Facebook CSO says Snowden disclosures brought security to forefront

The disclosures made it easier to have a conversation about security, according to Joe Sullivan

Facebook continues to upgrade its security infrastructure while also closely scrutinizing law enforcement requests, said CSO Joe Sullivan.
Facebook continues to upgrade its security infrastructure while also closely scrutinizing law enforcement requests, said CSO Joe Sullivan.

Facebook was already implementing stronger security controls when the U.S. National Security Agency's expansive surveillance program was revealed in June, its chief security officer said Thursday.

The social networking site has continued upgrading its security infrastructure, said Joe Sullivan[cq], who spoke to IDG News Service by phone from the Hack in the Box security conference in Kuala Lumpur.

Former NSA contractor Edward Snowden's disclosures "maybe made it a little bit easier to have that conversation publicly and show the effort that has been going on behind the scenes all along," Sullivan said.

On Tuesday, the Washington Post reported that the NSA was collecting email and instant messaging address books as the lists are transmitted on the Internet from services including Facebook, Yahoo, Microsoft and Google.

The company said it was unaware that data was collected and did not assist. Sullivan said information such as chat contact lists are now encrypted, as Facebook has enabled TLS (Transport Security Layer), or "https" encryption by default. That would shield the data unless the interceptor could decrypt it, although Facebook just turned on that feature for all users in July.

Facebook's security roadmap includes moving from 1,024-bit to 2,048-bit RSA encryption, Sullivan said. It also plans to implement Perfect Forward Secrecy, an encryption feature that limits the amount of data that can be decrypted if a private key is compromised in the future. Sullivan said he hopes that work is finished by year's end.

Facebook was one of many companies, including Microsoft, Google, Yahoo and Apple, that were wrapped into NSA's Prism program, which collected a wide variety of electronic data from service providers, according to slides published by the Washington Post.

After discussions with the U.S. government, Facebook and other technology companies were allowed in June to release some figures related to data collection requests from the U.S Foreign Intelligence Surveillance Court and National Security Letters.

But Facebook, Google and Yahoo are pushing to disclose more. The companies filed petitions on Sept. 9 asking the U.S Foreign Intelligence Surveillance Court for permission to release more information on orders and directives.

Sullivan said Facebook has had in place "very robust practices around scrutinizing every single law enforcement request so that when we had an opportunity to be transparent, we could feel good about that."

In August, the company released its first Global Government Requests Report. In many cases, Facebook didn't turn over data to a government despite a request.

Law enforcement often don't know how to ask for the information they're looking for, such as not being specific enough about what user they're seeking information on, Sullivan said. Other times, the account requested doesn't exist or can't be identified.

All requests are reviewed manually by a team to ensure they meet legal standards, which can be incredibly complicated. "As is apparent from the statistics, a decent percentage of requests that we get are not legally sufficient," Sullivan said.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the CMO newsletter!

Error: Please check your email address.
Show Comments

Supporting Association

Blog Posts

Why 2017 will herald a resurgence of values-based marketing

It doesn’t take long for predictions to become predictable: The rise and rise of Facebook; advancements in analytics; the normalisation of chatbots; personalisation, programmatic, automation, authenticity… The prediction that’s missing from these lists is that in 2017 we will witness a resurgence of values-based marketing.

Jacqueline Burns

Founder, Market Expertise

Why customer experience driven growth is set to take off

Our overall brand perceptions are invariably shaped by our experiences. And loyal customer relationships can be severed in moments by a negative service interaction.

Consistency and conversation: How branding and advertising can work better together

Advertising and branding are two of the most visible outputs of marketing, which is why getting them right is so important. However, too often the line between branding and advertising becomes blurred. This means advertising activity can be out of sync with brand, resulting in poor results for both functions.

Dan Ratner

managing director, uberbrand

Someone needs a swift kick up the bum for such an idiotic idea.

random

​Why a degree is no longer enough to get you hired as a skilled marketer

Read more

The frequent flyer programs are the new profit machines for airlines all over the world, as they have morphed to be mass marketing machin...

Steve@iFLYflat

Velocity frequent flyers program strong performer in mixed half-year for Virgin

Read more

Hi Jennifer, thanks for sharing these info regarding the digital marketing trends.I've created a related video to this topic, would you m...

Fabio Carry

Predictions: 17 digital marketing trends for 2017

Read more

Great news. Marketing automation can be very useful for companies at various stages of development. With so many tools out there it's bet...

Ben

How HBF rolled out marketing automation in eight months

Read more

I read a report that the business sector in Australia as a whole have yet to fully harness and see the proactive change that predictive a...

Alex Martin

Report: Predictive analytics, IoT, machine learning battle it out for marketing dollars

Read more

Latest Podcast

More podcasts

Sign in