Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
The Dutch government is clamping down on the way in which large organisations use its citizen's personal data.
The Dutch Data Protection Authority (DPA) threatened Google with a fine of €15m (£11.9m, $18.7m) on Monday, saying the search giant had breached various provisions of the Dutch data protection act via a privacy policy it introduced in 2012.
The company has been given until the end of February 2015 to change how it handles personal data, especially in regard to the tailoring of adverts based on keyword search queries, video viewing habits, location data and the content of email messages.
Jacob Kohnstamm, chairman of the Dutch DPA, said:
Google catches us in an invisible web of our personal data without telling us and without asking us for our consent. This has been ongoing since 2012 and we hope our patience will no longer be tested.
Kohnstamm explained how, under Dutch law, Google should have informed users that it was gathering data across a number of platforms - such as YouTube and Gmail - and obtained permission before combining or analysing that data.
The regulator has now demanded that Google obtains "unambiguous" consent from users before combining their data, "via a separate consent screen", rather than through its more generalised privacy policy.
It also ordered the company to add clarification to the policy so that users are better informed as to how each of the company's services is using their data.
Furthermore, Google is required to make it clear that YouTube is part of its setup, though the DPA did note that this already appeared to be underway.
Five other regulators - in France, Germany, Italy, Spain and the UK - have recently received a letter from Google detailing how it intends to comply with European privacy laws but the Dutch DPA says it has yet to establish whether the proposals will suffice within its own jurisdiction.
While the DPA's gripe with Google awaits resolution, it has now moved onto fellow data gatherer Facebook.
In another statement (in Dutch - view Google translate version) released on Tuesday it announced it would investigate Facebook's new privacy policy.
The social network announced last month that it intends to make changes to its policy, effective from 1 January 2015.
As Facebook has a physical presence in the Netherlands, the DPA says it is authorised "to act as supervisor", as per a European Court of Justice ruling on Google vs. Spain on 13 May 2014 (the 'right to be forgotten' case).
As such, it has asked Facebook to hold fire on its new privacy policy until it has had the chance to investigate how the changes may impact Dutch users, including how Facebook obtains permission for the use of their personal data.
The latest iteration of the policy states that Facebook can use:
your name, profile picture, content, and information in connection with commercial, sponsored, or related content (such as a brand you like) served or enhanced by us. This means, for example, that you permit a business or other entity to pay us to display your name and/or profile picture with your content or information, without any compensation to you. If you have selected a specific audience for your content or information, we will respect your choice when we use it.
Given how the key points of the policy have not changed since it was last revised in November 2013, it seems unlikely Facebook will comply with the DPA's wishes.
According to The Telegraph, the company responded by highlighting how it is "a company with international headquarters in Dublin", which routinely reviews its policies and procedures with its own regulator, the Irish Data Protection Commissioner.
Facebook said it is confident that its new privacy policy is compliant with all relevant laws.
Follow @Security_FAQs
Follow @NakedSecurity
Image of Dutch citizen courtesy of Shutterstock.
Kids can be street-smart and Facebook-stupid, to paraphrase how Vice News put it.
Want to hack a friend's Facebook account?
The site mixes wording associated with legitimate security services with that of malicious hacking, Long notes, as it first offers "recovery services" for regaining account access (sounds benign, eh? Don't count on it, he says), then jumps to the promise of hacking an account "without software assistance" and using "the most advanced exploits" on top of "5 methods of decryption" to get a target's password.
Read into this whatever cultural generalizations you will: recent numbers show that citizens of Germany, Spain, the UK, and the US have higher appetites for porn than anybody on the planet.
Last week, the Prime Minister gave a speech in which he announced new measures to protect children and challenged the internet's tech giants to shape up and do their part.
You are not paranoid about surveillance - at least, not as far as Facebook is concerned.
If it helps Losse to sell more books by tying it in to concern about PRISM-like surveillance, that's OK, as far as I'm concerned.
What that means is that even if you don't share details of your own personal information with Facebook, Facebook well may have gotten it through other people in your network who've let Facebook have access to their contact lists.
Facebook has paid out $20,000 for a serious bug that could have allowed an attacker to hijack anyone's account with ease, with no user interaction on the part of the victim.
For those Facebook users who are allergic to any notion of privacy whatsoever and would prefer that the entire world be privy to contents of their #dinner or antics of their adorable #children, Wednesday was a high and holy day indeed, for that was the day that Facebook embraced the hashtag. 
Currently, users control the audience for their posts, including those with hashtags. 
The women's coalition that sparked the change says that those who participated in its campaign against gender-based hate speech on Facebook sent over 60,000 tweets and 5,000 emails.
Is Facebook Home the long rumored Facebook phone? Nope.
What Facebook Home is supposed to do is replace your plain vanilla lockscreen with a continuously-updated feed from your Friends, a feature they call Cover Feed.
The feature people seem to like the best is called Chat Heads. 
"People use Facebook to stay connected with friends and family, to discover what’s going on in the world, and to share and express what matters to them."






Europe v. Facebook, an Austrian student organization that keeps tabs on Facebook's privacy transgressions, recently discovered that Facebook's latest timeline redesign allowed friends of friends to see the total number of Events a user has attended, even if that person's privacy settings were set to only allow friends to see such events. 

Those complaints were built on the work of meticulous document requester and researcher Max Schrems, who in 2011 extracted a pile of 1,200 pages that comprised his then-current personal-data Facebook dossier.
Before you start sobbing, let me tell you the good news.


As it is, those concerned about privacy are already disturbed by the possibility of Facebook's new Graph Search being able to squeeze out data that users might have posted and then forgotten about, or how it could be used to cross-relate disparate pieces of data about people, with less than desirable results. 
Following press interest, Facebook finally apologized on Wednesday, saying that it's working to fix a problem limiting used of pre-1910 birthdates.