Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - New Facebook Privacy Issues
News & Analysis

New Facebook Privacy Issues

ISBuzz TeamBy ISBuzz TeamFebruary 16, 2018Updated:July 4, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Experts from security and privacy advice and comparison website Comparitech commented on two new developments affecting Facebook users this week:

German court rules Facebook use of personal data illegal

Lee Munson, Security Researcher at Comparitech:

“A German court ruling – that Facebook does not go far enough in obtaining consent from users before using their personal data – could have far-reaching consequences for the social media giant. With the incoming European-wide General Data Protection Regulation (GDPR) placing a heavy emphasis on consumer privacy, not to mention a legislative framework, such a decision in one member state is likely to carry across all of them.

To counteract this decision, Facebook needs to become far more transparent about the data it is collecting and the way in which it is using that information. Not only that, it also needs to be much, much clearer in how it communicates its data usage policy to its users.

In the meantime, and certainly before GDPR comes into effect, users should always take the time to read and understand the privacy policies provided by every website that they visit and should not be afraid to walk away from any that are too demanding for their own personal tastes.”

Facebook is pushing its data-tracking Onavo VPN within its main mobile app

Paul Bischoff, privacy advocate at Comparitech:

“As of this week, some Facebook users on iOS devices have a new feature called “Protect” added to the app’s navigation menu. Clicking the link directs the user to a download page for Onavo Protect, a VPN service. Onavo’s App Store page says it can “warn you when you visit potentially malicious or harmful sites, help secure your personal information when you’re on public Wi-Fi,” and “add an extra layer of protection to all of your mobile data traffic by using our VPN.”

But Onavo’s real purpose undermines those claims. The company was acquired by Facebook in 2013. Whereas reputable VPN services do everything they can to protect users’ privacy, Onavo monitors and records what users do online while connected. In particular, this allows Facebook to keep track of what other apps people use, how they use them, and when they use them. The company’s app store description goes on to say it is used to “improve Facebook products and services, gain insights into the products and service people value, and build better experiences.”

Like most VPNs, Onavo encrypts all the internet traffic traveling to or from a device and routes it through an intermediary server in a remote location. This hardens your security, particularly when connected to public wifi. It can also prevent your internet service provider from monitoring what you do online.

he difference is that reputable, paid VPN providers don’t monitor or record users’ traffic. The best of them don’t even log metadata like IP addresses and timestamps. Onavo users, however, are just trading one raw deal for another. Instead of your ISP monitoring everything you do online, Facebook can record all of that data instead. Facebook isn’t interested in protecting its users’ privacy. The Onavo acquisition is a specious attempt for the company to get its hands on more data—data that a serious VPN provider wouldn’t dare record and Facebook users should not hand over lightly.

Avoid Onavo Protect like the plague.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}