Unmasking the Degree of Online Self-Disclosure (DOSD): A Deep Dive into Social Network Secrecy
Your privacy information are leaking when you surfing on the social networks: A survey of the degree of online self-disclosure (DOSD)
This paper presents a quantitative survey on the Privacy Information Leakage problem within the "Pengyou" social network in China. By deploying eight fake profiles and collecting 2,761 user profiles, the authors introduce the Degree of Online Self-Disclosure (DOSD) metric to measure user vulnerability and SOTA levels of information exposure.
TL;DR
In a world where digital connection is currency, personal privacy is often the price. This paper explores the Degree of Online Self-Disclosure (DOSD) within one of China's legacy social giants, Pengyou. By deploying fake users to befriend strangers, the researchers discovered that the vast majority of users—especially young adults—are essentially handing over their digital lives to unknown entities, revealing a systemic vulnerability in human trust rather than just platform code.
The Core Conflict: Privacy vs. Participation
The authors address a fundamental tension in Online Social Networks (OSNs): Information exposure is a double-edged sword. While self-disclosure facilitates friendship and social influence, it simultaneously arms malicious actors with data for stalking, phishing, and "Human Power Search" (cyber-manhunts).
The specific problem identified is the "ease of entry." If a stranger sends a friend request, how much information does the average user inadvertently sign away? The study focuses on the Chinese demographic, which at the time of writing, lacked the rigorous privacy awareness reported in contemporary Western studies (e.g., PEW reports).
Methodology: The "Fake Friend" Experiment
To measure real-world vulnerability, the researchers didn't just theorize—they simulated an attack. They created eight fake profiles across different age brackets (17, 23, 27, and 35) and genders.
The DOSD Metric
The technical heart of the paper is the definition of DOSD (Degree of Online Self-Disclosure).
- Field Leakage (): A binary indicator of whether a specific field (like 'Birthday' or 'Phone') is visible.
- DOSD (): The sum of leaked fields divided by the total number of possible fields.
Fig 1: Percentage of information leakage across various categories. Note the high visibility of Hobbies (90%) and Occupation (89%).
Experimental Insights: Who is Most at Risk?
The results provide a fascinating demographic breakdown of digital vulnerability:
- Peak Exposure: Young adult males (18-25) and females (26-30) exhibited the highest DOSD, reaching over 77-81%.
- The "Stranger Danger" Paradox: Despite the fake accounts having cartoon or pet photos (not real people), they gained 2,761 "friends" in just 30 days.
- Visual Over-disclosure: Users shared 26,767 photographs with these fake accounts, including photos of their homes, workplaces, and children.
Fig 2: The distribution of average DOSD. Younger adults show a significantly higher propensity to disclose than those over 30.
Critical Analysis: The Human Element
The most striking takeaway from this work is that tech-centric solutions are insufficient. The researchers argue that "no matter what the OSN providers do... the user himself" remains the entity with the power to nullify privacy.
Key Threats Identified:
- Advertising and Spam: 65% of users leaked emails, providing a goldmine for spammers.
- Organizational Risk: 68% provided company info, enabling corporate espionage and "Advanced Persistent Threats" (APTs).
- Minor Safety: Minors frequently accepted requests from 35-year-old fake accounts, highlighting a critical lack of predatory protection.
Future Outlook & Mitigations
The paper suggests several practical steps to curb this leakage:
- Owner Confirmation: Mandatory approval for tags and profile annotations.
- Third-Party Audits: Tools like Ghostery to help users visualize their own "privacy footprint."
- Gamified Training: Interactive curricula to teach new users about privacy settings before they start befriending strangers.
Conclusion
While this study was conducted in a specific era of the Chinese internet, its core thesis—that human trust is the ultimate zero-day vulnerability—remains more relevant than ever in the age of AI-driven social engineering. As users, we must realize that every "Accept" button is a potential breach of our real-world security.
