A look into user privacy andthird-party applications in Facebook
Information and Computer Security
ISSN: 2056-4961
Article publication date: 26 July 2021
Issue publication date: 3 August 2021
Abstract
Purpose
A huge amount of personal and sensitive data are shared on Facebook, which makes it a prime target for attackers. Adversaries can exploit third-party applications connected to a user’s Facebook profiles (i.e. Facebook apps) to gain access to this personal information. Users’ lack of knowledge and the varying privacy policies of these apps make them further vulnerable to information leakage. However, little has been done to identify mismatches between users’ perceptions and the privacy policies of Facebook apps. This paper aims to address this challenge in the work.
Design/methodology/approach
The authors conducted a lab study with 31 participants, where the authors received data on how they share information on Facebook, their Facebook-related security and privacy practices and their perceptions on the privacy aspects of 65 frequently-used Facebook apps in terms of data collection, sharing and deletion. The authors then compared participants’ perceptions with the privacy policy of each reported app. Participants also reported their expectations about the types of information that should not be collected or shared by any Facebook app.
Findings
The analysis reveals significant mismatches between users’ privacy perceptions and reality (i.e. privacy policies of Facebook apps), where the authors identified over-optimism not only in users’ perceptions of information collection but also in their self-efficacy in protecting their information in Facebook despite experiencing negative incidents in the past.
Originality/value
To the best of the knowledge, this is the first study on the gap between users’ privacy perceptions around Facebook apps and reality. The findings from this study offer direction for future research to address that gap through designing usable, effective and personalized privacy notices to help users to make informed decisions about using Facebook apps.
Keywords
Acknowledgements
Authors would like to thank Rochester Institute of Technology students and staff members for participating in this study. Authors would also like to thanks the reviewers for their valuable feedback. This material is based upon work supported by the National Science Foundation under Awards No. 1949694.
Citation
Seng, S., Al-Ameen, M.N. and Wright, M. (2021), "A look into user privacy andthird-party applications in Facebook", Information and Computer Security, Vol. 29 No. 2, pp. 283-313. https://doi.org/10.1108/ICS-08-2019-0108
Publisher
:Emerald Publishing Limited
Copyright © 2021, Emerald Publishing Limited