Facebook: Legal action against employers asking for your password
zdnet.com
zdnet.com
<sarcasm> Plus those employers shouldn't be getting their Facebook background checks for free. FB has to protect it's future revenue streams! </sarcasm>
When FB starts protecting user data from everybody, individuals, business and government, that'll be something. Might even be worth having to wade through your aunt's cats-in-clothing posts.
People shouldn't be getting roped in by the law because law enforcement has free reign to peruse profiles. As well, infiltrating profiles by 'social hacking' (aka asking to friend someone by having a profile with breasts on it) shouldn't be allowed by law enforcement doing fishing operations.
In other words, communications on Facebook should be considered as private communication. Monetization by anonymous advertising akin to Google's model should be the accepted quid pro quo for usage.
Assign a legal team to investigate all such orders, and proactively seek injunctions against those that overstep their authority.
Require that all government employees and contractors disclose their involvement (not publicly, obviously) and subject those individuals to enhanced scrutiny with regards to unwarranted data mining. Pursue aggressive legal action against the state for any individuals found in violation of this policy.
Of course, any of this would require Facebook or anyone else to treat its users as customers rather than products.
Does the "secret interpretation" of the Patriot Act we keep hearing about include unfettered access to social networks?
Collecting and retaining the least possible amount of information about users is good security; it's just bad commercial practice. It also protects your users in case you go out of business and end up sold (or pivoting) into a non-privacy-protecting business model, like what happened with Rapleaf.
It's pretty likely FB will quietly roll out a paid background check service (which will be hyper-secretive and kept whisper-quiet) at the same time they are publicly grandstanding about this issue. In the linked article, there is a link to a second article about a US Senator who is currently crusading on this issue. He comes right out and says there will be exceptions for law enforcement, government contractors, and jobs with security clearances. Look for them to extend those exceptions until social media spying is back to being a de-facto part of applying for a job, any job. They're going to legitimize this while pretending to be fighting it.
(sounds paranoid, yes ... until it happens)
I hope this isn't the case, but facebook doesn't really have a great record when it comes to privacy.
Facebook is doing this because not doing so would be really bad for business: i.e., it would threaten the user experience of the site. People would either quit Facebook, spend less time on it, severely tone down or alter their usage of it, or create fake profiles for work. Any or all of those things would be a big detriment to Facebook. So taking a stand on this issue is both good for business and good for PR.
Employers make 'facebook background check' hiring policy -> FB users/prospective employees become more conscious of this -> User engagement drops as users are more careful about posting anything under the sun -> FB loses
Facebook is valuable, but not "that" valuable where people would sacrifice a potential job opportunity in favor of keeping their Facebook profile.
That being said, I do like that Facebook has weighed in and it favors an individuals right to privacy.
I don't find it impressive or surprising. This is a major issue that would change what people would want to share. No sharing - no facebook. It's obvious that they need to do whatever they can fair, unfair, legal, fud to stop employers from requesting access to a facebook users page.
Another commenter (jerf http://news.ycombinator.com/item?id=3745916 ) brought up the issue of legal standing which I agree with. Facebook probably doesn't have legal standing (that is clear) but the mere fact they are raising the issue will stall the process and give them time to come up with a solution. And instill "carry on as usual nothing to see here" into facebook users.
They are getting out in front of the problem before it spins out of control.
Even if they wanted to build a case of coercion or duress they would need the cooperation of the employee to do this. And most importantly what is the specific harm done to facebook by this individual action? If I give you my facebook credentials and you login what damage has been done (to facebook in my specific case)?
If I was the opposing attorney I would raise the issue of whether they police and take action when people share their passwords in other cases. My guess is they have never taken action on something like this in the past.
And as far as changing their TOS what are they going to say? We forbid you from sharing your password with an employer (some might want to do this for some reason) or we forbid you to share with anyone? And if that is the case they have to police all sharing of passwords which, with hundreds of millions of users is simply not going to happen.
Permission to enter with a key does not necessarily transfer with possession of the key.
The analogy would be you rent a house and are given a key. And then you can give that key to someone else (like the cleaning person). You can also give the key to someone on Airbnb but that might be prohibited by other language ("you can't rent").
Your key example would be "does the employer have the right to give your password (which you gave them) to someone else". The answer to that is obviously "no" unless you told them it is ok to do.
Them letting you put a bit of your furniture in their house (i.e. content you own) doesn't mean the house itself is yours. Nor does it mean that your permission to enter their system necessarily transfers to other people even given that you happen to give those other people a copy of the key.
Accessing a computer system without authorization from the owner of that system is a crime. Facebook doesn't give authorization for employers to access their employee's accounts on their system, and explicitly forbids their users from transferring their own authorization to others.
As far as I can see, there is simply no way to construe an employer's access as authorized by the owner of the system i.e. Facebook.
As soon as you think about this in the context of a paid service, who can grant authorization becomes very clear. The fact that Facebook is providing a free service should not change a thing. It's still their service.
And actually this issues has been settled (you own it):
http://www.nytimes.com/2009/02/17/technology/internet/17face...
Next, check for example the T&C for 1and1.com web hosting (randomly picked).
http://order.1and1.com/Gtc?__lf=Static&linkOrigin=&l...
"You are responsible for maintaining the confidentiality of both your password and your account and are fully responsible for all activities that occur under your password and your account."
Now while 1and1 probably has some language that restricts your ability to resell something (same as you can't resell your cable connection) allowing someone to login (like your web designer?) to view what you have is most certainly not prohibited.
So if your employer said "I want your password to your webhosting account" I don't believe the web host would have standing and/or a cause of action.
>...(you) are fully responsible for all activities that occur under your password and your account
and Facebook's version, which goes: >You will not share your password, (or in the case of developers, your secret key), let anyone else access your account...
One says you're responsible for whatever happens on your account, the other explicitly says not to share your password. Kind of different, wouldn't you say?It's worth mentioning that letting randoms into your Facebook account isn't only playing chicken with your account security, you're also playing with the security of everyone you have friended, who implicitly trust that the only person on the account is the person who's name is on it.
That is something you do not have the right to do on an ethical level, let alone a legal one.
Is Facebook directly affected? Yes - people access their servers.
Harm, authorization etc etc can all be argued in the case, but there is no doubt at all that Facebook does have standing here.
I'm suspecting this could be posturing to stem the short-term damage while they try to get a law passed that gives them standing.
The best guess I could come up with is hitting the employer with some sort of cyber-hacking law, but I wouldn't be comfortable or happy with that sort of twisting of such a law.
http://en.m.wikipedia.org/wiki/MDY_Indus._LLC_v._Blizzard_En....
"The Court found that since the prohibition on botting was a prohibition related to Blizzard's copyright interest in WoW, users of Glider infringed Blizzard's copyright when played the game in violation of the license. The Court believed MDY to be encouraging and profiting from this copyright infringement, and therefore found MDY secondarily liable for the infringement"
Yes, it's a loophole in copyright law that can be used to massively expand it's scope. It is, however, well established in court.
This is in contrast to conventional EULAs, which forbid you from using the software until you agree to them (basically forbidding you to "receive" the software), and forbid you from any form of redistribution. The case hythloday cites is a EULA issue.
There's nothing abusive about how the GPL uses copyright law. If you violate the GPL and redistribute the software anyhow, that simply means that you are redistributing software without the consent of the owner, which is a very direct copyright violation, not a strange penumbric emanation or anything.
In other words, if the employer (Tortfeasor, Inc.) asks you to reveal your password, they're asking you to violate Facebook's TOS, which could be considered a contract you've entered into with Facebook, so Facebook could have grounds to sue the employer.
You'd have to ask a lawyer about the odds of Facebook winning such a suit, and what the damages might be. I'm just a programmer who gets his legal knowledge from Wikipedia.
Volokh discusses something else - what if the user does not allow the access voluntarily but is forced by the court (which, unlike employer, is entitled to use force to compel people to do things) to reveal the password. Then it would be like breaking into a house on a search warrant or forcing you to open the safe (this was discussed some time ago here because of other court decision that said - in TLDR version - that 5th amendment protects passwords). But that's different situation.
Because Facebook (the owner of the computer system) did not authorize the access. In fact, Facebook prohibits such access in its TOS.
If any potential employer asks for your Facebook account information, just inform them that your social network would not appreciate giving out their information to a 3rd party, and you think it would be a violation of their trust in you.
As a European working in the US, I find it astounding that these utter invasions of privacy are considered routine. I don't know whether they're legally acceptable in Europe, but they don't seem to be morally acceptable to most people.
Drug testing is uncommon outside the military however I did work for an IT outsourcing company who were threatening to bring it in at one point as it was standard practice in their US offices.
Never did it while I was there though, if they had they would have lost about 50% of their staff.
Obviously, this is not a relationship that exists in Europe.
Credit checking on the other hand I see as a complete invasion and I'm not convinced it would even give you anything useful, certainly not in this economy and likely not even in a good one.
A store clerk may be subjected to intrusive medical examination at any time; they are responsible for a few thousand dollar's worth of stock. A Wall Street trader is unlikely to be subjected to drug testing - drug use is, arguably, a part of their culture - despite being responsible for millions of dollars of other people's money.
For example, casinos drug-screen their employees, but I doubt that such drug screening happens to execs at the casinos who have more power/control over the money that the casino deals in.
As Nick Leeson said - nobody calls you a rogue trader when you're winning!
We've got a very liquid employment market. Easy to fire means easy to hire, which along with our healthy small business climate means if you've got something many companies would find disqualifying "on paper"* you're still going to be able to find ones that will hire you. Like the one that don't bother with background checks at all, they just see if you work out.
Traditionally we're big on second chances, e.g. move out of town for a fresh start. Things like the net and specifically Facebook are changing that, but there's still more than enough of it to make a big difference.
What are the legal implications for facebook applications? Are there some classes of applications that would be affected by this policy? Given enough permissions, most facebook apps DO access your account and could potentially violate the privacy of friends.
The facebook position above doesn't seem to be limited to employers, but much broader based. I could imagine a shady employer saying 'All candidates must install this (greedy permissions) app to submit an application'. What would be facebook's position on that?
Facebook Careers, Installing it allows you to jobsearch, be head hunted and fill in applications of course it also provides recruiters a huge amount of info about you.
I thought asking for personal information like marital status , age, etc.. is illegal in the U.S.
A quick Google search yielded "30 Interview Questions You Can't Ask"
Of the 30, I think about 20 can be learned from someone's Facebook account.
This is quite prevalent, and they make it very clear in the Acceptable Use policies that all usage is monitored.
Plus, you have the option to not access anything you want to keep personal from the office.
Yes, many companies have DLP (data loss prevention) systems what sniff all outbound data watching for information leaks. If you're posting on Facebook at work, it is very likely that your employer can see exactly what you're sending. We just don't care unless it's sensitive data (get back to work).
Weren't they, at one time, one of those sites trying to get your Gmail password/account so they could sniff out who your friends were?
In the extreme, this position gets really absurd. I never consented to allow gmail to store my email address in my friends' contact lists. At some point, "your" data becomes your friend's data and it's no longer yours to control.
http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:...
Human readable version
https://en.wikipedia.org/wiki/Data_Protection_Directive
Have fun over there
Your Facebook profile potentially contains clues about your national origin, religion, family status, and age (relevant if you're near 40).
Few employers are stupid enough to ask a woman if she's married in an interview.* Looking at Facebook can be the same thing.
* Policy guidance for employers urges them to avoid these issues (for good reason): http://web.uflib.ufl.edu/pers/develop/departmentalinterviewi... ; http://www.businesslink.gov.uk/bdotg/action/detail?itemId=10...
I have mixed feelings about the whole account access thing though.
On the one hand, I do think it's entirely unreasonable for your employer to have your password. There are certain exceptions to this (eg anything requiring Top Secret clearance?).
On the other hand, my personal view is nothing on the Internet is truly private. If you want it to remain private, you shouldn't put it on the Internet in any form, otherwise it's just a privacy policy change or a security breach or a bug away from being exposed.
The internet is fast becoming the only communication channel so not using it for anything private will rapidly become impossible.
I've read about police and city agencies requiring social networking passwords to be given up. Same for departments of corrections. Here's a photo of a job application for a clerical position at a police dept: http://i.imgur.com/hWsZT.jpg (From this reddit thread: http://www.reddit.com/r/WTF/comments/mtenb/wife_came_across_...)
It's apparently quite common. The real kicker is when they also include a non-disparagement agreement in the hiring process, so that they can easily fire you for non-publicly posting about your job.
Combine psychotic parents, "cyber bullying" (a crisis de jure), morals clauses in contracts, "think of the children" attitude, and sometimes tyrannical administration, and you get crazy stuff like this.
(1) http://www.aclu.org/blog/technology-and-liberty/want-job-pas...
I don't know the first thing about facebook app development. Seems like it could be easy to write up. Is it easy for facebook to kill such apps? Am I just making things up that don't make sense?
Which makes a fair bit of sense, because having an app do it would go through FBs own privacy control schemes.
So I guess we also have to make sure that employers can't require prospects to install apps. :/?
Employers that have these sort of practices deserve nothing less than business failure and I think that if enough key employees pack their bags that they will sooner or later get the message. Make it plain what the reason for your resignation is and if you can blog about it, I think that the spotlight of public opinion should help ram home the message that this sort of behavior is off-limits.
And that goes for any other service besides facebook as well, your private affairs are your private affairs, and any employer that wants to stick their nose in does not deserve your brain power.
http://www.zdnet.com/blog/facebook/facebook-no-plans-to-sue-...
And why this focus on facebook? Is password to gmail or mint.com or yahoogroups different? It looks like Facebook using lawmaking system as a PR move. That's definitely a new and creative development - using the Congress as an advertisement medium - but I don't think it's a welcome one.
Facebook is built around private stuff. The expectation is that the only people who will see it are the people who should be seeing it.
And why this focus on facebook?
Because employers are not asking for other passwords as often as Facebook passwords, and Facebook has a lot more relevant information. Asking for Mint logins would be a blatant violation of PCI laws.
If I don't behave to their liking they could of course cancel my account but that's pretty much it.
However as you would voluntarily give up the key that becomes complicated; a court would have to decide that you were given no choice (give up the password, or give up the job).
A United States District Court considered whether the Computer Fraud and Abuse Act criminalized TOS violations, and the court concluded that such a statute would be unconstitutional as applied in such a situation under the "void for vagueness" doctrine. U.S. v. Lori Drew, 259 F.R.D. 449 (C.D. Cal. 2009).
This is like handing out private photo albums or access to the private email account. Any employer demanding this from me can happily continue to be an employer without me as employee (not that I have anything in my FB account anyway, but it's a matter of principle).
The answer might be much more illuminating than anything an employer would ever learn from looking at the Facebook account itself.
What happend to their "Share everything with everyone!" policy?
Honestly. I think FB have had a bad rap over the privacy thing - a long time ago they were very bad. But so were a lot of people, they were just bigger.
Since then (which would have been about 2010, I guess) they've been fairly on the ball with security issues... and though some people disagree with the direction they went, they have built in an awful lot of privacy control.
</sarcasm>
I'm definitely against random employers asking for a fb password (or rather, access...there should be a way to give them read only access without the password, in any case). Just getting the username (to see what is posted publicly) is more defensible, as is getting deeper access for a security clearance (my credit report is basically boring; interviewing my friends is more useful, but I have literally never spoken to any of my neighbors more than twice each, and never at any length; this is probably not that uncommon). My Facebook account would be a good way to easily get that information.
What they should get is actually a snapshot, attested to by Facebook, of the configuration of the facebook account (data export/data dump) from a time chosen before you applied for the clearance, assuming Facebook could reconstruct that. That way I can't remove my anarchist/communist party friends; they could ask for a snapshot randomly selected in a 0-7 or 0-10 year interval beforehand.
I actually trust Facebook security (and my personal password management and computing environment) to be secure against accidental disclosure MORE than I trust OPM or the OPM contractors who do clearance investigations, and certainly more than the shitty credit check plus type investigators most private firms, state/local agencies use. So, giving long-lived access to my facebook profile (or password) would be a bigger cost than just giving them the data. (There have been several cases of laptops without full disk encryption going missing...) Incidentally, it might be interesting to note that most security clearance investigations are actually processed almost entirely by contractors working for the government, not by GS employees, since sometime in the 1990s.
I still don't believe in asking for or giving out FB profile info (beyond "make sure your public facebook profile is professional", for a public-facing role; that seems pretty reasonable to me, although what you have in your friends-locked area is up to you), but if you're going to do it, do it right.
I don't think it's unreasonable to include online social networking profiles in that.
Similarly, a court order should be able to get all the data from a profile, but not to allow the government to masquerade as you by logging in and actively communicating with others.
This has all been debated during the "key escrow" debate period; even the government wasn't able to make an argument for signing key escrow, only encryption key escrow. It's the same issue with a profile.
(I am generally against key escrow, but eliminating some classes of keys from the debate off the bat was a useful strategy then; it would be more useful now.)
The SSBI is not significantly more thorough than has become common for many private employees, and doesn't find, attempt to find, or care about a great deal of the personal information that may be found in a Facebook profile.
> Similarly, a court order should be able to get all the data from a profile, but not to allow the government to masquerade as you by logging in and actively communicating with others.
Facebook has been providing information in response to court orders for years, but does not provide the ability to masquerade as the user.