Facebook Needs to Secure Privacy and Security: 10 Ways to Do It - Security - News & Reviews - eWeek.com | eWeek

Privacy by Default

Privacy by Default
Verfasst von
Fahmida Y. Rashid
Fahmida Y. Rashid
Apr 25, 2011
2 minute read
eWeek Inhalte und Produktempfehlungen sind redaktionell unabhängig. Wir können Geld verdienen, wenn Sie auf Links zu unseren Partnern klicken. Mehr erfahren


Privacy by Default

1

Unlikely.


HTTPS by Default
Users who have turned on the HTTPS option on their accounts are secure knowing that their user data is encrypted, making it difficult for malicious individuals to steal personal information. Facebook buries the option on the setti

2

Mixed. Possibly for mobile, but unlikely for the main pages.


Vetting Applications
There has to be a middle ground between Apple’s App Store and Facebook’s current free-for-all. While it would make the platform less open if Facebook vetted applications, the vast majority of malicious applications w

3

Unlikely


Vetting Application Developers
If not the applications themselves, then the developers should be vetted. Right now, anyone can become a Facebook developer. Security experts say developers should have to meet some basic criteria to qualify to post

4

Low


Advertisement

Two-Factor Authentication
Two-factor authentication secures the login process by forcing users to use something they have (a token, a code-generator program or mobile device) with something they know (the password). It can be expensive. So the sec

5

High, as Facebook is in the process of rolling this out.


6

Moderate. A fix was supposed to be in place, but Facebook did not respond as to whether that fix has finally been implemented.


Controls for Photo Tagging
Currently, users can opt out of letting friends check them into Facebook Places. The ability to tag photos should also be an option that users can control. Giving users a way to restrict how they are tagged in photos wou

7

Unlikely


Secure Facebook Connect
More and more sites are turning on Facebook Connect and users are becoming more comfortable handing over their Facebook login credentials to third-party sites. This opens up the possibility of a rogue Website harvesting log

8

Moderate


Deciding What Apps Can Do
Instead of a blanket Allow on letting applications have access to user data, it should be customizable. Users can choose to add an application that can post to their wall, but not collect their mobile phone nu

9

Low


Real-Time Web Application Protection
There have been a number of cross-site scripting attacks detected in the Facebook API recently, which exposed users to malicious attacks. Facebook could implement proactive real-time Web-application protection

10

Unlikely

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Eigentum von TechnologyAdvice. © 2026 TechnologyAdvice. Alle Rechte vorbehalten

Werbetreibenden-Offenlegung: Einige der auf dieser Website erscheinenden Produkte stammen von Unternehmen, von denen TechnologyAdvice eine Vergütung erhält. Diese Vergütung kann beeinflussen, wie und wo Produkte auf dieser Website erscheinen, einschließlich beispielsweise der Reihenfolge, in der sie erscheinen. TechnologyAdvice schließt nicht alle Unternehmen oder alle auf dem Marktplatz verfügbaren Produkttypen ein.