Facebook CSO says Snowden disclosures brought security to forefront

The disclosures made it easier to have a conversation about security, according to Joe Sullivan

Facebook continues to upgrade its security infrastructure while also closely scrutinizing law enforcement requests, said CSO Joe Sullivan.
Facebook continues to upgrade its security infrastructure while also closely scrutinizing law enforcement requests, said CSO Joe Sullivan.

Facebook was already implementing stronger security controls when the U.S. National Security Agency's expansive surveillance program was revealed in June, its chief security officer said Thursday.

The social networking site has continued upgrading its security infrastructure, said Joe Sullivan[cq], who spoke to IDG News Service by phone from the Hack in the Box security conference in Kuala Lumpur.

Former NSA contractor Edward Snowden's disclosures "maybe made it a little bit easier to have that conversation publicly and show the effort that has been going on behind the scenes all along," Sullivan said.

On Tuesday, the Washington Post reported that the NSA was collecting email and instant messaging address books as the lists are transmitted on the Internet from services including Facebook, Yahoo, Microsoft and Google.

The company said it was unaware that data was collected and did not assist. Sullivan said information such as chat contact lists are now encrypted, as Facebook has enabled TLS (Transport Security Layer), or "https" encryption by default. That would shield the data unless the interceptor could decrypt it, although Facebook just turned on that feature for all users in July.

Facebook's security roadmap includes moving from 1,024-bit to 2,048-bit RSA encryption, Sullivan said. It also plans to implement Perfect Forward Secrecy, an encryption feature that limits the amount of data that can be decrypted if a private key is compromised in the future. Sullivan said he hopes that work is finished by year's end.

Facebook was one of many companies, including Microsoft, Google, Yahoo and Apple, that were wrapped into NSA's Prism program, which collected a wide variety of electronic data from service providers, according to slides published by the Washington Post.

After discussions with the U.S. government, Facebook and other technology companies were allowed in June to release some figures related to data collection requests from the U.S Foreign Intelligence Surveillance Court and National Security Letters.

But Facebook, Google and Yahoo are pushing to disclose more. The companies filed petitions on Sept. 9 asking the U.S Foreign Intelligence Surveillance Court for permission to release more information on orders and directives.

Sullivan said Facebook has had in place "very robust practices around scrutinizing every single law enforcement request so that when we had an opportunity to be transparent, we could feel good about that."

In August, the company released its first Global Government Requests Report. In many cases, Facebook didn't turn over data to a government despite a request.

Law enforcement often don't know how to ask for the information they're looking for, such as not being specific enough about what user they're seeking information on, Sullivan said. Other times, the account requested doesn't exist or can't be identified.

All requests are reviewed manually by a team to ensure they meet legal standards, which can be incredibly complicated. "As is apparent from the statistics, a decent percentage of requests that we get are not legally sufficient," Sullivan said.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the CMO newsletter!

Error: Please check your email address.
Show Comments

Supporting Association

Blog Posts

People in vegan houses shouldn't throw bacon

Picture this. You’re at a Gourmerican burger joint chomping a cheeseburger, when an outspoken vegan friend starts preaching that you’re killing the planet. Last week, that same vegan downed a pricey glass of pinot before their flight to a far-flung destination, armed with their strongest mossie repellant and first aid kit. Anything amiss?

Abbie Love

Strategist, Ikon Communications

The role of the CMO is evolving: Are you keeping up?

My (amazing) vacation in the Galapagos Islands earlier in the year got me thinking about Charles Darwin and his theory of evolution. What does this have to do with the role of today’s CMO, you ask? Plenty.

Sheryl Pattek

Vice-president, executive partner

Getting your business ready for the Entrepreneurial Consumer

We all know the digital revolution has completely transformed the way consumers are interacting with brands, and that a lot of businesses are finding it hard to catch up. One way to closing this brand gap is to understand consumer behaviour and build a brand experience that meets these new needs.

Pip Stocks

CEO and founder, BrandHook

Or just go to sites like www.shopsthatshiptoaustralia.c... and others and be sure that the stores will send to where you live :-)


Why online shopping is like dating – RedBalloon CEO

Read more

Personalisation is the key. Customers demand a very relatable and well defined CX where the sincerity and understanding of their disposit...

Hitesh Parekh

In pictures: Improving cutomer experiences through smart personalisation

Read more

Thanks for this. The key for me is the effective of governance where it dictates and sets the proactive policy when it comes to CX. Tech ...

Hitesh Parekh

6 lessons in modern marketing from a customer experience chief

Read more

Very well said “With today’s consumers more demanding of the brands and merchants they shop, it’s imperative for merchants to not just co...


CMO's top 10 martech stories for this week - 29 September

Read more

Very interesting article which touches on the importance of a feedback loop fuelled by customer and market insights. Ideally this scenari...

Andrew Reid

Building customer insights in the data and digital age

Read more

Latest Podcast

More podcasts

Sign in