Facebook accidentally exposes members’ dates of birth

During a public beta test of its new user interface, social networking website Facebook has accidentally exposed personal information — at this stage limited to the date of birth and age — of all its members.

According to Sophos, which created a YouTube video illustrating the flaw, as many as 80 million dates of birth have been disclosed, even of users who opted to keep it hidden. The flaw was probably caused by the new site template not adding the proper privacy hooks to the birthday field, causing it to be displayed regardless of a user’s privacy preferences.

Given that a person’s name and date of birth are two crucial (though, on their own, insufficient) ingredients of identity theft, this breach is potentially serious — and of course, users suffer the indignity of having their actual age revealed. It highlights the privacy pitfalls of social networking — which necessarily involves entrusting personal information to a third party aggregator — and the issue of legal recourse available to members whose privacy has been compromised. The flaw has subsequently been fixed by Facebook.