In the wake of yet another privacy controversy, Facebook is planning to use encryption to block third-party application providers from sharing user-identification numbers. The exposure was revealed earlier this week, and Facebook is moving quickly to avoid a new wave of criticism.
A Wall Street Journal investigation discovered that many of the most popular Facebook apps have been delivering personal identifying information — including names, and sometimes friends’ names — to advertising and Internet-tracking companies. The Journal estimated tens of millions of Facebook app users — even those who chose the strictest privacy settings — aren’t aware that their information has been shared.
With some in the privacy industry suggesting that Facebook is unable to control what goes on under its social-networking banner, the company promised to take steps to thwart those third-party applications, which include many of the top 10 games people play on the site.
Facebook’s Dilemma
“The proposal builds on our recent support for a parameter called signed request, which is inspired by our discussions in the OAuth community,” Mike Vernal, a Facebook engineer, wrote on the company’s developer blog. “We will start encrypting this parameter as well, using the application’s secret key, so that only the application will be able to read this information. This will prevent the accidental disclosure of information via HTTP headers.”
“Our plan is to enable parameter encryption as an option over the next few weeks and to then work with the community to add support for this option to the various Facebook SDKs,” he continued. “Once the design is finalized, we will work with our developers to ensure a speedy transition to encrypted parameters.”
Facebook had to move fast. In the days since the Journal report, a lawsuit has been filed against Zynga, the maker of some of the games that are transmitting personal information. Facebook…