Facebook's new groups feature worries some
IDG News Service - This week's overhaul of Facebook groups quickly led to an outcry over the way the service works, but the bigger lesson may be simply this: Be careful who you befriend.
The problems started on Thursday, the day after Facebook revamped groups, giving users a way to compartmentalize their Facebook lives and post certain items to pre-designated groups of people.
That's when technology blogger Michael Arrington, Facebook CEO Mark Zuckerberg and Mahalo founder Jason Calacanis all found themselves added to a group called NAMBLA. It wasn't immediately clear what this page was set up for, but NAMBLA is an acronym for the unsavory North American Man/Boy Love Association. (For South Park fans, it refers to the National Association of Marlon Brando Look-Alikes).
Mahalo CEO Calacanis quickly fired off an e-mail to Zuckerberg saying that he was troubled to have been added to the group without being given the opportunity to opt in.
That was followed by general confusion, with some reporting that Facebook's new feature could be used to unilaterally add anyone to a group.
But that isn't the case. The groups feature now lets users automatically add existing friends to groups, but they can't do this with people they don't know.
How did Zuckerberg get added to NAMBLA then? That's all down to tech blogger Arrington. "I typed in his name and hit enter," Arrington wrote on TechCrunch. "He's my Facebook friend, I therefore have the right to add him."
Arrington added that "as soon as Zuckerberg unsubscribed I lost the ability to add him to any further groups at all, another protection against spamming and pranks."
A Facebook spokeswoman confirmed that group members can only add their friends to the group.
"If you have a friend that is adding you to groups you do not want to belong to, or they are behaving in a way that bothers you, you can tell them to stop doing it, block them or remove them as a friend -- and they will no longer ever have the ability to add you to any group," she wrote in an e-mail. "If you don't trust someone to look out for you when making these types of decisions on the site, we'd suggest that you shouldn't be friends on Facebook."
Facebook Friends can also send messages and tag photos of other friends. Neither of these features has generated any type of outcry.
Arrington himself was added to the group by someone named Jon Fisher, one of Arrington's 4,824 Facebook friends. Fisher is also one of Calacanis's 4,740 friends.
Still, there is something disquieting about the way groups works, according to Chet Wisniewski, a senior security adviser with Sophos. He's concerned with the fact that people cannot opt out of the groups sign-up feature. "I'm uncomfortable with the idea that other people can determine what I display," he said. "The fact that it can't be opted out of, to me, seems a bit strange."
Facebook's groups Help Center confirms that there's simply no way to prevent people from adding you to groups. And the critics say that rather than being added automatically, friends should be given the choice to opt into any groups.
In a sign that Calacanis and Wisniewski may be on to something, online affiliate marketers have begun speculating about how the feature could be misused to drive traffic to marketing Web sites -- a favorite form of Facebook abuse. "If you were to make a group named AT&T and decided to make a few 'official' Facebook spokesperson accounts to add to the fun, you could essentially launch a campaign offering FREE WIRELESS SERVICE FOR EVERYONE DURING THE MONTH OF OCTOBER," wrote a poster named Jon to the Wickedfire.com Internet marketing forum.
This Jon also claimed to have set up a fake NAMBLA page.
"Seeing as how crowd manipulation and influence over the interwebz is sooooooo easy already, plus tack on this as a social parody of sorts, and poof, you have yourself a publicity nightmare on a scale that would be spreading far more rapidly than any BP oil spill ever could," he added.
Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three... All Privacy White Papers
- Close a Dangerous Vulnerability: Automated Methods for Managing Admin Rights
- In this exclusive webcast from Viewfinity, you'll hear how to leverage Group Policy Object settings to close this vulnerability by elevating privileges for...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
All Privacy Webcasts