Prosecutors Sue Facebook Over Cambridge Analytica

The US federal district of Washington DC is suing Facebook for Cambridge Analytica access to the individual data of millions of the site’s users without their permission being asked for.

Prosecutors said 852 D.C. users downloaded the misleading application provided by Cambridge Analytica but that a much larger portion of DC residents, approximately 340,000 people, had their data collected because they were friends of those initial users through Facebook. 

This could mean Facebook faces a fine of up to $1.7 billion if all 340,000 instances are considered “violations” under the statute.

However, it seems that this might just be the beginning of a major Facebook data sharing problem as there is now discussion over whether Spotify and Netflix have the options to read and or trash personal messages. Facebook also is being accused of using location-based advertising after a user has even blocked that company’s GPS access on their phones. 

“Facebook failed to protect the privacy of its users and deceived them about who had access to their data and how it was used,” the city’s attorney general, Karl Racine.

“Facebook put users at risk of manipulation by allowing companies like Cambridge Analytica and other third-party applications to collect personal data without users’ permission. Today’s lawsuit is about making Facebook live up to its promise to protect its users’ privacy.”

Facebook, has more than 2 billion active users around the world. Through a website and a mobile application which allows users to communicate and share content with personalised networks of “friends.”

An investigation earlier in 2018 found that Cambridge Analytica, which worked for Donald Trump’s political campaign, had collected Facebook profiles data of more than 50 million users without their permission. The DC attorney general said that this process exposed almost half of the district’s residents’ data to potential political manipulation in the 2016 presidential election. 

In a statement, Facebook said: “None of these partnerships or features gave companies access to information without people’s permission, nor did they violate our 2012 settlement with the FTC.”

“Facebook does not use WiFi data to determine your location for ads if you have location services turned off. We do use IP and other information such as check-ins and current city from your profile. We explain this to people, including in our Privacy Basics site and on the About Facebook Ads site.”

However, there is no obvious combination of settings that users can employ to prevent their location from being used by advertisers to target them.

The district attorney said the maximum penalty under the act is $5,000 “per violation”. However, the law in not clear as to what may constitute a single violation according to the regulations.

Original News by CSI

You MIght Also Read:

The Cambridge Analytica Scandal 'highlights need for AI regulation':

 

« China’s Hackers Have Stolen EU, US & Global Secrets
Cyber Attacks On Business Are Surging »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Securezoo

Securezoo

Securezoo's mission is to simplify and enhance information security by providing trusted security guidance, products, and information to small and mid-sized businesses and security professionals.

Spiceworks

Spiceworks

Spiceworks provide a range of free apps for IT professionals including network inventory, network monitor, and help desk.

CERT.BY

CERT.BY

The National Computer Emergency Response Team of the Republic of Belarus.

StickyMinds

StickyMinds

StickyMinds is the web's first interactive testing community exclusively engaged in improving software quality throughout the software development lifecycle.

Cyber Risk Agency

Cyber Risk Agency

Cyber Risk Agency is a cybersecurity consulting firm specializing in managing cyber risks for SMEs.

Retail & Hospitality Information Sharing & Analysis Center (RH-ISAC)

Retail & Hospitality Information Sharing & Analysis Center (RH-ISAC)

Retail & Hospitality ISAC operates as a central hub for sharing sector-specific cyber security information and intelligence.

IDnext

IDnext

IDnext is the open and independent platform to support innovative approaches in the world of the Digital identity.

R2S Technologies

R2S Technologies

R2S can help you implement a cyber security framework to ensure your business is more resilient towards the growing threat of cyber crime. We provide Web and Mobile Application Security Assessment..

ITRenew

ITRenew

ITRenew is a leading global IT lifecycle management solutions company, specializing in onsite data center decommissioning and data erasure services.

Cyber@StationF

Cyber@StationF

Cyber@StationF is an up to 6 months international startup acceleration programme, whose members provide solutions for the Cybersecurity industry.

ditno

ditno

ditno uses machine learning to help you build a fully governed and micro-segmented network. Dramatically mitigate risk and prevent lateral movement across your organisation – all from one centralised

Bugbank

Bugbank

Bugbank (aka Vulnerability Bank) is a leading SaaS platform for internet security services in China.

Quad9 Foundation

Quad9 Foundation

Quad9 is a free security solution that uses DNS to protect your system against the most common cyber threats. It improves your system's performance, plus, it preserves and protects your privacy.

Creative ITC

Creative ITC

Creative ITC is a leading infrastructure and cloud enablement company. We design and deliver exceptional managed services and cloud solutions.

Astran

Astran

At Astran, we revolutionize data security by introducing a groundbreaking solution for data confidentiality headaches.

eGeneration

eGeneration

eGeneration is one of the leading technology solutions and system integration companies in Bangladesh.