%0 Conference Proceedings %T Undoing of Privacy Policies on Facebook %+ Indian Institute of Technology Bombay (IIT Bombay) %A Patil, Vishwas, T. %A Shyamasundar, R., K. %Z Part 2: Privacy %< avec comité de lecture %( Lecture Notes in Computer Science %B 31th IFIP Annual Conference on Data and Applications Security and Privacy (DBSEC) %C Philadelphia, PA, United States %Y Giovanni Livraga %Y Sencun Zhu %I Springer International Publishing %3 Data and Applications Security and Privacy XXXI %V LNCS-10359 %P 239-255 %8 2017-07-19 %D 2017 %R 10.1007/978-3-319-61176-1_13 %Z Computer Science [cs]Conference papers %X Facebook has a very flexible privacy and security policy specification that is based on intensional and extensional categories of user relationships. The former is fixed by Facebook but controlled by users whereas the latter is facilitated by Facebook with limited control to users. Relations and flows among categories is through a well-defined set of protocols and is subjected to the topology of underlying social graph that continuously evolves by consuming user interactions. In this paper, we analyze how far the specified privacy policies of the users in Facebook preserve the standard interpretation of the policies. That is, we investigate whether Facebook users really preserve their privacy as they understand it or certain of their innocuous actions leak information contrary to their privacy settings. We demonstrate the kind of possible breaches and discuss how plausibly they could be set right without compromising performance. The breaches are validated through experiments on the Facebook. %G English %Z TC 11 %Z WG 11.3 %2 https://inria.hal.science/hal-01684373/document %2 https://inria.hal.science/hal-01684373/file/453481_1_En_13_Chapter.pdf %L hal-01684373 %U https://inria.hal.science/hal-01684373 %~ IFIP-LNCS %~ IFIP %~ IFIP-TC %~ IFIP-WG %~ IFIP-TC11 %~ IFIP-WG11-3 %~ IFIP-DBSEC %~ IFIP-LNCS-10359