The Inconvenient Truth About Web Certificates

  • Vratonjic N
  • Freudiger J
  • Bindschaedler V
  • et al.
N/ACitations
Citations of this article
51Readers
Mendeley users who have this article in their library.
Get full text

Abstract

We have conducted the first thorough analysis of the market for privacy practices and policies in online social networks. From an evaluation of 45 social networking sites using 260 criteria we find that many popular assumptions regarding privacy and social networking need to be revisited when considering the entire ecosystem instead of only a handful of well-known sites. Contrary to the common perception of an oligopolistic market, we find evidence of vigorous competition for new users. Despite observing many poor security practices, there is evidence that social network providers are making efforts to implement privacy enhancing technologies with substantial diversity in the amount of privacy control offered. However, privacy is rarely used as a selling point, even then only as auxiliary, nondecisive feature. Sites also failed to promote their existing privacy controls within the site. We similarly found great diversity in the length and content of formal privacy policies, but found an opposite promotional trend: though almost all policies are not accessible to ordinary users due to obfuscating legal jargon, they conspicuously vaunt the sites privacy practices. We conclude that the market for privacy in social networks is dysfunctional in that there is significant variation in sites privacy controls, data collection requirements, and legal privacy policies, but this is not effectively conveyed to users. Our empirical findings motivate us to introduce the novel model of a privacy communication game, where the economically rational choice for a site operator is to make privacy control available to evade criticism from privacy fundamentalists, while hiding the privacy control interface and privacy policy to maximize sign-up numbers and encourage data sharing from the pragmatic majority of users.

Cite

CITATION STYLE

APA

Vratonjic, N., Freudiger, J., Bindschaedler, V., & Hubaux, J.-P. (2013). The Inconvenient Truth About Web Certificates. In Economics of Information Security and Privacy III (pp. 79–117). Springer New York. https://doi.org/10.1007/978-1-4614-1981-5_5

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free