Advertisement

Facebook software bug made private posts public for millions of users

A file photo of Facebook logos. Loic Venance/Getty Images

NEW YORK — Facebook said Thursday that a software bug made some private posts public for as many as 14 million users over several days in May.

The problem, which Facebook said it has fixed, is the latest privacy scandal for the world’s largest social media company.

It said the bug automatically suggested that users make new posts public, even if they had previously restricted posts to “friends only” or another private setting. If users did not notice the new default suggestion, they unwittingly sent their post to a broader audience than they had intended.

READ MORE: Facebook denies report it gave extensive user data to phone makers

Erin Egan, Facebook’s chief privacy officer, said the bug did not affect past posts. Facebook is notifying users who were affected and posted publicly during the time the bug was active, advising them to review their posts.

Story continues below advertisement

The news follows recent furor over Facebook’s sharing of user data with device makers, including China’s Huawei. The company is also still recovering from the Cambridge Analytica scandal, in which a Trump-affiliated data-mining firm got access to the personal data of as many as 87 million Facebook users.

Get the day's top news, political, economic, and current affairs headlines, delivered to your inbox once a day.

Get daily National news

Get the day's top news, political, economic, and current affairs headlines, delivered to your inbox once a day.
By providing your email address, you have read and agree to Global News' Terms and Conditions and Privacy Policy.

WATCH: Facebook introduces ‘clear history’ and ‘watch party’ features

Click to play video: 'Facebook introduces ‘clear history’ and ‘watch party’ features'
Facebook introduces ‘clear history’ and ‘watch party’ features

Jonathan Mayer, a professor of computer science and public affairs at Princeton University, said on Twitter that this latest privacy gaffe “looks like a viable Federal Trade Commission/state attorney general deception case.” That’s because the company had promised that the setting users set in their most recent privacy preferences would be maintained for future posts. In this case, this did not happen for several days.

Facebook’s 2011 consent decree with the FTC calls for the company to get “express consent” from users before sharing their information beyond what they established in their privacy settings. Even if the bug was an accident on Facebook’s part, Mayer said in an email that the FTC can bring enforcement action for privacy mistakes.

Story continues below advertisement

WATCH: Facebook executives grilled over Canadian data collection

Click to play video: 'Facebook executives grilled over Canadian data collection'
Facebook executives grilled over Canadian data collection

Facebook, which has 2.2 billion users, says the bug was active from May 18 until May 27. While the company says it stopped the error on May 22, it was not able to change all the posts back to their original privacy perimeters until later.

The mistake happened, that company said, when it was building a new way for people to share “featured items” on their profiles. These items, which include posts and photo albums, are automatically public. In the process of creating this feature, Facebook said it accidentally made the suggested audience for all new posts public.

When people post to Facebook, the service suggests and audience for their posts, based on past privacy settings. So if you made all your posts “friends only” in the past, it will suggest that you make your new post “friends only” too. You can still manually change the privacy of the posts — anywhere from “public” to “only me” — and this was the case during the bug’s life span too.

Advertisement

Sponsored content

AdChoices