Unmasking the Invisible: How Your Social Network Profile Leaks Your Identity
Personally identifiable information leakage through online social networks
The paper introduces a prototype software model developed in NetLogo designed to analyze and visualize the leakage of Personally Identifiable Information (PII) on Online Social Networks (OSNs), specifically Facebook. It identifies how default security settings and information deduction (e.g., inferring gender from a name) expose users to cyber threats like identity theft and Advanced Persistent Threats (APTs).
TL;DR
Social networking convenience often comes at a steep security cost. This paper introduces a specialized prototype model built in NetLogo to visualize how Personally Identifiable Information (PII) "leaks" through Facebook. By simulating the paths that "Friends," "Friends of Friends," and the "Public" take through your data, the study demonstrates that even if you don't post your gender or location explicitly, they can be deduced with alarming ease, turning users into easy targets for cyber criminals.
The "Invisible" Danger: Why Privacy Settings Aren't Enough
The core challenge in OSN security is that users often view their profiles through a social lens—sharing photos and updates to connect—while attackers view them as a data mine. The authors identify a phenomenon called Information Deduction. This is the process where pieces of non-sensitive data are combined to reveal highly sensitive identity markers. For instance, sharing a "clear avatar photo" and your "real name" allows a third party to deduce your gender and potentially your ethnicity or age, even if those fields are set to private.
Methodology: Visualizing the Leakage
To make these invisible threats tangible, the researchers developed a model using NetLogo. The model treats every piece of shareable information as a "node."
- Direct Access: Represented by solid lines, showing who can see what based on current settings.
- Information Deduction: Represented by dashed lines, showing what an attacker can guess based on what you've shared.
- Vulnerability Rating: The model simulates "viewers" navigating these links. Nodes that are visited more frequently grow larger, visually representing a higher vulnerability.
Figure: The setup shows how a public name (Direct Access) allows for the deduction of gender (Dashed Leakage Line).
The Mechanics of Deduction
The model highlights specific logical pairs that lead to leakage:
| Information Shared | Possible Deductions |
|---|---|
| Avatar Photo | Gender |
| Name | Gender |
| Photos | Gender, Friends list, Location details |
| Activities/Events | Routine Location Information |
Critical Findings: The Default Setting Trap
The research investigated Facebook due to its global dominance. A staggering realization was the difference between "Non-OSN" and "OSN" perspectives:
- Non-OSN Perspective: Even without an account, search engines can often index your name and profile picture. This is enough to provide the "seed" for further identity deduction.
- Internal OSN Perspective: Once a user is "logged in" to the network (even if not your friend), default settings often expose almost everything—friend lists, albums, and location tags.
Figure: A simulation of complete public access, highlighting the massive "attack surface" available to a malicious actor.
Impact: Identity Theft and Cyber Espionage
The paper warns that these leaks aren't just a personal nuisance; they are a corporate threat. Advanced Persistent Threats (APTs) often start with social engineering. By harvesting PII from an employee's OSN profile, attackers can craft highly convincing phishing messages or find leverage (extortion/blackmail) against disgruntled staff to gain access to corporate networks.
Conclusion and Future Outlook
The study concludes that "User Awareness" is the only true defense. While platforms like Facebook have updated their privacy interfaces since this study's publication (2013), the underlying logic of Information Deduction remains a cornerstone of modern cybercrime.
Takeaway: If you haven't audited your "Public View" settings lately, you might be providing a roadmap for identity thieves. The "invisible nature" of information deduction means that "what you don't say" can still be "heard" by the right algorithm.
Limitations
While effective as a visualization tool, the prototype relies on user-reported answers to questions rather than automated API scraping. Future iterations would benefit from real-time data ingestion to provide a more accurate "Security Score."
