The Deactivated Friend Attack: How Your "Gone" Friends Might Be Cloaking Spies

Your Facebook deactivated friend or a cloaked spy

2012-03-01
Shah Mahmood, Yvo Desmedt
Summary
Problem
Method
Results
Takeaways
Abstract

This paper identifies a zero-day privacy vulnerability in Facebook termed the "Deactivated Friend Attack." By exploiting the temporary nature of account deactivation, an attacker can remain invisible ("cloaked") on a victim's friend list to avoid detection while periodically "uncloaking" to harvest private data.

TL;DR

Researchers have uncovered a "zero-day" privacy loophole on Facebook that allows attackers to remain on a victim's friend list indefinitely without being seen. By abusing the deactivation feature, an attacker can "cloak" themselves, becoming invisible and un-unfriendable, only to "uncloak" briefly to steal private updates. In an extensive field test, the researchers maintained access to over 4,300 profiles for nearly nine months with a 0% detection rate.

Background: The Illusion of Social Privacy

In the traditional social graph, the relationship between friends is mutual and visible. If you no longer trust someone, you unfriend them. This paper shatters that assumption by introducing the Deactivated Friend Attack. It positions this vulnerability as a "Cloaked Channel"—a concept borrowed from science fiction (specifically Star Trek) where an enemy ship becomes invisible to scanners but can still observe and eventually strike.

The Problem: The One-Way Mirror of Deactivation

Most social networks view account deactivation as a "pause" button for the user. However, the authors point out a critical oversight:

  • Invisibility: While deactivated, your name disappears from your friends' lists.
  • Invulnerability: Because you aren't on the list, the victim cannot click "Unfriend" or move you to a "Restricted" list.
  • Persistent Access: The friendship bond remains in the database. When the attacker reactivates, they instantly regain access to all "Friends-only" data.

The "Why" is simple: Facebook's design prioritizes a seamless return for users who leave the platform, but it ignores the security implications of "ghost" friends who can return at will to harvest data.

Methodology: The Art of Cloaking

The researchers modeled the attack probability using several behavioral factors ( to ), such as the likelihood of a victim checking their friend list vs. the timing of the attacker's "uncloaking."

Mathematical Probability Model of Detection

The Attack Cycle:

  1. Infiltration: Send a targeted friend request (often using social engineering or a "legend" profile).
  2. Cloaking: Immediately deactivate upon acceptance.
  3. Surveillance: Periodically reactivate for short bursts (e.g., 10 minutes) during the victim's "silent hours" (late night) to crawl their profile.
  4. Re-cloaking: Deactivate again before the victim logs in.

Experimental Evidence: 4,300+ Victims, 0 Detection

To prove the viability, the authors ran a three-phase experiment over 606 days.

Friend Request Acceptance Rates

Phase 1: Gaining Trust

By using targeted requests, they achieved a 62% acceptance rate. This is significantly higher than random bot attacks (which usually hover around 35%), proving that "targeted" social engineering is highly effective.

Phase 2: The Cloak

For 261 days, the researchers cycled between deactivation and brief reactivation. Despite having thousands of "friends," not a single user unfriended them during this phase. The invisibility was 100% effective.

Phase 3: The Reality Check

When the account was finally left "uncloaked" (permanently active) for 60 days, only 5.5% of users eventually removed the account. This suggests that even when visible, users are slow to prune their friend lists, making the "cloaked" invisibility even more powerful for long-term spying.

Critical Insight & Solutions

The core of this problem is the State of Non-Existence. When a friend deactivates, they shouldn't just vanish; they should remain visible in a "Deactivated" state so the user can still manage the relationship.

The Authors' Proposed Fixes:

  1. Notifications: Notify users when a friend reactivates an account.
  2. Visible Deactivation: Show deactivated friends as "blurred" entries in the list, allowing them to be unfriended.
  3. Rate Limiting: Flag accounts that toggle activation status frequently (a clear sign of automated crawling).

Conclusion

This paper serves as a stark reminder that features designed for "user convenience" (like easy deactivation) often create massive security debt. The "Deactivated Friend Attack" is a silent, persistent backdoor that turns a momentary lapse in judgment—accepting one wrong friend request—into a lifetime of surveillance. As social networks evolve, they must recognize that a user's right to manage their social circle must extend even to those who have temporarily "gone dark."

Find Similar Papers

Try Our Examples

  • Search for recent papers that investigate "cloaked" or "shadow" profile vulnerabilities in modern social media platforms like Instagram or LinkedIn.
  • Which study first formally defined the "Cloaked Channel" in the context of cybersecurity, and how does this paper's application to social networking expand that definition?
  • Explore research that applies the "Deactivated Friend Attack" logic to automated Socialbot networks or large-scale data scraping campaigns.
Contents
The Deactivated Friend Attack: How Your "Gone" Friends Might Be Cloaking Spies
1. TL;DR
2. Background: The Illusion of Social Privacy
3. The Problem: The One-Way Mirror of Deactivation
4. Methodology: The Art of Cloaking
4.1. The Attack Cycle:
5. Experimental Evidence: 4,300+ Victims, 0 Detection
5.1. Phase 1: Gaining Trust
5.2. Phase 2: The Cloak
5.3. Phase 3: The Reality Check
6. Critical Insight & Solutions
7. Conclusion