Montana city asks for social network logins on job application
montanasnewsstation.com
montanasnewsstation.com
1. Most sites have a terms of service that says you will not give you login information out to anyone else, or allow anyone else to login to your account. So by requesting this information the City is asking potential applications to violate a contract. Especially since they specifically mentioned Facebook and this is in the Facebook ToS.
2. There are a lot of things that are illegal for employers to ask for (sexual preference, groups that you belong to, ethnicity, etc) and most of these things are present in someone's Facebook profile. So by requiring access to Facebook, you are requiring them to hand over access to information that it is illegal to require...
3. Lots of people use the same password for multiple accounts. Their Facebook password could be their online banking password. That puts an employer at a HUGE liability if one of the employees breaks into this information to do some identity theft. Even if some 3rd party gains access through another method, you could be investigated as the possible leak and/or theif.
4. By requiring users to provide this information (i.e. passwords to personal accounts) you're only going to end up with employees that will easily give out secure information. The vulnerability of your workplace to social engineering attacks will go WAY up because anyone that would be smart enough to question whether there really is a 'Bob from IT' that 'needs their password' are people that wouldn't fill in their information into the application.
5. Employers that do this open themselves up to possible lawsuits from people for requiring information that no one will ever truthfully fill out and then using it as some sort of 'we can fire you at any time because we know that you lied on your application' carrot over someone's head.
Edit:
Also, I could give my Facebook login to this employer. Deface my Facebook account, then claim that the company/ did it b/c the company had access to that information.
You have to figure that just statistically, one of them is going to do something stupid in hiring every once in awhile.
Is there are broader point to be made here?
Besides, while this kind of practice may be particularly loathsome to us it doesn't seem to be bothering the people filling out the applications. The article says no candidate has withdrawn from consideration over the policy. Further, when presented with an alternative method to check out profiles without usernames and passwords they said they'd look into it. It seems like a simple mistake made by someone who doesn't necessarily have the most acute awareness of how social networking sites work.
All of a sudden, we have this dossier we share with our friends (similar to the memories of going to a party or whatnot) that is now a dossier that companies want to see. Not only that, but there's an interesting legal issue here: are companies allowed to inspect your private property?
Can a company looking to hire someone say, "we'd like to hire you, but first you need to give us the keys to your house so we can rummage around and see if there's anything we don't like in there."? That's a huge invasion of privacy. Likewise, our social networking profiles often have privacy controls for similar reasons - and sets them up to be sued very easily.
For example, (generally speaking) a company isn't allowed to discriminate on religious grounds when hiring. If an HR person asks about it and doesn't hire you, you've got decent grounds to sue. By asking for my social networking password, they can get access to that information without asking for it. Likewise, there's all sorts of stuff on our profiles that you can't ask about during an interview without running afoul of the law.
The broader point is that there's a potential loss of privacy and employment rights here that's very serious. If someone decides not to hire me because of my sexual orientation that they learned from getting my social networking password, that's highly illegal. And this is a way of getting those questions answered that aren't allowed to be asked without it seeming like you're asking them.
Social networks are for "friends". People we want to share certain data with easily. This data is often things we don't want potential employers to see or use in judging us - not because it paints us in a bad light like red solo cups might, but because my sexual orientation, political affiliation, group affiliations, religion, relationship status, etc. are all not things that employers should have the right to use when determining whether I am a good employee.
This reminds me of the Milgram Experiment, in that very few will refuse authorities orders on even severe matters (in the experiment it was potentially killing someone), so why are people going to refuse it on something seen to be as trivial as a facebook password. However, this is a breach of one of the fundamental human rights, the privacy of thought which in the US has been extended, in some cases, to entire laptops at border crossings.
Friends and business associates of the job applicant also have privacy expectations around content they intend to be viewable only by trusted individuals.
The tools of change are technological, not legal. Instead of trying to change the law, render it obsolete and utterly unenforcable, and "win" by fait accompli.
I feel a similar way about file sharing. I personally believe very strongly that the ability to send arbitrary files to arbitrary recipients unmolested is a right akin to free speech. But there is no point trying to "beat the system". The solution is to invent technology which renders the law an unenforcable joke.
It's a great time to be a programmer. The tools and opportunity to change the future course of events are right in front of us, to a degree far in excess of what your average non-billionaire voter (or lawyer) could ever enjoy.
We don't need more individual lawsuits. We need plausible deniability implemented in social networks, at a stroke rendering unreliable the whole practise of evaluating someone by their online activities. Sounds like a challenge to me!
But why not attack the problem from multiple points? Attack with both a legal and technological response.
"You know, I can understand that concern. One thing that's important for folks to understand about what we look for is none of the things that the federal constitution lists as protected things, we don't use those. We're not putting out this broad brush stroke of trying to find out all kinds of information about the person that we're not able to use or shouldn't use in the hiring process," Sullivan said.
I think they get it just fine, they just don't care.
I'm actually surprised that we haven't seen a news story about that, perhaps because if it happens you'll never know that's why you didn't get the job. As more people come on the Internet, the odds of your name or handle being truly unique go down. The google results for "jerf" have gone from all me, all the time in 1999, to a random hodgepodge of results, mostly courtesy of user accounts on high-page-rank services I don't use that aren't me, oh, and oi for that Urban Dictionary result. (That one was news to me. I could have gone without knowing that one, even though I'm sure it's another of UB's crappy "some guy somewhere used this word once and I'm going to put it on UB" results.) And my real name's results have long since been cluttered by "not me", some of which are even close enough to me to be confusing to a potential employer due to technology interests.