Facebook CSO says Snowden disclosures brought security to forefront

The disclosures made it easier to have a conversation about security, according to Joe Sullivan

Facebook continues to upgrade its security infrastructure while also closely scrutinizing law enforcement requests, said CSO Joe Sullivan.
Facebook continues to upgrade its security infrastructure while also closely scrutinizing law enforcement requests, said CSO Joe Sullivan.

Facebook was already implementing stronger security controls when the U.S. National Security Agency's expansive surveillance program was revealed in June, its chief security officer said Thursday.

The social networking site has continued upgrading its security infrastructure, said Joe Sullivan[cq], who spoke to IDG News Service by phone from the Hack in the Box security conference in Kuala Lumpur.

Former NSA contractor Edward Snowden's disclosures "maybe made it a little bit easier to have that conversation publicly and show the effort that has been going on behind the scenes all along," Sullivan said.

On Tuesday, the Washington Post reported that the NSA was collecting email and instant messaging address books as the lists are transmitted on the Internet from services including Facebook, Yahoo, Microsoft and Google.

The company said it was unaware that data was collected and did not assist. Sullivan said information such as chat contact lists are now encrypted, as Facebook has enabled TLS (Transport Security Layer), or "https" encryption by default. That would shield the data unless the interceptor could decrypt it, although Facebook just turned on that feature for all users in July.

Facebook's security roadmap includes moving from 1,024-bit to 2,048-bit RSA encryption, Sullivan said. It also plans to implement Perfect Forward Secrecy, an encryption feature that limits the amount of data that can be decrypted if a private key is compromised in the future. Sullivan said he hopes that work is finished by year's end.

Facebook was one of many companies, including Microsoft, Google, Yahoo and Apple, that were wrapped into NSA's Prism program, which collected a wide variety of electronic data from service providers, according to slides published by the Washington Post.

After discussions with the U.S. government, Facebook and other technology companies were allowed in June to release some figures related to data collection requests from the U.S Foreign Intelligence Surveillance Court and National Security Letters.

But Facebook, Google and Yahoo are pushing to disclose more. The companies filed petitions on Sept. 9 asking the U.S Foreign Intelligence Surveillance Court for permission to release more information on orders and directives.

Sullivan said Facebook has had in place "very robust practices around scrutinizing every single law enforcement request so that when we had an opportunity to be transparent, we could feel good about that."

In August, the company released its first Global Government Requests Report. In many cases, Facebook didn't turn over data to a government despite a request.

Law enforcement often don't know how to ask for the information they're looking for, such as not being specific enough about what user they're seeking information on, Sullivan said. Other times, the account requested doesn't exist or can't be identified.

All requests are reviewed manually by a team to ensure they meet legal standards, which can be incredibly complicated. "As is apparent from the statistics, a decent percentage of requests that we get are not legally sufficient," Sullivan said.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Show Comments

Blog Posts

7 ways to champion a human centred design culture

Human Centred Design (HCD) has come a long way in the last decade with many forward-thinking organisations now asking for HCD teams on their projects. It’s increasingly seen as essential to unlocking innovation, driving superior customer experiences and reducing delivery risk.

Shane Burford

Head of research and design, RXP Group

Building a human-curated brand

If the FANG (Facebook, Amazon, Netflix, Google) sector and their measured worth are the final argument for the successful 21st Century model, then they are beyond reproach. Fine-tuning masses of algorithms to reduce human touchpoints and deliver wild returns to investors—all with workforces infinitesimally small compared to the giants of the 20th Century—has been proven out.

Will Smith

Co-founder and head of new markets, The Plum Guide

Sustainability trends brands can expect in 2020

​Marketers have made strides this year in sustainability with the number of brands rallying behind the Not Business As Usual alliance for action against climate change being a sign of the times. While sustainability efforts have gained momentum this year, 2020 is shaping up to be the year brands are really held accountable for their work in this area.

Ben King

CSR manager & sustainability expert, Finder

Hey Vanessa, thanks for providing us the things marketers should know about data privacy. This was really an informative post.

astha sharma

5 things marketers should know about data privacy in 2020

Read more

Well, that's good to know that. Any other news you want to share here? I can't wait to see more.

Phil Godfrey

Queensland appoints first chief customer and digital officer

Read more

It's a pretty interesting article to read. I will learn more about this company later.

Dan Bullock

40 staff and 1000 contracts affected as foodora closes its Australian operations

Read more

If you think it can benefit both consumer and seller then it would be great

Simon Bird

Why Ford is counting on the Internet of Things to drive customer engagement

Read more

It's a good idea. Customers really should control their data. Now I understand why it's important.

Elvin Huntsberry

Salesforce CMO: Modern marketers have an obligation to give customers control of their data

Read more

Latest Podcast

More podcasts

Sign in