Facebook Faces Class-Action Suit Over Beacon

By Nancy Gohring
Wed, August 13, 2008

IDG News Service —

A class-action suit filed in California charges Facebook and a handful of other companies, including Blockbuster, Fandango and Overstock, with violating online privacy and computer fraud laws related to Facebook's controversial Beacon system.

Beacon is a program designed by Facebook that shares information about Facebook users' Internet activities with friends. When a Facebook user who has Beacon turned on buys an item on Overstock.com, for example, a message appears on their Facebook page about the purchase, so that all the user's friends can see the message.

But Beacon came under fire from the start from privacy advocates, some of whom wondered how much information Facebook was gathering about how many Internet users.

The lawsuit alleges that Facebook gathered information about its users' online activities before it even asked them whether they wanted that information to appear on their profiles. "By the time any user was notified that Facebook was (at a minimum), an observing party to the transaction, and that Facebook was asking for an approval to publicly broadcast identifying information regarding the event, personally identifying information had already been communicated to Facebook," the suit reads.

In addition, the program was initially set up as an opt-out system, but it was very cumbersome to do so, the suit alleges. Facebook users had to visit each Beacon affiliate Web site, of which there were initially 44, and opt out of the program on each site.

Also, Beacon collected information about all visitors -- not just Facebook users -- who conducted certain activities on the third-party sites that were part of the program, according to the suit, which was filed on Tuesday in the U.S. District Court for the Northern District of California. For example, any time someone bought or rented a movie or placed a movie in their queue on Blockbuster.com, a notification about the activity was sent to Facebook. That happened regardless of whether the person using the Blockbuster site was a Facebook customer.

"Thus, non-Facebook persons who utilized the Facebook Beacon Activated Affiliate Websites were not told that their transaction, and indeed, every transaction they engaged in upon the Website was being communicated to a third party (Facebook) with whom they had no relationship whatsoever," the suit reads.

The suit covers the period of Nov. 7, 2007, through Dec. 5, 2007, when Facebook changed the way the program works. After Dec. 5, Beacon became an opt-in system and users could turn it off completely.

The class purports to represent all Facebook members who during that period visited any of the Beacon affiliate Web pages and did something that would trigger Beacon to send a message to Facebook. The suit estimates there are tens of thousands of people affected.

A Facebook spokesman said the company had not been served the suit but planned to review it closely when it receives it.

The suit asks the court to require Facebook and the other affiliate sites to delete any of the data they collected without user knowledge, award restitution to class members and return any "ill-gotten gains" from the activities that allegedly violated privacy and fraud laws.

The suit also names as defendants Hotwire, STA Travel, Zappos.com and Gamefly, as well as other unnamed companies that were initially involved in the Beacon program but not named by Facebook.

Earlier this year, a woman in Texas sought class-action status for a suit against Blockbuster for its participation in Beacon.

Learn how your answer to this question compares to your peers by taking this quick poll. See how your peers are dealing with the challenge of ensuring a highly capable server infrastructure as technological shifts impact the application server platform.
With increasing data growth, comes increased need for data security.  The existing DLP model, with a focus on compliance/enforcement is not sufficient as the data discovery and classification capabilities are not granular enough.  Read this paper to find how you can efficiently and accurately manage your risk by rapidly inventorying and classifying your data and then developing remediation workflows that support business needs. 
This paper breaks down attack sources into four categories: external, malicious insiders, accidental insiders, and unknown.
The rapid growth of data and technology is creating challenges for organizations as this digital data is considered to be business communications and must be preserved according the same industry-specific regulations governing the retention and discovery of emails and more traditional forms of electronic communications. This paper examines the role that Data Loss Prevention ("DLP") technology can play in helping organizations address the challenges of locating information in response to electronic discovery.
This research, conducted by the Ponemon Institute, focuses on issues relating to the use of data protection solutions such as endpoint encryption and data loss prevention within the workplace.
This report, by Jon Oltsik from Enterprise Strategy Group, examines the need for a new business-centric approach to DLP in order to align business and security requirements.
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
VMware recently announced VMware vFabric™ Data Director, a new database deployment and operations platform that enables enterprise IT organizations to offer database as a private cloud service. Built on top of VMware vSphere 5, vFabric Data Director enables IT organizations to ontrol database sprawl through automation and consistent policy enforcement and accelerate application development cycles with self-service database management. Attend this webcast to learn how vFabric Data Director can help you build database-as-a-service in your datacenter.
A simple, cost-effective disaster-recovery solution for virtual environments is high on the agenda for IT organizations as they virtualize more business-critical applications with VMware. VMware vCenter™ Site Recovery Manager-the market-leading disaster-recovery product-ensures the simplest and most reliable disaster protection for all virtualized applications. VMware vCenter Site Recovery Manager provides centralized management of recovery plans, enables nondisruptive testing and automates site-failover processes.
Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to expand disaster protection beyond their most critical applications, largely because they are uncertain whether the quality of the protection is really worth its cost. VMware vCenter™ Site Recovery Manager 5 is the market-leading disaster recovery product that addresses this situation for organizations of all kinds. It complements VMware vSphere to ensure the simplest and most reliable disaster protection for all virtualized applications.
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center