Explorer 10), there is no guarantee that the other end will respect your request.
  6. From the above information, a data-miners like Facebook or Google (yes, others do it too) obtain a very detailed picture of your online activity and probably know you better than your parents.  GeoIP information is used to connect the online trail to physical locations.  Fingerprinting techniques are used to distinguish individual browsers (an approximation for individual persons).  The moment you log in with your profile, the crumbs trail gets associated to it.  Log in with other profiles on other sites and they might get associated as well.  Public records such as phone books and land registries are used to enrich the data with physical locations and phone numbers.  Census data and other information about the neighbourhood is used to enhance the information.  If you check in on sites such as FourSquare, the data collection will include detail of some of your offline habits as well, although an “anonymous” GPS track from your mobile device coupled with static map data is already enough to figure out where (and with whom) you are hanging out.  If you log on from work or from campus, or just display a website with a visible “like”-button or an invisible web-beacon that has the same spying functionality from such locations, your workplace becomes also known to the data miner.  Ultimately, the profiles they keep about ordinary people are more detailed than the profiles that the FBI keeps about persons of interest.

Q: Does anyone here actually believe that their name, email and date of birth, as well as general interests such as photography are somehow otherwise unknown to the powers that be ?  Seriously ?

A: It depends on your behaviour, online an offline.  Marketers have asked questions since long before the internet and generally people tend to be trusting and willing to share, so probably your statement is right most of the cases.  That said, identity theft is such an endemic problem nowadays because the marketers do not secure their databases properly and questionable individuals break into them to steal all of this valuable personal information.  Date of birth is something you should keep for the state and for financial institutions.  Other businesses may have a legitimate need to ascertain that you are of legal age.  There is no need to give them the exact (identifying!) birth date.  Give them a bogus birth date that makes you slightly younger and you are safe.  I generally recommend not to volunteer information to marketers, whether it is on websites, product registration forms, or sweepstakes, because their interests are not aligned with yours.  All they want is your money.  If a business insists on personal details that are not necessary to close the transaction, bring your business elsewhere.


The school year is around the corner and more pressure to join Facebook is likely.  If you are happy with Facebook, good for you.  I will not adopt Facebook any time soon.  Just the memory of how difficult it was to close the previous account is deterrent enough:  they did not let me close the account unless I manually removed every piece of information from it first.  Having been through that, I do not want to do it again.

4 Responses

  1. No, wait. You wrote all of that out of, er, indifference? :)

  2. @Alexandre: I am not indifferent to my friends nagging me about getting on Facebook, hence I explain to them why I am indifferent to Facebook :)

  3. methinks thou dost protest too much ;)

    this comment was posted via facebook login button on your site btw

  4. @Sam:You can use Facebook login to identify yourself to the WordPress.com site. It is not my site, and even if it was I fail to see why it should matter that you identified yourself with your Facebook login. Unlike Facebook (which keeps users without FB accounts out of their walled gardens) this blog is accessible to the anonymous reader.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )


Connecting to %s