Friends Becoming Informants: How your friends are spilling your secrets to Facebook

Email
Personal data: if you won't provide it, Facebook knows someone who will

Big companies make two kinds of announcements. There are RAH RAH RAH HOORAY FOR US announcements designed to get as much attention as possible, and there are the announcements that firms sneak out on a Friday evening when all the European journalists are drunk and the US ones are heading home.

Facebook's blog post about a major security breach falls into the latter category, because Facebook really doesn't want you to think about shadow profiles.

As Violet Blue writes on ZDNet: "The personal information leaked by the bug is information that had not been given to Facebook by the users - it is data Facebook has been compiling on its users behind closed doors, without their consent."

It turns out that if Facebook can't get information about you from you, it'll grab it from your friends instead.

What are shadow profiles?

We've known about shadow profiles for some time: in 2011, Europe vs Facebook filed a complaint against Facebook Ireland with the Irish data protection watchdog (PDF) on the grounds that Facebook was collecting "as much information of users and non-users as possible."

Facebook strenuously denied the allegations at the time, so the leak of shadow profiles must be rather embarrassing.

Here's how it works. Let's say you only put a very basic amount of information on your profile and keep details such as your main email address or your mobile phone number away from Facebook.

If any of your friends have that information and they sync their address books with Facebook, Facebook gets that contact info. If a friend from X university or Y employer searches for you, Facebook knows it's pretty likely that you went to X university or worked at Y employer.

If you aren't on Facebook but somebody's put your details into Facebook's friend finder, those details are now on Facebook.

Facebook isn't the only firm who stores address book details, but others such as Twitter delete the data after 18 months. Facebook doesn't, and it appears to store much more information - and that's none of your business, because other people provided it.

According to Facebook, giving you any control over that information would be a freedom of speech violation.

I'm not sure that's legal, because here in the EU we have pretty solid data protection legislation: it's based on "data minimisation", which is the principle that organisations shouldn't hold more data about you than is strictly necessary. "You should not hold personal data on the off-chance that it might be useful in the future," the Information Commissioner's Office says. Facebook, it seems, is doing exactly that.

I'm not one for conspiracy theories, but this one's a beauty: when you consider that over and above the things you consciously share Facebook can also record your GPS location, the websites you visit and any information your social network contacts have about you, it looks like the sort of thing the security services would just love.

By an interesting coincidence, Facebook's former security chief, a former FBI man who left Facebook in 2010, now works at the NSA.

If you're looking for me, I'm the one in the tinfoil hat.

Carrie Marshall
Contributor

Writer, broadcaster, musician and kitchen gadget obsessive Carrie Marshall has been writing about tech since 1998, contributing sage advice and odd opinions to all kinds of magazines and websites as well as writing more than a dozen books. Her memoir, Carrie Kills A Man, is on sale now and her next book, about pop music, is out in 2025. She is the singer in Glaswegian rock band Unquiet Mind.

Latest in Facebook
The Meta logo on a smartphone in front of the Facebook logo a little bit blurred in the background
Meta's new 'Link History' feature for the Facebook app isn't as protective of your data as it claims
The Meta Quest 3 in action
How much more data can Meta collect? Probably a lot, thanks to the Meta Quest 3 and Ray-Ban smart glasses
A laptop screen showing a Facebook Groups page
Scam alert: how to spot hoax posts in your Facebook Groups
Facebook
Facebook Messenger is losing a useful messaging feature soon
mother watching her daughter's activity online
Meta's new Facebook parental controls show social media still doesn't like responsibility
Phone screen closeup showing the download page for the Facebook app in the app store.
Meta wants to create a Facebook app store to compete with Apple's App Store and Google Play
Latest in News
MacBook Air mute key
The new M4 MacBook Air finally fixes an Apple keyboard annoyance that's been around for decades
A collage of Ellie and Joel in The Last of Us season 2
The Last of Us season 2's new trailer teases a huge showdown between Bella Ramsey's Ellie and Pedro Pascal's Joel, but the big moment I'm waiting for is still being held back
Apple iPhone 16 Pro Max REVIEW
New iPhone 17 Air leak may have revealed some key specs – and how it compares to the iPhone 17 Pro Max
Gaming with AI
I asked Gemini to play a text-based adventure game with me and the AI whisked me away to a word-based fantasy
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price