Absence of malicious history/intent doesn't render them incapable of being (directly or indirectly) dangerous. One could easily pose a rational argument for users to take prophylactic measures (e.g., Facebook Disconnect, Ghostery, and the other browser plug-ins) based solely on the increasing number of data breaches.[1][2]
However, this is a relatively weak argument, as it requires making an underlying assumption that the leaked data is dangerous. We have no evidence to support the assertion that leaked information of the kind shared on Facebook would pose any danger to the affected users. This is fundamentally different from the dangers of data breaches concerning health and financial records; these records contain information necessary to steal identities and engage in other nefarious operations. Facebook doesn't collect social security numbers or other extremely sensitive personally identifiable information.
Facebook does, however, collect evidence of our predispositions and predilections. Arguably, this information is far more dangerous than mere personally identifiable information, because rather than identifying us outright, it gets to the heart of what makes each of us unique. We are incapable of imagining the complete set of scenarios where this information could be used nefariously, and as such, its dangers fall within the scope of ``unknown unknowns''
Compare this situation to the case of a breach of financial data: the uses of this data are well-enumerated, and one could argue that the cost of the next health information data breach is a known unknown. Based on historical evidence, we know that another breach will occur, and we know how criminals use the leaked information. With data on Facebook, however, we don't know whether this information could be used maliciously. Moreover, if it could be used maliciously, we don't know how it might be used. Therefore, it deserves as much privacy (if not more) as one's financial and health records.
Comments
Absence of malicious history/intent doesn't render them incapable of being (directly or indirectly) dangerous. One could easily pose a rational argument for users to take prophylactic measures (e.g., Facebook Disconnect, Ghostery, and the other browser plug-ins) based solely on the increasing number of data breaches.[1][2]
However, this is a relatively weak argument, as it requires making an underlying assumption that the leaked data is dangerous. We have no evidence to support the assertion that leaked information of the kind shared on Facebook would pose any danger to the affected users. This is fundamentally different from the dangers of data breaches concerning health and financial records; these records contain information necessary to steal identities and engage in other nefarious operations. Facebook doesn't collect social security numbers or other extremely sensitive personally identifiable information.
Facebook does, however, collect evidence of our predispositions and predilections. Arguably, this information is far more dangerous than mere personally identifiable information, because rather than identifying us outright, it gets to the heart of what makes each of us unique. We are incapable of imagining the complete set of scenarios where this information could be used nefariously, and as such, its dangers fall within the scope of ``unknown unknowns''
Compare this situation to the case of a breach of financial data: the uses of this data are well-enumerated, and one could argue that the cost of the next health information data breach is a known unknown. Based on historical evidence, we know that another breach will occur, and we know how criminals use the leaked information. With data on Facebook, however, we don't know whether this information could be used maliciously. Moreover, if it could be used maliciously, we don't know how it might be used. Therefore, it deserves as much privacy (if not more) as one's financial and health records.
[1] http://www.idtheftcenter.org/artman2/publish/lib_survey/ITRC... [2] http://www.privacyrights.org/data-breach