7 ms·
Facebook: Legal action against employers asking for your password
- rdl 14y agoThis is a very reasonable action for Facebook to take to protect its brand and product. I'm definitely against random employers asking for a fb password (or rather, access...there should be a way to give them read only access without the password, in any case). Just getting the username (to see what is posted publicly) is more defensible, as is getting deeper access for a security clearance (my credit report is basically boring; interviewing my friends is more useful, but I have literally never spoken to any of my neighbors more than twice each, and never at any length; this is probably not that uncommon). My Facebook account would be a good way to easily get that information.
- click170 14y agoHow would giving them read-only access be significantly better than the current situation of them demanding read-write access? They aren't asking so they can pretend to be you, they're asking so they can snoop on what you've posted that isn't public..
- rdl 14y agoBecause they don't need write access. It's a basic principle of security to only give people the access they need -- it keeps them honest, and protects you if they're dishonest or incompetent (or both). What they should get is actually a snapshot, attested to by Facebook, of the configuration of the facebook account (data export/data dump) from a time chosen before you applied for the clearance, assuming Facebook could reconstruct that. That way I can't remove my anarchist/communist party friends; they could ask for a snapshot randomly selected in a 0-7 or 0-10 year interval beforehand. I actually trust Facebook security (and my personal password management and computing environment) to be secure against accidental disclosure MORE than I trust OPM or the OPM contractors who do clearance investigations, and certainly more than the shitty credit check plus type investigators most private firms, state/local agencies use. So, giving long-lived access to my facebook profile (or password) would be a bigger cost than just giving them the data. (There have been several cases of laptops without full disk encryption going missing...) Incidentally, it might be interesting to note that most security clearance investigations are actually processed almost entirely by contractors working for the government, not by GS employees, since sometime in the 1990s. I still don't believe in asking for or giving out FB profile info (beyond "make sure your public facebook profile is professional", for a public-facing role; that seems pretty reasonable to me, although what you have in your friends-locked area is up to you), but if you're going to do it, do it right.
- nknight 14y agoThey don't need read access, either. This is about an invasion of privacy, not technical capabilities.
- rdl 14y agoThere are already cases where people consent to credit and background checks (fairly thorough; talking to neighbors, friends, etc. at length, for 7-10 years). These are voluntary checks for high level security clearances with the government. I don't think it's unreasonable to include online social networking profiles in that. Similarly, a court order should be able to get all the data from a profile, but not to allow the government to masquerade as you by logging in and actively communicating with others. This has all been debated during the "key escrow" debate period; even the government wasn't able to make an argument for signing key escrow, only encryption key escrow. It's the same issue with a profile. (I am generally against key escrow, but eliminating some classes of keys from the debate off the bat was a useful strategy then; it would be more useful now.)
- nknight 14y ago> There are already cases where people consent to credit and background checks (fairly thorough; talking to neighbors, friends, etc. at length, for 7-10 years). These are voluntary checks for high level security clearances with the government. The SSBI is not significantly more thorough than has become common for many private employees, and doesn't find, attempt to find, or care about a great deal of the personal information that may be found in a Facebook profile. > Similarly, a court order should be able to get all the data from a profile, but not to allow the government to masquerade as you by logging in and actively communicating with others. Facebook has been providing information in response to court orders for years, but does not provide the ability to masquerade as the user.
- lutorm 14y agoI fail to see how "my password is under an NDA" could not be a sufficient response to this silliness. Are they really making breach of contract a necessary condition for employment?
- deleted 14y ago[deleted]
- marshray 14y agoIf you're unemployed and need a job, the choice between defending Facebook's NDA and putting food on the table is obvious. I doubt most people even realize that somewhere in Facebook's ToS it says they mustn't disclose their password.
- JGailor 14y agoFacebook played the Friend card in their press release, and did it really well. If you are giving up your Facebook password, you're not just giving up your information, you're also giving up your friend's information as well. If any potential employer asks for your Facebook account information, just inform them that your social network would not appreciate giving out their information to a 3rd party, and you think it would be a violation of their trust in you.
- prophetjohn 14y agoIf an employer asks for my Facebook password (or equivalent, as I don't use Facebook), I plan to tell them that I don't appreciate being asked to give out my information. I don't want to work for a company where I need to put spin on an argument to have them not violate my privacy.
- wtvanhest 14y agoThis is not about you, I or other highly employable people. This is about person trying to get any job they can.
- pyre 14y agoIt's also about law enforcement jobs where they might hold it against you if you refuse. You have a right to refuse, but then they can just deny you the job because you "obviously" have something to hide.
- CGamesPlay 14y agoThe reason that this sort of legal action is necessary is because the kind of people who are being asked this aren't the kind of people who can walk into any company in the valley and get another job. In those situations, the employee doesn't have any cards to play.
- JGailor 14y agoI understand your point completely, and I agree with you. It still doesn't change the fact that when you give up your Facebook account information, you are not just surrendering up your personal information, you are giving up the personal information of everyone in your network that has chosen to share with you. It's a breach of trust with that network.
- dminor 14y agoClearly what we need is a dummy password that leads to a bland profile where your "friends" all note how employable you are.
- judofyr 14y agoRight, but then the employee will only ask for both your passwords…
- codesuela 14y agonot if this is not the default. If they were to implement it they would do it like Truecrypt where you are able to choose between "normal" encryption and creating a hidden volume which allows for plausible deniability ( see https://en.wikipedia.org/wiki/Plausible_deniability#Use_in_cryptography https://en.wikipedia.org/wiki/Plausible_deniability#Use_in_c... ).
- ErrantX 14y agoI think this is an example of somewhere where a legal solution is preferable to "plausible deniability" - at least in terms of ease of use for the majority of FaceBook users :)
- free 14y agoDid I miss the sarcasm? How is that clear to you? I thought asking for personal information like marital status , age, etc.. is illegal in the U.S.
- sixothree 14y agoThat would be the initial reaction for most job seekers. And I'm betting that's exactly what facebook was trying to prevent with this move.
- deleted 14y ago[deleted]
- powrtoch 14y agoI have to say, I'm really impressed with Facebook for coming out and making this their issue, instead of just waiting for the applicants and employers to slowly work it out between themselves. In hindsight, it's seems like an obviously smart move (both to impress their userbase and to remove disincentives to use Facebook), but somehow it didn't occur to me that they might join in on the fight. Good for them.
- nextparadigms 14y agoI actually expected them to do this, because it would've been to their detriment if they didn't. If asking for the employees password became a "thing", people would've started quitting Facebook, or at the very least try to make fake accounts for their employers. But even so, it's still nice to see them actually doing it.
- orbitingpluto 14y agoAgreed. Damn good PR move. <sarcasm> Plus those employers shouldn't be getting their Facebook background checks for free. FB has to protect it's future revenue streams! </sarcasm> When FB starts protecting user data from everybody, individuals, business and government, that'll be something. Might even be worth having to wade through your aunt's cats-in-clothing posts.
- joering2 14y agoHOW can Facebook, or anyone else _successfully_ protect user data from government without breaking the law?
- orbitingpluto 14y agoBy providing at least token resistance? People shouldn't be getting roped in by the law because law enforcement has free reign to peruse profiles. As well, infiltrating profiles by 'social hacking' (aka asking to friend someone by having a profile with breasts on it) shouldn't be allowed by law enforcement doing fishing operations. In other words, communications on Facebook should be considered as private communication. Monetization by anonymous advertising akin to Google's model should be the accepted quid pro quo for usage.
- bburns 14y agoDoesn't this fall into the realm of discriminatory interview questions to begin with? I'm pretty sure a case could be made in a discriminatory hiring suit without introducing new laws.
- TomatoTomato 14y agoThis was my first response. A quick Google search yielded "30 Interview Questions You Can't Ask" Of the 30, I think about 20 can be learned from someone's Facebook account.
- rmc 14y agoI'd have always thought that if you were to give out your password, you'd never be (legally) allowed to access your facebook account again (since you'd be in breech of the terms of service). And also that the potential employer would not legally be allowed to access it, since they'd be accessing a computer system, by pretending to be someone else.
- tjoff 14y agoI'd have always thought that the terms of service (that I haven't signed (checking a check box doesn't count)) couldn't just make something, that wasn't already, illegal. If I don't behave to their liking they could of course cancel my account but that's pretty much it.
- TomatoTomato 14y agoComputer Fraud and Abuse Act of 1986 has been stretched such that federal prosecutors have won convictions based on the theory that violating a website’s ‘terms of service’ is a crime under this law. However, eventually it was deemed that this may be too broad a standard, but no clear decision has been made.
- ErrantX 14y agoSomeone suggested to me earlier that it might be possible to call it unauthorised access, which is a crime under that act. However as you would voluntarily give up the key that becomes complicated; a court would have to decide that you were given no choice (give up the password, or give up the job).
- tomp 14y agoI support Facebook's stance on this, but I'm also quite surprised! What happend to their "Share everything with everyone!" policy?
- ErrantX 14y agoThey changed it ages ago to "Share everything you want with everyone!" Honestly. I think FB have had a bad rap over the privacy thing - a long time ago they were very bad. But so were a lot of people, they were just bigger. Since then (which would have been about 2010, I guess) they've been fairly on the ball with security issues... and though some people disagree with the direction they went, they have built in an awful lot of privacy control.
- kposehn 14y agoI figure I'll ask potential employees of mine if they've ever given their password out instead. If they say yes, I'll say "...why?" The answer might be much more illuminating than anything an employer would ever learn from looking at the Facebook account itself.
- TomatoTomato 14y agoYou have nothing to fear if you have nothing to hide. </sarcasm>
- djb_hackernews 14y agoWho is actually asking for FB passwords? I doubt anyone actually is, and if they are it's part of a scam involving the promise of employment to desperate people.
- jonknee 14y agoIf what I've read is true, lots of places. A school teacher in my area just got fired for making a student give access to his/her Facebook account which the teacher used to punish students who had talked about the teacher. I've read about police and city agencies requiring social networking passwords to be given up. Same for departments of corrections. Here's a photo of a job application for a clerical position at a police dept: http://i.imgur.com/hWsZT.jpg http://i.imgur.com/hWsZT.jpg (From this reddit thread: http://www.reddit.com/r/WTF/comments/mtenb/wife_came_across_this_on_a_job_application/ http://www.reddit.com/r/WTF/comments/mtenb/wife_came_across_...) It's apparently quite common. The real kicker is when they also include a non-disparagement agreement in the hiring process, so that they can easily fire you for non-publicly posting about your job.
- simonbrown 14y agoI have accounts on around 200 sites. Would I need to list every single one?
- cageface 14y agoFirst link in the story: http://www.zdnet.com/blog/facebook/employer-demands-facebook-login-credentials-during-interview/327?tag=content;siu-container http://www.zdnet.com/blog/facebook/employer-demands-facebook...
- Duff 14y agoSchools are breeding grounds for this sort of thing. Combine psychotic parents, "cyber bullying" (a crisis de jure), morals clauses in contracts, "think of the children" attitude, and sometimes tyrannical administration, and you get crazy stuff like this.
- maigret 14y ago
- balakk 14y agoWhat about employers intercepting SSL connections to spy on social networking/external email usage on the corporate network? Is that against the law too? Genuine question. This is quite prevalent, and they make it very clear in the Acceptable Use policies that all usage is monitored.
- mvip 14y agoIf your employer is doing that, it probably a good time to start looking for another job.
- marshray 14y agoSome of those jobs pay really really well. Plus, you have the option to not access anything you want to keep personal from the office.
- freehunter 14y agoWhy? Anything you do at work is open to your place of employment. I work in network/information security, and while we don't decrypt encrypted connections, we do log employee Internet access and use the data for investigative purposes. Why would an employee have an expectation of privacy from their employer while they are using corporate assets? Yes, many companies have DLP (data loss prevention) systems what sniff all outbound data watching for information leaks. If you're posting on Facebook at work, it is very likely that your employer can see exactly what you're sending. We just don't care unless it's sensitive data (get back to work).
- reginaldo 14y agoIANAL, and I don't live in the US either, but I can tell you that at least here in Brazil the network traffic is the property of the employer, and you have no expectation of privacy while working, so they can do whatever they want with the traffic that is going to their routers.
- davidwparker 14y agoMost jobs that I know that would do that actually just block those sites though. They sniff and block.
- davidw 14y ago> “If you are a Facebook user, you should never have to share your password, let anyone access your account, or do anything that might jeopardize the security of your account or violate the privacy of your friends,” Weren't they, at one time, one of those sites trying to get your Gmail password/account so they could sniff out who your friends were?
- DevX101 14y agoYes. In fact, I'd argue that privacy invasion played one of the most important roles in the rapid rise of Facebook and LinkedIn
- drivebyacct2 14y agoPrivacy invasion? It has always explicitly said "enter your gmail username and password so we can import your contacts" or something equally obvious and transparent.
- DevX101 14y agoThe privacy invasion is for the contacts who never consented to give Facebook their information.
- kiloaper 14y agoSame thing with Viber and other apps. Some of friends use their services and now they have my contact information and can build up a shadow profile on me. I consented to none of that. While they may deny that's their intent it doesn't change the fact they have all that data.
- davidw 14y agoAlso, it contributes to a culture of "sure, I'll give you my login information".
- tedunangst 14y ago
- DevX101 14y ago| “If you are a Facebook user, you should never have to share your password, let anyone access your account, or do anything that might jeopardize the security of your account or violate the privacy of your friends,” What are the legal implications for facebook applications? Are there some classes of applications that would be affected by this policy? Given enough permissions, most facebook apps DO access your account and could potentially violate the privacy of friends. The facebook position above doesn't seem to be limited to employers, but much broader based. I could imagine a shady employer saying 'All candidates must install this (greedy permissions) app to submit an application'. What would be facebook's position on that?
- jiggy2011 14y agohmm , sounds like a great opportunity for a startup! Facebook Careers, Installing it allows you to jobsearch, be head hunted and fill in applications of course it also provides recruiters a huge amount of info about you.
- freehunter 14y agoLike LinkedIn? Where the only information posted is exactly what you want employers to see?
- jerf 14y agoOn what grounds could Facebook sue an employer who asks for your Facebook password? It isn't immediately obvious they have standing to sue the employers. Based on what I assume is their terms of service page (closest thing I could find) [1], it looks like they could sue the employee for giving away their password, but I don't immediately see any grounds for suing the employer. There doesn't seem to be anything forbidding you from using Facebook with somebody else's account at the moment (though look for this to change any minute). I'm suspecting this could be posturing to stem the short-term damage while they try to get a law passed that gives them standing. The best guess I could come up with is hitting the employer with some sort of cyber-hacking law, but I wouldn't be comfortable or happy with that sort of twisting of such a law. [1]: http://www.facebook.com/legal/terms http://www.facebook.com/legal/terms
- hythloday 14y agoI think Blizzard vs. MDY suggests that inducing a user to break the TOS renders the inducer liable to claims of copyright infringement. http://en.m.wikipedia.org/wiki/MDY_Indus._LLC_v._Blizzard_Entmt,_Inc http://en.m.wikipedia.org/wiki/MDY_Indus._LLC_v._Blizzard_En.... "The Court found that since the prohibition on botting was a prohibition related to Blizzard's copyright interest in WoW, users of Glider infringed Blizzard's copyright when played the game in violation of the license. The Court believed MDY to be encouraging and profiting from this copyright infringement, and therefore found MDY secondarily liable for the infringement"
- rhizome 14y agoWhile apparently successful in this case, that would appear to be a gross misuse of copyright and this layman would say that Blizzard got lucky and the judgement as precedent sounds fragile.
- Tuna-Fish 14y agoThat's exactly the way GPL misuses copyright to enforce terms on people who have not agreed to contracts with the software provider. Yes, it's a loophole in copyright law that can be used to massively expand it's scope. It is, however, well established in court.
- cletus 14y agoGood for Facebook for standing up against this sort of thing. I have mixed feelings about the whole account access thing though. On the one hand, I do think it's entirely unreasonable for your employer to have your password. There are certain exceptions to this (eg anything requiring Top Secret clearance?). On the other hand, my personal view is nothing on the Internet is truly private. If you want it to remain private, you shouldn't put it on the Internet in any form, otherwise it's just a privacy policy change or a security breach or a bug away from being exposed.
- jiggy2011 14y agoThis is true, however if you treat everything on the Internet as public then that removes many possible uses for it. The internet is fast becoming the only communication channel so not using it for anything private will rapidly become impossible.
- why-el 14y agoHow about attacks on privacy that use other channels? I dont quite understand the idea tat if you want to protect your privacy, you should stay away from the internet. This, 1) gives other privacy invaders a free pass, and 2) makes the internet look like a platform incapable of crafting its own laws.
- duck 14y ago"You want my FB password? Sure, but please know that if anyone asks for my company computer account password I will comply with that as well."
- jiggy2011 14y agoonly for a bar of chocolate!
- deleted 14y ago[deleted]
- DanI-S 14y agoI wish there were someone willing to stand up for us against employment-related credit checks and drug testing, too. As a European working in the US, I find it astounding that these utter invasions of privacy are considered routine. I don't know whether they're legally acceptable in Europe, but they don't seem to be morally acceptable to most people.
- jiggy2011 14y agoThey are legal certainly in the UK , perhaps less common. Credit checks are fairly common though, especially for finance type institutions Drug testing is uncommon outside the military however I did work for an IT outsourcing company who were threatening to bring it in at one point as it was standard practice in their US offices. Never did it while I was there though, if they had they would have lost about 50% of their staff.
- mjwalshe 14y agoDV security clearance requires drug tests in the UK
- quandrum 14y agoOne thing to remember in the US is that health insurance companies drive a lot of the drug testing. They offer it for free to employers, and in return get the benefit of never having (suspected) addicts try to obtain employer based coverage. Obviously, this is not a relationship that exists in Europe.
- DanI-S 14y agoThat's fascinating, disturbing and something I had not considered.
- dredmorbius 14y ago[Citation needed]
- simcop2387 14y ago
- parvinsingh 14y agoWell, you dont need pwd to piggyback into a user's account. Since the userID/pwd validation is theirs, they can bypass the validation if they want based on some prefix or suffix in the userID field.
- soupysoupysoup 14y agoAm I wrong in thinking the only thing this does is protect Facebook's financial interests? Don't they profit from the proper app and ad based mining and selling of this information anyway? There are so many references to the underground background checking methods employed by legal abuses of social networking, wouldn't it take a huge chunk out of their business model to have individuals simply show the information directly to employers, free of charge?
- AsylumWarden 14y agoThat is why I have a dummy facebook account. Seriously, when I give someone else access to my account they can then also peer into the lives of my family and friends many of whom only post with security settings that share only with Friends or just Family. I've then given away their right to privacy as well. Uggg....
- stef25 14y agoIdea: Facebook could add an alternate password feature that, if entered only shows content you can manage in your privacy settings. So just like you could hide an album from certain friends, you could hide other content (from yourself) if your alt password is entered. Kind of like plausible deniability in TrueCrypt.
- shreeshga 14y agoEmployers want passwords of FB and not LinkedIn accounts? Thats cruel on LinkedIn.
- laconian 14y agoI like this trend of the big Internet companies taking proactice steps to right the wrongs that are happening in their space. If only more companies had backbones.
- jmilloy 14y agoI'm wondering if, instead, an employer created a facebook app that asked for maximum access, and asked their employees to authorize it. It might no longer be unauthorized access/tortious interference. I don't know the first thing about facebook app development. Seems like it could be easy to write up. Is it easy for facebook to kill such apps? Am I just making things up that don't make sense?
- drbawb 14y agoI would think it would have to be "authorized access" according to the scope of the FB ToS. Which makes a fair bit of sense, because having an app do it would go through FBs own privacy control schemes. So I guess we also have to make sure that employers can't require prospects to install apps. :/?
- smsm42 14y agoI wonder what happened to good old not putting private stuff on facebook? It's not like you have to use it. And why this focus on facebook? Is password to gmail or mint.com or yahoogroups different? It looks like Facebook using lawmaking system as a PR move. That's definitely a new and creative development - using the Congress as an advertisement medium - but I don't think it's a welcome one.
- freehunter 14y agoI wonder what happened to good old not putting private stuff on facebook? Facebook is built around private stuff. The expectation is that the only people who will see it are the people who should be seeing it. And why this focus on facebook? Because employers are not asking for other passwords as often as Facebook passwords, and Facebook has a lot more relevant information. Asking for Mint logins would be a blatant violation of PCI laws.
- smsm42 14y agoI don't think Facebook is built around private stuff, I think Facebook is built around sharing. I also recall Facebook managers stated many times that they see concept of privacy to be obsolete and harmful. Yes, of course, Facebook has privacy settings, since that vision is not yet accepted by most people, but the goal of it is sharing, not hiding (unlike webmail, for example) - the information on Facebook is by design supposed to be shared with other people. Of course, the set of these people can be different, but I think the easiest way to avoid publicizing private information is not publishing it on the site that is built for sharing and has always promoted sharing.
- deleted 14y ago[deleted]
- oleganza 14y agoBy taking this legal action Facebook tries to protect itself in the long run. Imagine if it becomes more common to hand out your account to HR. Quick enough, people will avoid connecting with each other on that platform and move to a competing platform where nobody is watching them.
- keithpeter 14y agoIf anyone in the US is looking for models for privacy legislation, we have some okish ones in Europe http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:31995L0046:EN:HTML http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:... Human readable version https://en.wikipedia.org/wiki/Data_Protection_Directive https://en.wikipedia.org/wiki/Data_Protection_Directive Have fun over there
- codezero 14y agoCouldn't an employer just make applicants apply via a Facebook app and get all the info they want legitimately?
- EricDeb 14y agoHas anyone's employer actually asked for this? I would be extremely offended if a company asked for my FB password
- pentae 14y agoPot, meet kettle.
- brownbat 14y agoI think lawyers should just fight this with current anti-discrimination law. Your Facebook profile potentially contains clues about your national origin, religion, family status, and age (relevant if you're near 40). Few employers are stupid enough to ask a woman if she's married in an interview.* Looking at Facebook can be the same thing. * Policy guidance for employers urges them to avoid these issues (for good reason): http://web.uflib.ufl.edu/pers/develop/departmentalinterviewingguide3.htm http://web.uflib.ufl.edu/pers/develop/departmentalinterviewi... ; http://www.businesslink.gov.uk/bdotg/action/detail?itemId=1073792193&type=RESOURCES http://www.businesslink.gov.uk/bdotg/action/detail?itemId=10...
- brownbat 14y agoI'm honestly a little disapointed in the ACLU on this issue. Facebook is doing a good thing taking it on, but the ACLU is bringing this up on behalf of Robert Collins. In the Robert Collins case,(1) the employer (the MD Dept of Corrections) hoped Facebook would reveal "gang affiliations." Race based discrimination alarm bells should be ringing! The best interests of your client are to politely remind the MD DoC that Baltimore juries are especially sensitive to discrimination issues and tend to be very skeptical of enforcement/corrections management.(2) Collins should walk away with a blank check under current law. ACLU is rolling the dice on some new "right to privacy for things you publicly posted" instead. I think it's the wrong way and wrong time for them to argue for that. (1) http://www.aclu.org/blog/technology-and-liberty/want-job-password-please http://www.aclu.org/blog/technology-and-liberty/want-job-pas... (2) http://www.guardian.co.uk/media/2008/sep/06/wire http://www.guardian.co.uk/media/2008/sep/06/wire
- linuxhansl 14y agoHonestly, who hands out his/her Facebook password to an employer?! This is like handing out private photo albums or access to the private email account. Any employer demanding this from me can happily continue to be an employer without me as employee (not that I have anything in my FB account anyway, but it's a matter of principle).
- jacquesm 14y agoSuggestion: if your employer asks you for your facebook credentials and you have other options in terms of employment immediately hand in your resignation. Employers that have these sort of practices deserve nothing less than business failure and I think that if enough key employees pack their bags that they will sooner or later get the message. Make it plain what the reason for your resignation is and if you can blog about it, I think that the spotlight of public opinion should help ram home the message that this sort of behavior is off-limits. And that goes for any other service besides facebook as well, your private affairs are your private affairs, and any employer that wants to stick their nose in does not deserve your brain power.
- jamesbritt 14y agoSummary: Facebook wants to protect its users from employers demanding access to their accounts. The company has clarified, however, that it currently has no plans to sue such employers. http://www.zdnet.com/blog/facebook/facebook-no-plans-to-sue-employers-asking-for-your-password/10802?tag=mantle_skin;content http://www.zdnet.com/blog/facebook/facebook-no-plans-to-sue-... http://news.ycombinator.com/item?id=3749693 http://news.ycombinator.com/item?id=3749693