Unmasking the Invisible: How Your Social Network Profile Leaks Your Identity

Personally identifiable information leakage through online social networks

2013-10-01
Candice Louw, Sebastiaan H. von Solms
Summary
Problem
Method
Results
Takeaways
Abstract

The paper introduces a prototype software model developed in NetLogo designed to analyze and visualize the leakage of Personally Identifiable Information (PII) on Online Social Networks (OSNs), specifically Facebook. It identifies how default security settings and information deduction (e.g., inferring gender from a name) expose users to cyber threats like identity theft and Advanced Persistent Threats (APTs).

TL;DR

Social networking convenience often comes at a steep security cost. This paper introduces a specialized prototype model built in NetLogo to visualize how Personally Identifiable Information (PII) "leaks" through Facebook. By simulating the paths that "Friends," "Friends of Friends," and the "Public" take through your data, the study demonstrates that even if you don't post your gender or location explicitly, they can be deduced with alarming ease, turning users into easy targets for cyber criminals.

The "Invisible" Danger: Why Privacy Settings Aren't Enough

The core challenge in OSN security is that users often view their profiles through a social lens—sharing photos and updates to connect—while attackers view them as a data mine. The authors identify a phenomenon called Information Deduction. This is the process where pieces of non-sensitive data are combined to reveal highly sensitive identity markers. For instance, sharing a "clear avatar photo" and your "real name" allows a third party to deduce your gender and potentially your ethnicity or age, even if those fields are set to private.

Methodology: Visualizing the Leakage

To make these invisible threats tangible, the researchers developed a model using NetLogo. The model treats every piece of shareable information as a "node."

  • Direct Access: Represented by solid lines, showing who can see what based on current settings.
  • Information Deduction: Represented by dashed lines, showing what an attacker can guess based on what you've shared.
  • Vulnerability Rating: The model simulates "viewers" navigating these links. Nodes that are visited more frequently grow larger, visually representing a higher vulnerability.

Model Architecture and Initial Setup Figure: The setup shows how a public name (Direct Access) allows for the deduction of gender (Dashed Leakage Line).

The Mechanics of Deduction

The model highlights specific logical pairs that lead to leakage:

Information SharedPossible Deductions
Avatar PhotoGender
NameGender
PhotosGender, Friends list, Location details
Activities/EventsRoutine Location Information

Critical Findings: The Default Setting Trap

The research investigated Facebook due to its global dominance. A staggering realization was the difference between "Non-OSN" and "OSN" perspectives:

  1. Non-OSN Perspective: Even without an account, search engines can often index your name and profile picture. This is enough to provide the "seed" for further identity deduction.
  2. Internal OSN Perspective: Once a user is "logged in" to the network (even if not your friend), default settings often expose almost everything—friend lists, albums, and location tags.

Full Information Exposure Simulation Figure: A simulation of complete public access, highlighting the massive "attack surface" available to a malicious actor.

Impact: Identity Theft and Cyber Espionage

The paper warns that these leaks aren't just a personal nuisance; they are a corporate threat. Advanced Persistent Threats (APTs) often start with social engineering. By harvesting PII from an employee's OSN profile, attackers can craft highly convincing phishing messages or find leverage (extortion/blackmail) against disgruntled staff to gain access to corporate networks.

Conclusion and Future Outlook

The study concludes that "User Awareness" is the only true defense. While platforms like Facebook have updated their privacy interfaces since this study's publication (2013), the underlying logic of Information Deduction remains a cornerstone of modern cybercrime.

Takeaway: If you haven't audited your "Public View" settings lately, you might be providing a roadmap for identity thieves. The "invisible nature" of information deduction means that "what you don't say" can still be "heard" by the right algorithm.

Limitations

While effective as a visualization tool, the prototype relies on user-reported answers to questions rather than automated API scraping. Future iterations would benefit from real-time data ingestion to provide a more accurate "Security Score."

Find Similar Papers

Try Our Examples

  • Find recent papers that utilize graph theory or agent-based modeling to simulate PII leakage in modern decentralized social networks.
  • Which seminal research first defined the "87% identity uniqueness" metric for PII combinations, and how has this changed with the advent of AI-driven data scraping?
  • Explore how contemporary "Privacy-Enhancing Technologies" (PETs) have been integrated into OSN interfaces to mitigate the information deduction risks identified in this prototype.
Contents
Unmasking the Invisible: How Your Social Network Profile Leaks Your Identity
1. TL;DR
2. The "Invisible" Danger: Why Privacy Settings Aren't Enough
3. Methodology: Visualizing the Leakage
3.1. The Mechanics of Deduction
4. Critical Findings: The Default Setting Trap
5. Impact: Identity Theft and Cyber Espionage
6. Conclusion and Future Outlook
6.1. Limitations