Beyond the Glass House: Why Facebook and Google+ Fail the Privacy Test
2405_Who needs Facebook or Google+ anyway privacy and sociality in social network sites.
This keynote paper explores the conflict between privacy and social utility in Social Network Sites (SNS), specifically analyzing the structural flaws of Facebook and Google+. It introduces "Clique," a privacy-preserving SNS developed under the EU FP7 project PrimeLife, as a functional alternative to current commercial architectures.
TL;DR
Privacy in social networks isn't just about "who can see my posts"—it's about the fundamental architecture of our digital identities. This paper by Ronald Leenes argues that the business models of tech giants are diametrically opposed to genuine privacy. While Google+ tried to fix Facebook's "openness" with Circles, both fall short by aiming to become global "Identity Hubs." The solution lies in architectures like Clique that support audience segregation and partial identities.
The Core Conflict: Architecture as Destiny
The central thesis of Leenes' work is that privacy failures in SNS are not accidental bugs; they are features of the business model.
- The Transparency Bias: Facebook’s architecture is inherently biased toward maximum disclosure to fuel its ad-driven engine.
- The Identity Hub Trap: By using "Facebook Connect" or "Google Accounts," these platforms transition from simple social sites to mandatory identity providers (IDPs), tracking users across the entire web.
The author argues that human beings naturally operate through partial identities—we are different people to our parents than we are to our colleagues. Current SNS force a "flattening" of these identities, leading to the "wrong audience" problem.
Methodology: From Circles to Clique
Leenes evaluates current solutions and introduces a more robust alternative:
- Google+ Circles: Acknowledged as an improvement for "audience segregation," but ultimately flawed because it remains tied to a centralized identity that Google uses for cross-service tracking.
- Clique (The PrimeLife Project): This is a privacy-preserving SNS architecture. Unlike commercial platforms, Clique is designed to facilitate sociality without requiring a singular, transparent identity. It allows users to maintain cryptographic boundaries between different social roles.
Note: The author emphasizes that the structural design of the platform dictates the social behavior and privacy levels achievable by the user.
Critical Analysis: The Business of Identity
The most striking insight in this keynote is the critique of Identity Management (IDM). When a social network becomes your "digital passport" for other websites, privacy becomes impossible. The paper warns that:
- Individuals lose the ability to remain anonymous or pseudonymous.
- Service providers gain access to rich user profiles that users never intended to share with them.
- True "sociality" requires the safety of knowing your data stays within the intended context.
Conclusion and Future Outlook
Ronald Leenes reminds us that "Who needs Facebook?" is not just a rhetorical question—it is a call for a technical and legal shift.
Key Takeaways:
- Technical Inductive Bias: Architectural choices in SNS are not neutral; they reflect the commercial interests of the provider.
- Audience Segregation: This is the "Gold Standard" for privacy that current platforms are failing to provide.
- Digital Sovereignty: We must move toward decentralized identity systems where the user, not the provider, controls the flow of information across social contexts.
While Google+ may have faded into history since this paper was published, the core problem of "Identity Hubs" has only intensified with the rise of the "Log in with..." economy, making Leenes' analysis more relevant today than ever.
