Colleges and Employers Demanding Facebook Passwords
redtape.msnbc.msn.com
redtape.msnbc.msn.com
First, I consider this the equivalent of asking to record conversations I have with my friends. If you as an employer think that it’s part of your business to eavesdrop on my friendships and romances, then we know where we stand and I will be over here working with someone else.
Second, I can’t give you my FB credentials even if I wanted to. The reason is that by doing so, I am violating the privacy expectations of other people, who do not expect that the things they share with me in private messages or on their wall or photos will be shared with my employer.
I have a similar arrangement with the person I date. She is welcome to ask me about my FB and email, however she is not allowed to rifle through it at will because other people may have an expectation of privacy in things they have emailed me.
I am curious, however, what will happen to people who really don't have a facebook. I've never had an account, would they believe me or assume I deleted it?
At that point I delete my Facebook account and never look back.
As soon as you apply for a job that is high level or sensitive enough, that information will be part of the dossier they review. Depending what is in your FB, or any other comment history you may have, it MIGHT be wise to keep that FB. Lest they think you were trying to hide something.
I need a FB account for work. When FB inevitably becomes so invasive that people begin to panic and delete their profiles, I can safely delete (deactivate) mine. FB may keep all of my data, hopefully I won't have given them anything that isn't worthless.
I think the only safe policy is to refrain entirely from adding any information to the system; you may never get it back. Even seemingly innocuous status updates and public conversations could look suspicious/unprofessional/embarrassing later on.
If you don't mind me asking, why do you need an FB account for work, especially when it sounds like you don't even use it?
Its a real pain in the ass, mixes personal and work way too much. I had a Facebook account already, and i still do, so i didn't mind too much....but i dislike the left overs its causes (installed apps, pages in my name, app keys in my name etc...although this was just due to poor management of these assets)
If you apply for a job that is sensitive enough, they are already going to completely rifle through your personal life.
A step further, and this is where I think I am, is the "delete" option, where you, small 'd', "delete" Facebook, but your information is still there in case you want to come back. It's not accessible to your buddy Joe Blow, but it's there.
Finally, and I might be wrong here, but there is a big 'D' "Delete" option, where facebook deletes your info "permanently" or as "permanently" as they'd like you to believe.
I don't plan on going back to facebook soon, but I'm with you in worrying at times that a sensitive employer would look at a "deleted" or "Deleted" facebook and think "What is this guy trying to hide?"
Also, deleting these accounts does not assure complete invisibility on the net. If you've used your account to comment on a public facebook account or page, there is no assurance that deleting your account would delete that post too.
What's interesting is that the purpose of the background check process seems to be threefold (as I gleaned from talking to an FBI Special Agent who interviewed me about a friend):
1. Identify possible ways in which the investigated person might be manipulated. Having an affair? Had an affair a few years ago which the current spouse doesn't know about? Gambling problem? Drug issues? If so, you might be susceptible to blackmail or bribery.
2. Identify propensities for dishonesty or lack of trustworthiness. Did you cheat on tests? Do you follow-thru on promises? I was asked a lot of questions about how much I trusted this friend.
3. Identify possible 3rd party allegiances. Are you someone identified by the mafia at age 15 as a person who will go to college, look sparkling clean, and then infiltrate the FBI? To make sure, the FBI interviews people from many phases of one's life. It would be really hard to have seemingly normal friends while you were secretly off training with some foreign terrorist organization. I suspect I was also background checked, but I never signed-off on it. The FBI seems to be using the social graph transitively to verify that you aren't hiding anything. No proof of this last statement though.
I've been told that, at least for normal governmental security clearances, the goal is not to determine if you are a good or bad person -- it's to determine if you are hiding something. If your wife knows about the affair you had five years ago, it will be hard to use that knowledge to blackmail you. However, if it remained a secret, you might do something not so good for the USA to save your marriage.
I was asked about the additional names (expressed only as initials due to space constraints) on my friend's condo deed. She had purchased the condo while in law school, and her parents co-signed on the loan. Only after the interview did I realize that the FBI was confirming she did not have a sugar daddy!
Your employer may not have the power to access those "deleted" records, but there are parties out their that do have access, i.e. Governments and such
Legislation Facebook should back if they have an ounce of brains.
Consider that as popular as Facebook is, it is still mostly popular for younger people, who vote less than older people.
Consider how easy it is to convince the government to end almost any right or freedom if you mention security/terrorism.
Consider that while this might become an election issue, it almost certainly won't be the election issue. The economy, abortion, and all the other old standbys, will be the votes that really matter to an elected politician, not a vote, or lack of a vote, either way on facebook.
Consider that once this violation of privacy becomes status quo, it becomes 100x harder to roll it back.
I expect a lot of things, but I would not be surprised if this forced access to friend only level of information on facebook becomes the norm.
Diligently create a facebook "version" of yourself which appears to be a great worker/student/whatevertheywant?
I mean you can fight the system, but sabotaging it is so much more fun.
"Put it all together and I think we all now see the fundamental utility of LinkedIn — it’s the one place where you can demonstrate how honest, decent and accomplished you are, even if you have to lie and cheat to do it." http://www.creators.com/lifestylefeatures/humor/work-daze/li...
At that point, I would start my own company, we wouldn't check Facebook accounts (and would let people know this) and we would have a line out the door of job applicants who want their privacy respected.
It seems to me that this is clearly the sort of thing that should be illegal because there is a huge imbalance in terms of bargaining power in these situations.
Introducing facebook background searches! For a low fee of $2499, fb will comb through your prospective employee's postings and alert you of any trouble spots!
Two hours later, here is what I sincerely suggest you say:
The people I interact with have an expectation of privacy around the things
they share on FB with me, or even the fact that we know each other.
When I come to work here, you will have certain expectations about my discretion
and ability to respect the company’s need for privacy and my co-worker’s needs
for privacy by not sharing things I see, hear, or are privy to with a third party,
even—or especially—if I am offered a financial inducement such as an attractive
offer of employment with a company I respect.
I therefore ask you to recognize that I am giving my friends and family the exact
same expectation of privacy that you can reply on from me once I join your firm.
I don’t think that’s smarmy or righteous, it’s just good old-fashioned golden rule stuff, and you are demonstrating your integrity. There will be a certain number of companies who ask to shoulder-surf your facebook, and I will guess that some of them will back down if you say those words to them and mean it.JM2C, of course, I am not qualified to give career advice.
Pretty sure a few well placed class action lawsuits would cure this practice.
/sarcasm
If every employer demanded this I would have the easiest choice in the world. Start my own company and not ask to read my employees personal communications.
Drugs are about as easy to quit as Facebook for some people...
On a more serious note, it seems to be that drug testing is only required where physical safety is compromised by drugs, like drivers, warehouse workers, etc. Similar to how people who have direct responsibility of money may have to undergo credit checks. Properly managed, these seems like acceptable precautions to me.
I've never been asked to take one, nor would I submit to one for a software development job, despite being drug-free.
I am having trouble coming up with a legitimate need that an employer would have for a facebook account password, short of someone who has a high level security clearance where phone taps and surveillance are also to be expected.
Even if we take this argument to a logical conclusion where every employer will eventually feel compelled to do this, this would destroy the value proposition of Facebook entirely. It would effectively turn Facebook into LinkedIn. If it can't be used for fun, people won't use it, which is entirely against Facebook's interests (which means they'll adjust the privacy policy and sue offending employers).
The idea that this is a serious phenomenon gets clicks, but it has no legs to stand on.
(IANAL, TINLA)
Hah, do you think for a huge amount of people simply getting a different job is really that easy? The working class of the US is completely on the ropes, they are told to take any job they can get because they are so desperate for work. It's nice, as a privileged person being able to go up yours I'll keep my dignity and my rights, but the impoverished and desperate do not have that luxury unless they want to starve.
Also simply give a fake facebook account with a few fake contacts for your friends and family. Most people are too stupid that they wouldn't recognize the inactive accounts as fakes.
The statute (18 U.S.C. 1030) also creates a civil remedy; Facebook may be able to sue employers who access an applicant's account. Even if the statute is held to not apply in such situations (or held to be unconstitutional as applied in such situations [1]), Facebook may still be able to sue under state law for inducing said applicants to breach their contract with Facebook (tortious inteference) by sharing their password.
[1] E.g., see U.S. v. Lori Drew, 259 F.R.D. 449 (C.D. Cal. 2009), where a district court held that 18 U.S.C. 1030 criminalized TOS violations (including falsifying one's date of birth) but was unconstitutional in that regard.
We've seen something very similar in the discussions around data rights when people die-- family who inherit passwords are unlikely to be sued where there is explicit permission granted-- because they are not "impersonating" anyone.
What could to prevent this is if requests in this manner can be considered coercion or duress-- automatically disqualifying contracts with language requiring disclosure of private passwords, and penalizing parties that try to include similar clauses.
I'd love to cite some cases, but have to run (I do appreciate the legal thoroughness!)
"Hey look, we're quickly aggregating all of our personal data into one centralized place creating an obviously appealing target for authority as evidenced by this recent trend of college sports programs invading the privacy of students. Let's all talk about it on Facebook."
Any site that requires Facebook as a login or comment function is dead to me.
Putting bugs in your phone and residence is difficult, requires technical expertise and people to actually monitor. So well, what can you do? Like the article says, the option was to educate. But then comes social media and kills the technical barrier, so great, lets spy on our students, candidates, etc, and have them give us clearence to do so through intimidation.
We never had those rights to begin with, spying was just more of a hassle then than it is now.
Now begins the real fight for those rights. If we fail, then we are left with a socialitariam-regime and forced to keep using some hypocritical-media in order to be able to get jobs/loans/etc while we keep private matters offline (until new technology breaks that barrier too).
When all worthwhile criteria are equal, worthless criteria are used to decide.
"This guy swore in a facebook post, so lets go with the other guy."
That's also just scratching the surface of the problem when you begin to consider sexual inclinations, religion, political views and ehtnicity.
None of that information should be relevant to most job applications, but once available they will surely be used to the employers will and you have no say in it.
I've had a post that I accidentally made public on my Facebook come back to bite me in the ass, and it won't happen ever again.
Anyway, I presume this is a US thing, this would never happen in the EU, it would go to the european court of human rights (or some court or other) so fast you won't even have time to apply lube!
I imagine that with the username/password, they'd notice that it was created two weeks ago, and that your friend network is all bots.
Why not add in some of your real friends? I said nothing about bots. Tell them why you need this. Change the name of your real account to something else. Hide it. Disable it.
I think also that the new facebook timeline allows you to place "stories" and "events" to any point of time in the past.
Or start deleting what you want hidden from your facebook account and then hand over the details.
Or, how about some foresight. I don't know, how about I create a second account and keep that running side by side right now, because I'm in one of those industries that are douches about this kind of thing. I know some people that do this to keep stuff hidden from family members.
Man, I have to think of everything round here... :)
Everything I've just said I think is extremely wrong and if an employer asked me for these then I'd tell them to go fk themselves.
I hope you'd walk away, and I hope I would too. But my point is, it's easy to say what your ethics are, and a lot harder to act ethically in the moment. Doing that little thing you were sure you would never do is so easy when your boss is staring at you, or your coworker needs you to cover their ass, or you stand to make an extra $20k a year if you get this job, or whatever.
My friend said she realized that day that in order to be a good doctor, you have to always know, at any given moment, that you might just have to walk away. You have to be ready.
I'm not a doctor, but it's a rule I've taken to heart.
I feel bad even telling this story, because my friend is a super ethical person and this is far from her proudest moment. But that's how these things go, right? You come to a moment where every practical consideration tells you to do the thing you don't believe in, and no one ever has to know, and it probably won't cause any harm this one time ... and you become someone you never wanted to be. It takes real strength and forethought to make the right call there in the moment.
In modern medicine, it's almost never a choice between doing harm and not doing harm. It's more like, "well, assuming we've properly guessed what's wrong with you, the studies say you have a 20% chance that this surgery will work and won't kill you, and a 10% chance of living more than three months without the surgery. Your family will have to go into debt to make the surgery happen, so your call." The best you can do is explain as much as you can to the patient and let them decide -- so it becomes their impossible ethical decision instead of yours. That's better, right?
- do no harm to your kids
- do no harm to some stranger
Pick one."....However, on a general note, I think it is important to realize that every text message you send, every cell phone conversation you have, every post to the CNN forum you make, every tweet you send ... is directly attributable to your IP whether you use your own name or not. With Facebook and Google tracking everything you do, whether you are logged in or not, I would go one step further, and say all of these things are directly attributable to you personally.
I would strongly urge young people to really think about what they are putting out there. Consider this, the military was doing the equivalent of credit checks for sensitive positions during the 60s. Now you need a credit check to do ANYTHING, even things that don't require credit. How long before an internet and phone background check is standard in the background checks organizations do before offering jobs?
I can tell you the military is doing this sort of screening right now for sensitive positions, but at least you are confronted about it. It still basically ends your career, but they will give you a chance to explain your posts. In the private sector in the future, they will just deep six your application and you won't know what happened. Or they'll let you in at entry level, maybe, and subsequently you'll start running up against an invisible barrier as you try to advance beyond the first or second layer of management. Or you will find resistance to you advancing into management at all.
Also be mindful, it can affect more than your professional life. Think about what the background checks for apartments will look like in the 2020s. Or what 'dating sites' will be like in the 2020s.
Please consider your future before you make comments on ... say ... black people and Hurricane Katrina ... that might be misconstrued. Or post an opinion on ... say ... American soldiers in Afghanistan ... that could be taken out of context and viewed in a negative light.
All that said, the absolute best defense against these sorts of situations is just not to be a douche, which isn't very hard..."
----
I think that comment is apropos here as well. I encourage all of the young people I work with, as often as I can, to be careful about what comments they put ANYWHERE on the internet. To be mindful of what they say during ANY cell phone conversation. And to try to limit their use of text messaging.
I know this sucks, but this stuff is serious...these things WILL affect your future.
I think I remember this post.. I also recall posting a link to an XKCD that greatly sums up my feelings on the matter.
Good luck, I'm behind 7 proxies.
Now the employer wonders: Why is this account going to such trouble to hide its actions?
I've seen this post before. (edit: no offense intended - a lot of people post the same thing on repetitive topics, your one is just a little unique)
I'm wondering how you came up with this idea. It seems ... odd but strangely credible. Is this an extension of some process which already happens?
"Yes, that's really my password. High security. Don't you have a secure password like that? You really should you know."
"It didn't work? Are you sure you typed it in correctly? Try it again."
(The first being the one you file for an invasion of privacy, of course).
Why is this specifically targeted at social media? No one should request copies of people's private keys as part of any routine interview process. This is no different from asking for a copy of someone's PO box key, and the law should also clearly say that that is illegal (if it isn't already?)
Your data belongs to Facebook, not to you. Sad, but true.
Edit: (submitted too soon) I'm sure there's something legally dubious about requesting private keys in this way, but the PO box example was a clear reminder to me about how we wrongly think of our data on private services as "ours".
Really, I'm probably trying to hard. This is phishing, plain and simple, and should be treated as such.
Facebook has no more or less access to/ownership of your life than your ISP and cell phone company.
Social media monitoring on colleges, while spreading quickly among athletic departments, seems to be limited to athletes at the moment. There's nothing stopping schools from applying the same policies to other students, however.
Look, college athletics has a lot of issues. Colleges secure all economic benefits associated with player performance in exchange for a college scholarship (I hope O'Bannon v. NCAA solves that problem soon). [0]
But how can anyone extrapolate requirements from college athletes to the entire student body? Would any Ivy School dream of asking an applicant for their password, when said applicant's mother might be a partner at a law firm? What about the constitutional issues regarding the same request from a public university (funded by taxpayer money)?
[0] http://www.theatlantic.com/magazine/archive/2011/10/the-sham...
If they weren't joking, walk out immediately, stating why. Warn others.
I could and would never work in a place where a "social network username and password" field has made it as far as the application process, even if it isn't mandatory (yet). And neither should you.
When I get done laughing, I'll happily write down my 'password' for them: if they have any shame, they'll be beet red when they get done reading it.
OK, I probably won't get the job, but that's OK since it's clearly somewhere I wouldn't actually have wanted to work anyway.
Seriously, this whole notion is so asinine that it's almost beyond belief. I mean, why not just ask me for a copy of the key to my PO box, a copy of my car key, permission to tap my phone, and access to put a camera in my living room? Get real, people...
> "I can't believe some people think it's OK to do this,” he said. “Maybe it's OK if you live in a totalitarian regime, but we still have a Constitution to protect us. It's not a far leap from reading people's Facebook posts to reading their email. ... As a society, where are we going to draw the line?"
Surely they are misquoting this lawyer, or did the First Amendment start applying to corporations all of a sudden?
It's almost like the existence of the constitution encourages challenges to privacy. The "if you had a defense but didn't use it then you must be okay with what's happening" thinking.
"No Act of Parliament can be unconstitutional, for the law of the land knows not the word or the idea."
http://www.homeoffice.gov.uk/agencies-public-bodies/crb/
I have three current CRB 'disclosures' as I worked for three employers for a brief period last year. A full disclosure is not limited to convictions but can include cautions and other information that the police may have. Bit more concrete than some prison manager having a quick look at a facebook profile.
"Aside from the free speech concerns, Shear also thinks colleges take on unnecessary liability when they aggressively monitor student posts."
Yes, I'd have thought there was a huge vicarious liability/duty of care issue with this. I don't want to know what my students put on their facebook accounts!
"Goemann also noted that the rush to social media monitoring raises an often overlooked legal concern: It's against Facebook's Terms of Service."
That occurred to me as well as soon as I read past the first few sentences. Many people on this forum provide Web services. Do you actually have any way/interest in enforcing this aspect of the typical ToS or is it just there as some kind of protection for you?
That would be my initial objection too. There's no real point in going beyond that. If the FB ToS have any legal weight then it would be most likely unlawful for me to share my FB login details with anyone.
An employer who attempted to do that and then sacked you would be performing constructive dismissal and probably be in breach of the [letter of the] Computer Misuse Act for attempting to gain access to a computer system without proper authorisation.
A company that followed through and consulted your FB would then be holding private information on your friends and there are all sorts of regulations that they're supposed to comply with then. Presumably they'd also be in breach of the European Convention of Human Rights @ Art.8 (at least).
TBH it sound quite fun. One could create a FB profile as a honey-trap - access would provide the evidence for a willing barrister to take a large company to the cleaners ... or that's how it seems.
IANAL needless to say.
About this thing in special. Finland has a pretty strict law against privacy violations in job interviews. You ask a wrong question as an interviewer and the whole recruitment process might be at risk. Of course you can ask about hobbies and whatnots, but anything too private may get you a "I don't feel like answering that" as an answer. And then you are in trouble. But that works just fine for us. A job interview is supposed to be about the work, not the applicants past time.
* Asking somebody for access to their email/social network account is actually a great question to ask in a job interview. If somebody is so careless about their private data to easily give away access to it upon request, that would easily disqualify them in my book.
Hopefully this ends fast.
It's to the point where I think you could almost start one of those hipster movements I'm always hearing about. Give it a sophisticated name like Entropism. Set an example by running around the Internet behind seven proxies, inside a virtual machine, with JS disabled, running firefox, with a fake user agent, going over each one of your posts with a style-analysis program and dataset, clearing most history every five minutes, blocking cookies, deliberately messing with the response times of your hardware to prevent device fingerprinting, spoofing your MAC, etc etc.
I mean, how do I know that this company is trustworthy? Are they paying their bills on time? Is there cash in the bank?
But, our team was small (30 people), and not in the "money sports" (football, basketball, baseball), so we could get away with this. Larger teams in higher profile sports won't be able to do this.
But you can always create a phony one.
http://news.ycombinator.com/item?id=3669568
Personally, I like to have a real life off the computer sometimes.
BUT, the amount of people that look at me funny because I didn't, and the article that i linked to just reinforces that.
Only illegal if you're a law enforcement officer in most developed countries. But unethical even if you're not.
On a humorous note, if personal lives are a deciding factor in whom a business chooses to employ over and above other, skills-based qualifications, the job you are applying to is likely very easy, and thus the kind of job that robots will be doing soon.
Then, if you get the job (although I don't think I'd want to work at a place that's looking over my shoulder constantly), you can reactivate it whenever you want.
I'm struggling to come up with any justification. About all I can fathom is a world in which they have to prove 100% that you're not insider trading. But if they need your Facebook to prove this, this need to tap your personal phone # and read all your snailmail too. And every personal email account.
Wow this is depressing.
Seriously, most people will say things like "I don't have anything to hide so it doesn't bother me".
They won't know, or care, until they run into a specific case where it affects them -- at which point, chances are, it will have taken them entirely by surprise. (It takes only one off-handed reference to a drunken Facebook photo in a job interview, for instance, to put the fear of God into many users).
I'm not suggesting that people would abandon Facebook en masse if they were better informed about it. And hell, I'm not sure many people even would care all that much. But I bet you'd see a marked shift in user behavior in pretty much any users in college or older. (Basically, anyone thinking about employment).
Sometimes people have to learn things the hard way...
i) National ID cards. These failed not because of (well publicised) privacy concerns, or because people didn't want to have to carry an ID card, but because the government said that cards would cost > £100 for most people.
ii) National Criminal DNA database. The UK has a huge DNA database, and it used to include profiles from people who had been arrested but never charged nor convicted. A court of human rights said that it's abuse to keep those indefinitely; government offered 12 years but that was reduced to (I think) 6 years. Many people said they didn't care if they were on the database, saying that they were innocent and that if it helps the police they'd volunteer. (Missing the problem of false positives and having to keep too much data).
For both of these things there were active campaign groups warning about the risks, but many people just didn't seem to care.
I might aquiesce to a FB access request as long as I was also given access to all emails, phone calls, SIN numbers, banking information and sexual habits of the Deans or CEO of the institution. That seems fair, considering I never use FB.
You'll likely have to make other provisions--but if it's really a big deal, it's not that difficult or taxing, really. Plus you can have a bit of fun creating your fake you for these types of things.
Want my Facebook password? No thank you, I will go somewhere else.
Not that I use Facebook or have used it in the past enough that there's anything on there I wouldn't want any given person to see, but this is some bullshit business.
Privacy by default.
Also my facebook answer is "i don't have one at the moment" and I wouldn't use my real name on facebook.
Talk about a perverse network effect.
It's like if any company asked you for this info - I would ask for access to the CEO's email - or the financial drive and tell them that in order to work there, you'll need to perform an audit of their ethics and finances to ensure your not engaging in a relationship with a criminal organization.
How is this any different than drug testing employees?
learn the hard way I suppose? in any case, I still feel that social media sites are plagued by abuse by third parties.
But to give perspective here: this is for college athletes. Nothing new.
Those people, usually, agree to several freedom limitations, such as ridicule curfews and sex life control before games and such.
I doubt one more freedom limitation is any concern.
About the fears of it leaking to other jobs, well they are doing that for decades and you still have to hear your manager saying the curfew today will be 3pm cuz he do not want you making sex before the launch tomorrow.