Don’t do SECURITY. Do business SECURELY.

Popular Facebook apps found passing user IDs to advertisers

A Wall Street Journal investigation found popular Facebook apps, including FarmVille, were sending users' identifying IDs to advertising and tracking firms.

A Wall Street Journal investigation reported that many of the most popular Facebook applications were transmitting users’ unique Facebook IDs to advertising and internet tracking companies. The IDs could be used to look up users’ names and, in some cases, information about their friends.

What happened

  • Apps named in reporting included Zynga’s FarmVille and several apps from LOLapps.
  • The Journal said the issue affected tens of millions of Facebook app users.
  • Facebook said the leakage was largely caused by how browsers pass referrer information, and that it would work with developers to fix it.
  • US lawmakers wrote to Facebook and MySpace seeking explanations of how user information was shared with third parties.

Why it mattered

The story put a spotlight on how personal data flowed from social platforms through third-party apps to advertisers, a theme that would return on a far larger scale with Cambridge Analytica in 2018.

Lessons for organisations

Check what data your websites and apps leak to third parties, including through URLs, referrer headers, and embedded tracking code. Supplier and developer agreements should limit how shared personal data can be used.

Source: Forbes

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights