Cory Watilo

 

A REAL Facebook privacy issue: Email addresses NOT listed on Facebook are getting indexed by Google - Update: Fixed by Facebook


I'm not one to freak out my personal information getting "leaked" from my mostly private Facebook profile, mainly because I don't publish things that I don't want people to know, but this is another story. This is a REAL Facebook privacy issue.

I Googled my email address (as I occasionally do) to see if it was indexed anywhere, because I like to keep it off the grid as much as I can. As it turns out, Facebook is the ONLY website that publishes my address, and the thing is...I don't even use that address on Facebook.

So what's happening here? Well, Facebook's "Opt out of emails from Facebook" page is getting indexed by Google. I'm assuming (based on critical thinking and moderate fact checking) addresses appear on this page if the following criteria are met:

  • Email address is not tied to an account on Facebook
  • Email address has been submitted by a friend using the "Find a friend" feature


What makes this a big problem is the fact that you can find THOUSANDS of email addresses by doing a simple Google search like:

site:facebook.com "Do you want to stop receiving Facebook emails" - fixed by Facebook

or

site:facebook.com "Do you want to stop receiving Facebook emails" @gmail.com - fixed by Facebook

Queries like this returned thousands of results, and I'm sure with a little digging, you could find more.

One obvious problem is that spammers can easily scrape this data and add easily legitimate address to their lists, many of whom might not give their addresses to Facebook for a reason. I actually remember seeing this problem a while back (maybe 6 months to a year ago), but forgot about it. I'm a little surprised that this one has slipped through the cracks for this long.

Follow me on Twitter and I'll let you know how this thing turns out.

Update: Sachin Agarwal pointed out on Hacker News that a lot of addresses getting indexed are secret addresses that people use to post to blogs (ie: Blogger). Yikes.

Update: It looks like Facebook has fixed the issue by preventing search engines from indexing that page. A big thanks to Blake Ross from Facebook for joining the thread on Hacker News to find the root of the problem and get it fixed. My email address is safe, once again!

Loading mentions Retweet
Posted 3 months ago

10 Comments

Jun 03, 2010
Aviraj Saluja said...
This is just incredibly messed up
Jun 03, 2010
val said...
Holy crap... now i know why i keep getting email about penis enlargement. thanks facebook.
Jun 03, 2010
ian kennedy said...
It should be easy enough for Facebook to block search engines from these pages. Careless oversight.
Jun 03, 2010
fady said...
Great catch!!!
Jun 03, 2010
Dave said...
Weird, you can actually opt-out those email addresses using the target page.
Jun 03, 2010
Chris said...
I did a search on Google as you mention in the post and got no results. What happened?
Jun 03, 2010
fady said...
Yeah, that is weird, as I copied the query, and did find what he was mentioning, but now - no results! That is some quick damage control
Jun 03, 2010
moioci said...
I recently changed my registered FB email to a variation on my gmail address. Within 2 days, I was receiving spam addressed to that email I'd never used anywhere else before or since.
Jul 02, 2010
Кори, привет! Ты предлагаешь в этом пост е следовать за тобой на Щебетать, но там в настройках ты это блокируешь!! Сознательно ли? Или это кто-то сделал вместо тебя?
Aug 31, 2010
Jen said...
I want to be able to allow facebook to have people search for me within FB but not for it to pop up on a google search. Is this possible?

Leave a comment...