To read this content please select one of the options below:

A look into user privacy andthird-party applications in Facebook

Sovantharith Seng (Rochester Institute of Technology, Rochester, New York, USA)
Mahdi Nasrullah Al-Ameen (Utah State University, Logan, Utah, USA)
Matthew Wright (Rochester Institute of Technology, Rochester, New York, USA)

Information and Computer Security

ISSN: 2056-4961

Article publication date: 26 July 2021

Issue publication date: 3 August 2021

364

Abstract

Purpose

A huge amount of personal and sensitive data are shared on Facebook, which makes it a prime target for attackers. Adversaries can exploit third-party applications connected to a user’s Facebook profiles (i.e. Facebook apps) to gain access to this personal information. Users’ lack of knowledge and the varying privacy policies of these apps make them further vulnerable to information leakage. However, little has been done to identify mismatches between users’ perceptions and the privacy policies of Facebook apps. This paper aims to address this challenge in the work.

Design/methodology/approach

The authors conducted a lab study with 31 participants, where the authors received data on how they share information on Facebook, their Facebook-related security and privacy practices and their perceptions on the privacy aspects of 65 frequently-used Facebook apps in terms of data collection, sharing and deletion. The authors then compared participants’ perceptions with the privacy policy of each reported app. Participants also reported their expectations about the types of information that should not be collected or shared by any Facebook app.

Findings

The analysis reveals significant mismatches between users’ privacy perceptions and reality (i.e. privacy policies of Facebook apps), where the authors identified over-optimism not only in users’ perceptions of information collection but also in their self-efficacy in protecting their information in Facebook despite experiencing negative incidents in the past.

Originality/value

To the best of the knowledge, this is the first study on the gap between users’ privacy perceptions around Facebook apps and reality. The findings from this study offer direction for future research to address that gap through designing usable, effective and personalized privacy notices to help users to make informed decisions about using Facebook apps.

Keywords

Acknowledgements

Authors would like to thank Rochester Institute of Technology students and staff members for participating in this study. Authors would also like to thanks the reviewers for their valuable feedback. This material is based upon work supported by the National Science Foundation under Awards No. 1949694.

Citation

Seng, S., Al-Ameen, M.N. and Wright, M. (2021), "A look into user privacy andthird-party applications in Facebook", Information and Computer Security, Vol. 29 No. 2, pp. 283-313. https://doi.org/10.1108/ICS-08-2019-0108

Publisher

:

Emerald Publishing Limited

Copyright © 2021, Emerald Publishing Limited

Related articles