The Architecture of Invisibility: Reasoning About What You Cannot Control in Social Networks
Privacy settings in social networking systems: what you cannot control
The paper introduces an ontology-based framework using OWL (Web Ontology Language) to formally analyze the completeness of privacy control policies in Social Networking Systems (SNSs). It defines formal notions of "Completely Controllable" and "Completely Known" to identify gaps between user-ideal privacy protections and actual SNS settings, validated through a Facebook case study.
TL;DR
Social Networking Systems (SNSs) like Facebook give users the illusion of control through privacy dashboards, but a vast amount of sensitive data is actually governed by opaque, hard-coded system policies. This paper proposes a formal ontology-based framework to map out these "missing policies." By reifying data relationships into protectable resources, the authors prove that Facebook’s privacy settings are fundamentally incomplete, failing to let users control basic actions like who sees their "Likes" or friendship links.
The "Illusion of Control" Problem
When you adjust your Facebook settings, you are interacting with a subset of the system's access control logic. However, existing research (and common user frustration) shows:
- Fixed Rules: Many data interactions are governed by fixed rules the user can never change.
- Lack of Transparency: System-defined policies are buried in help pages or inferred through trial and error.
- Complexity: As information becomes more interconnected (tags, check-ins, wall posts), the "surface area" of privacy-sensitive data grows beyond what a simple toggle switch can manage.
Methodology: Reifying the Social Graph
The authors suggest that we shouldn't just protect "objects" (like a photo), but the relationships (properties) between objects.
1. The SNS Ontology
They model the SNS using OWL (Web Ontology Language), categorizing data into Users, DigitalObjects, and Annotations. This allows for a granular hierarchy (e.g., a UserTag is a specific type of Annotation).
Figure 1: The formal model of Facebook's concepts and properties.
2. Property Reification
To assign permissions to relationships (which OWL doesn't natively support as "resources"), the authors use reification. They turn a property (e.g., "Alice owns Photo1") into a class (ReifiedProperty). This makes it possible to write a rule like: "Only Alice can 'Select' (view) the relationship where 'Alice owns Photo1'."
3. The Completeness Logic
The framework compares three sets of permissions:
- S (Settings): What you can control.
- D (Described): What the system says it does.
- I (Ideal): What should be protected (anything relating to you or your objects).
If , then the system is incomplete.
Case Study: Analyzing Facebook
The authors applied this to Facebook’s policy landscape circa 2013. Even with Facebook’s extensive settings, the results were a definitive "Fail."
Figure 2: The intersection of Ideal, Setting, and Described permissions.
Key Findings:
- The M-Gap (Missing Policies): The authors identified several critical missing controls. For example, while you can control who sees your posts, you often cannot control the visibility of the "fact" that you liked something or that you are friends with someone (Permissions M2 and M4).
- Policy Asymmetry: If Bob tags Alice in a photo, Alice has limited control over the creation of that tag compared to her control over her own photos.
Critical Insight: Why This Matters Today
While this paper was published in 2013, its core insight is more relevant than ever in the age of AI and massive data scraping. The "Missing Policies" identified here are exactly what data brokers and scrapers exploit.
Limitations: The framework relies on the researcher accurately modeling the SNS ontology and the user's "Ideal Policies." If the ontology is too simple, the analysis will miss subtle privacy leaks. Furthermore, automated discovery of these missing policies remains a computational challenge for future work.
Conclusion
This work formalizes the intuition that we are not masters of our own digital shadows. By moving from a "file-folder" view of privacy to a "relationship-link" view, the authors provide a rigorous methodology for auditing social platforms. It challenges SNS developers to move beyond "Privacy Dashboards" and toward provable privacy coverage.
