Feeds

Teen data on Myspace compromised

Hack allows 'private' entries to be made public

The Essential Guide to IT Transformation

A security hole in the popular MySpace social networking site allowed users to view entries marked "private", a crucial protection for users aged under 16, according to weekend reports.

Though the site is said to have fixed the problem, it was said by news reports to have been active for months. Nobody at MySpace was immediately available for comment.

The explosion of social networking sites has caused significant worry for parents and politicians over how to protect children from sexual advances over websites. The amount of information that young people reveal about themselves coupled with the opportunities for deception by sexual predators has led to concerns that the sites can be dangerous.

Leading social networking site MySpace introduced private profiles as a security measure. Earlier this summer, MySpace owner News Corporation introduced new rules to protect teenagers.

The profile of anyone under 16 was changed so that it was automatically set to "private", a status that users could previously choose, but which was not compulsory. Users over 18 attempting to contact users under 16 now have to type in the child's actual first and last name or email address in order to initiate contact, a move designed to protect children from unsolicited advances.

A piece of code has now been revealed which users claim can allow access to private profiles. Information about the hack became widely publicised through news site Digg.com last weekend, and reports this week claim that the problem has been fixed.

There are much earlier reports of the existence of the hack, though, which suggest that profiles have been being hacked for months. A post by a user called AtariBoy on the site Geeklimit.com in April detailed a hack which claimed to access users' private profile details.

"Many myspacers use CSS [cascading style sheets] to hide their comments, friends list and blog links," wrote AtariBoy. "These elements are not deleted tho [sic] and are still available publicly to anyone. You can view them by one of two methods below."

The site was said this week to have fixed the problem, though some users of the hack reported subsequently that it still worked and private profiles were still accessible.

"In the UK, the vulnerabilities alleged could amount to a breach of the Data Protection Act," said Struan Robertson, editor of OUT-LAW.COM and a technology lawyer with Pinsent Masons.

The Data Protection Act says "appropriate technical and organisational measures" must be taken to prevent unauthorised access to personal data held by organisations.

"For any site, the technical measures that are appropriate will vary depending on the type of data held and the harm that might result from a security breach," Robertson said. "There is best practice guidance in the UK for sites used by children and, if the allegations are true, it may be that MySpace fell short of the standard expected."

The Home Office taskforce's "Good practice guidance for the moderation of interactive services for children" refers to the Data Protection Act provisions and notes: "If data systems are vulnerable to hacking, or operated by people outside the control of the service operator, there is the potential that the security of users' personal data could be at risk."

If the Act's security principle were found to have been breached, a person who suffered as a result could be entitled to sue in the UK for compensation for distress.

See: guidelines from The Home Office taskforce on child protection on the internet (35 page/191KB PDF)

Copyright © 2006, OUT-LAW.com

OUT-LAW.COM is part of international law firm Pinsent Masons.

HP ProLiant Gen8: Integrated lifecycle automation

More from The Register

next story
BBC goes offline in MASSIVE COCKUP: Stephen Fry partly muzzled
Auntie tight-lipped as major outage rolls on
iPad? More like iFAD: We reveal why Apple fell into IBM's arms
But never fear fanbois, you're still lapping up iPhones, Macs
White? Male? You work in tech? Let us guess ... Twitter? We KNEW it!
Grim diversity numbers dumped alongside Facebook earnings
HP, Microsoft prove it again: Big Business doesn't create jobs
SMEs get lip service - what they need is dinner at the Club
Bose says today IS F*** With Dre Day: Beats sued in patent battle
Music gear giant seeks some of that sweet, sweet Apple pie
Amazon Reveals One Weird Trick: A Loss On Almost $20bn In Sales
Investors really hate it: Share price plunge as growth SLOWS in key AWS division
Dude, you're getting a Dell – with BITCOIN: IT giant slurps cryptocash
1. Buy PC with Bitcoin. 2. Mine more coins. 3. Goto step 1
There's NOTHING on TV in Europe – American video DOMINATES
Even France's mega subsidies don't stop US content onslaught
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.