<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.theindustrystandard.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>The Industry Standard - Facebook bug leaks members&amp;#039; birthday data - Comments</title>
 <link>http://www.theindustrystandard.com/news/2008/07/16/facebook-bug-leaks-members-birthday-data</link>
 <description>Comments for &quot;Facebook bug leaks members&#039; birthday data&quot;</description>
 <language>en</language>
<item>
 <title>Facebook bug leaks members&#039; birthday data</title>
 <link>http://www.theindustrystandard.com/news/2008/07/16/facebook-bug-leaks-members-birthday-data</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;
&lt;p&gt;A glitch in a test version of Facebook&#039;s Web site inadvertently exposed the birthdays of Facebook&#039;s 80 million members this week.&lt;/p&gt;
&lt;p&gt;The bug was &lt;a href=&quot;http://www.sophos.com/pressoffice/news/articles/2008/07/facebook-birthday.html?_log_from=rss&quot; rel=&quot;nofollow&quot;&gt;discovered&lt;/a&gt; over the weekend by Sophos Senior Technology Consultant Graham Cluley. While checking out Facebook&#039;s &lt;a href=&quot;http://www.new.facebook.com/&quot; rel=&quot;nofollow&quot;&gt;new design&lt;/a&gt;, Cluley noticed that the birth dates of some of his privacy-obsessed acquaintances were popping up when they should have been hidden. &lt;/p&gt;
&lt;p&gt;Facebook allows users to control who sees private information such as their birth date, which can be a valuable nugget of data for identity thieves. But Cluley discovered that the new site was making this information public to other members. &quot;Their new profile page essentially ignored the privacy setting to withhold the data of birth,&quot; he said.&lt;/p&gt;
&lt;p&gt;&quot;For a brief period of time, a small number of users were able to access a private beta of Facebook&#039;s new site design meant only for developers. During that time, some of those users had their birthdays revealed due to a bug,&quot; Facebook said Wednesday in a statement. The company could not say exactly how long this data was exposed or how many people viewed the beta site, but the bug was patched within hours of Cluley&#039;s discovery.&lt;/p&gt;
&lt;p&gt;Facebook may intend for the beta site to be private, but it has been open to the &lt;a href=&quot;http://developers.facebook.com/news.php?blog=1&amp;amp;story=129&quot; rel=&quot;nofollow&quot;&gt;general public&lt;/a&gt; for several days.  It features a new profile design that should be rolled out as an option to Facebook users some time this week.&lt;/p&gt;
&lt;p&gt;Cluley himself did not consider this a major data breach, but he said it should serve as a warning to people who put a lot of information on social networks. &quot;It raises a more serious question which is, &#039;Can you trust these social networks to look after your data properly?&#039;&quot; he said. &lt;/p&gt;
&lt;p&gt;Facebook is sensitive about privacy. In November the company scrambled to fix its Beacon ad system after a CA researcher discovered that the system was collecting data on users&#039; online behavior, despite Facebook&#039;s assurances to the contrary.&lt;/p&gt;
&lt;p&gt;&quot;With Beacon we just screwed it up,&quot; said Matt Cohler, the company&#039;s vice president of product management, during a March session with reporters.&lt;/p&gt;
&lt;p&gt;Cluley isn&#039;t sure that won&#039;t happen again. He&#039;s telling his friends to just make up a birth date on Facebook from now on.&lt;/p&gt;
</description>
 <comments>http://www.theindustrystandard.com/news/2008/07/16/facebook-bug-leaks-members-birthday-data#comments</comments>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/1604">Data Breach</category>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/2105">Data protection</category>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/1402">IDGNS</category>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/1531">Internet</category>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/1428">Security</category>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/1607">Sites</category>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/1681">Social Networking</category>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/5667">Software &amp;amp; Web</category>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/98">Breaking News</category>
 <pubDate>Wed, 16 Jul 2008 16:10:39 -0700</pubDate>
 <dc:creator>IDG News Service</dc:creator>
 <guid isPermaLink="false">109843 at http://www.theindustrystandard.com</guid>
</item>
</channel>
</rss>
