Facebook Suspends Hundreds Of Apps

Did you just notice a Facebook  app you use  has disappeared?  After reviewing “thousands” of apps on its platform following a major data misuse scandal that blew up in March, Facebook has announced it has suspended around 200 apps, pending what it describes as a “thorough investigation” into whether or not their developers misused Facebook user data.

The action is part of a still ongoing audit of third party applications running on the platform announced by Facebook in the wake of the Cambridge Analytica data misuse scandal

Cambridge Analytica was a third party developer who used quiz apps to extract and pass Facebook user data to the consultancy for political ad targeting purposes.

CEO Mark Zuckerberg  announced the app audit on March 21, writing that the company would “investigate all apps that had access to large amounts of information before we changed our platform to dramatically reduce data access in 2014, and we will conduct a full audit of any app with suspicious activity”. Apps that would not agree to a “thorough audit” would also be banned, he said then.

Just under two months on and the tally is around 200 ‘suspicious’ app suspensions, though the review process is ongoing, and Facebook is not being more specific about the total number of apps it’s looked at so far (beyond saying “thousands”), so expect that figure to rise.

In the Cambridge Analytica  instance, Facebook admitted that personal information on as many as 87 million users may have been passed to the political consultancy, without most people’s knowledge or consent.

Giving an update on the app audit process in a blog post, Ime Archibong, Facebook’s VP of product partnerships, writes that the investigation is “in full swing”.

“We have large teams of internal and external experts working hard to investigate these apps as quickly as possible,” he says.

“To date thousands of apps have been investigated and around 200 have been suspended, pending a thorough investigation into whether they did in fact misuse any data... “Where we find evidence that these or other apps did misuse data, we will ban them and notify people via this website. It will show people if they or their friends installed an app that misused data before 2015, just as we did for Cambridge Analytica.”

Archibong does not confirm how much longer the audit will take, but does admit there’s a long way to go, writing that: “There is a lot more work to be done to find all the apps that may have misused people’s Facebook data – and it will take time.”

“We are investing heavily to make sure this investigation is as thorough and timely as possible,” he adds. 

Where Facebook does have concerns about an app, such as the 200 apps it has suspended pending a fuller probe, Archibong says it will conduct interviews; make requests for information (“which ask a series of detailed questions about the app and the data it has access to”); and perform audits “that may include on-site inspections”. So Facebook will not be doing on-site inspections in every suspicious app instance.

Given the likely scale of data misuse by developers on its platform there is an argument for Facebook to publish a public list of suspensions.

A Facebook spokeswoman has subsequenty been reported to say that the the company intends to provide more details about any apps it decides to ban after concluding each case-by-case investigation. Although she also said the company has not yet decided how it will share information about these apps. 

The spokeswoman declined to specify how many thousands of apps Facebook has reviewed at this stage; how long it believes the full investigation process will take; nor how large a quantity of user data it’s using as its benchmark to trigger individual app investigations. The process remains pretty shrouded and caveated, making its rigor and value hard to quantify.

Techcrunch

You Might Also Read: 

Facebook Collects Your Data Even If You Don’t Use Facebook:

Regulation Might Actually Protect Facebook:
 

 

« Turkey Using German Spy Software On Opposition Politicians & Activists
Barclays Bank Want To Stop Cybercrime »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Protegrity

Protegrity

Protegrity is an enterprise and cloud data security software for data-centric encryption and tokenization to protect sensitive data while maintaining usability.

Innotec Security

Innotec Security

Innotec Security is a Spanish company specializing in cybersecurity-as-a-service, cyber resilience and cyber risk management.

SEPPmail

SEPPmail

SEPPmail is a patented e-mail encryption solution to secure your electronic communication.

totemo

totemo

Totemo offers solutions for the secure exchange of business information.

Slovenska Akreditacija (SA)

Slovenska Akreditacija (SA)

Slovenska Akreditacija (Slovenia Accreditation) is the national standards accreditation body for Slovenia.

Danish Maritime Cybersecurity Unit

Danish Maritime Cybersecurity Unit

The Danish Maritime Cybersecurity Unit is tasked with delivering the initiatives set out in the Cyber and Information Security Strategy for the Maritime Sector.

ThreatGen

ThreatGen

ThreatGEN™ works with your team to improve your resiliency and industrial cybersecurity capabilities through an innovative and modernized approach to training and services.

ThreatSwitch

ThreatSwitch

ThreatSwitch a software platform for cleared federal contractors to get and stay compliant with NISPOM and Conforming Change 2.

Cyber Polygon

Cyber Polygon

Cyber Polygon is an annual online exercise which connects various global organisations to train their competencies and exchange best practices.

HacWare

HacWare

HacWare is a data driven cybersecurity awareness product that leverages machine learning and behavior analytics help IT professionals combat phishing.

RocketCyber

RocketCyber

RocketCyber is a Managed SOC platform empowering Managed Service Providers (MSPs) to deliver security services to small and medium businesses.

HunCERT

HunCERT

HunCERT's mission is to assist Hungarian Internet Service Providers in applying appropriate procedures to address the risks of computer network incidents and to respond to such incidents.

DoControl

DoControl

DoControl gives organizations the automated, self-service tools they need for SaaS applications data access monitoring, orchestration, and remediation.

Computer Services Inc (CSI)

Computer Services Inc (CSI)

CSI is a leading fintech, regtech and cybersecurity solutions partner operating at the intersection of innovation and service.

Aspire Technology Solutions

Aspire Technology Solutions

Aspire is an award-winning IT Managed Service and Cyber Security Provider. We specialise in cyber security, cloud, connectivity, managed services, unified communications and IT support.

Genix Cyber

Genix Cyber

Genix Cyber provides world-class cybersecurity services that protect systems, cloud applications, infrastructure, critical data, and networks from evolving cyber threats.

Core42

Core42

Core42 provides a full-spectrum of AI enablement solutions covering cloud, data, cybersecurity and digital services designed for customer success.