---
title: On the Grey Zones of Privacy
description: The Facebook app requests specific permissions and you then consent to the information exchange. But what happens when consent reaches into your contacts? 
image: https://reflare.com/hubfs/Blog%20image%20in%20post/On%20the%20Grey%20Zones%20of%20Privacy.png
---

[![Reflare home](https://reflare.com/hs-fs/hubfs/Reflare%20website%20images/Reflare%20Logos/reflare%20logo.png?width=421&height=150&name=reflare%20logo.png "Reflare home")](https://reflare.com)

[![logo](https://reflare.com/hs-fs/hubfs/Reflare%20website%20images/Reflare%20Logos/logo.png?width=262&height=82&name=logo.png "logo")](https://reflare.com/act3)

[![reflare logo](https://reflare.com/hs-fs/hubfs/Reflare%20website%20images/Reflare%20Logos/reflare%20logo.png?width=168&height=60&name=reflare%20logo.png "reflare logo")](https://reflare.com/act3)

- [Galena](https://reflare.com/galena) 
    - [Galena Overview](https://reflare.com/galena)
    - [Galena for Tech Teams](https://reflare.com/technical-teams)
    - [Galena for L&D Teams](https://reflare.com/learning-development)
    - [Galena Security and Deployment](https://reflare.com/security-deployment)
- Training 
    - [Capture the Flag](https://reflare.com/rctf-reflare-capture-the-flag)
    - [Developers](https://reflare.com/rcsd)
    - [Administrators](https://reflare.com/rcsa)
    - [PCI DSS](https://reflare.com/rcsd)
- Audit 
    - [PCI DSS](https://reflare.com/pcidss)
    - [PCI 3DS](https://reflare.com/pci3ds)
    - [PCI PIN](https://reflare.com/pcipin)
    - [PCI DSS ASV](https://reflare.com/pcidssasv)
    - [Penetration Testing](https://reflare.com/penetration)
    - [Vulnerability Scanning](https://reflare.com/vulnerability)
    - [Advisory and Management](https://reflare.com/advisory)
- [Research](https://reflare.com/research) 
    - [Anatomy of a Breach](https://reflare.com/research/tag/anatomy-of-a-breach)
    - [High Tech](https://reflare.com/research/tag/high-tech)
    - [Infosec Culture](https://reflare.com/research/tag/infosec-culture)
    - [Infrastructure](https://reflare.com/research/tag/infrastructure)
    - [Normal People and Infosec](https://reflare.com/research/tag/normal-people-and-infosec)
    - [WTFWIB](https://whythefuckwasibreached.com/)
- [About](https://reflare.com/about) 
    - [Contact](https://reflare.com/contact)
    - [Company](https://reflare.com/about)
    - [Careers](https://reflare.com/careers)
    - [Service Status](https://statuspage.reflare.com/)
- [日本語](https://jp.reflare.com/)

[Login](https://reflare.com/login)

[Buy Now](https://www.hubspot.com/)

[Login](https://www.hubspot.com/)Login to your Reflare account

- [Galena](https://reflare.com/galena)
  
  
  
  
  
  
  
  
  
    - [Galena Overview](https://reflare.com/galena)
    - [Galena for Tech Teams](https://reflare.com/technical-teams)
    - [Galena for L&D Teams](https://reflare.com/learning-development)
    - [Galena Security and Deployment](https://reflare.com/security-deployment)
- Training
  
  
  
  
  
  
  
  
  
    - [Capture the Flag](https://reflare.com/rctf-reflare-capture-the-flag)
    - [Developers](https://reflare.com/rcsd)
    - [Administrators](https://reflare.com/rcsa)
    - [PCI DSS](https://reflare.com/rcsd)
- Audit
  
  
  
  
  
  
  
  
  
    - [PCI DSS](https://reflare.com/pcidss)
    - [PCI 3DS](https://reflare.com/pci3ds)
    - [PCI PIN](https://reflare.com/pcipin)
    - [PCI DSS ASV](https://reflare.com/pcidssasv)
    - [Penetration Testing](https://reflare.com/penetration)
    - [Vulnerability Scanning](https://reflare.com/vulnerability)
    - [Advisory and Management](https://reflare.com/advisory)
- [Research](https://reflare.com/research)
  
  
  
  
  
  
  
  
  
    - [Anatomy of a Breach](https://reflare.com/research/tag/anatomy-of-a-breach)
    - [High Tech](https://reflare.com/research/tag/high-tech)
    - [Infosec Culture](https://reflare.com/research/tag/infosec-culture)
    - [Infrastructure](https://reflare.com/research/tag/infrastructure)
    - [Normal People and Infosec](https://reflare.com/research/tag/normal-people-and-infosec)
    - [WTFWIB](https://whythefuckwasibreached.com/)
- [About](https://reflare.com/about)
  
  
  
  
  
  
  
  
  
    - [Contact](https://reflare.com/contact)
    - [Company](https://reflare.com/about)
    - [Careers](https://reflare.com/careers)
    - [Service Status](https://statuspage.reflare.com/)
- [日本語](https://jp.reflare.com/)

[Buy Now](https://www.hubspot.com/)

<https://reflare.com/research> Research

#### Share this

[Share on Twitter](https://twitter.com/share?url=https://reflare.com/research/on-the-grey-zones-of-privacy&text=On%20the%20Grey%20Zones%20of%20Privacy) [Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https://reflare.com/research/on-the-grey-zones-of-privacy&t=On%20the%20Grey%20Zones%20of%20Privacy) [Share on LinkedIn](https://www.linkedin.com/shareArticle?mini=true&url=https://reflare.com/research/on-the-grey-zones-of-privacy&t=On%20the%20Grey%20Zones%20of%20Privacy)

# On the Grey Zones of Privacy

 by [**Reflare Research Team**](https://reflare.com/research/author/reflare-research-team) on Mar 23, 2018 2:04:00 PM

Facebook apps operate on the principle that you explicitly agree to each access requested. The app requests certain permissions, and you then consent to the information exchange. But what happens when consent reaches into the details of your contacts? 

First Published 23rd March 2018

![On the Grey Zones of Privacy](https://reflare.com/hs-fs/hubfs/Blog%20image%20in%20post/On%20the%20Grey%20Zones%20of%20Privacy.png?width=672&height=448&name=On%20the%20Grey%20Zones%20of%20Privacy.png)

*Enter angry emoji here.*

4 min read  |  Reflare Research Team

Data privacy appears to be self-evident on the surface. When posting, liking, commenting or sharing, these actions should only be visible to the audience defined in the settings - Friends, Friends of Friends or Everyone.

When using a Facebook app such as a messaging client, social game or quiz, the app should only receive the access requested on the confirmation page. This access may range from “Basic Account Information” to “Let this app post for me”. Everything is relatively straight forward.

But what happens when one of your friends is granting an app access to their basic information, friend list and feed? The app will now be authorized to see that you two are friends and would also see any posts, likes and comments of yours that your friend can see. Your friend can effectively grant access to your data to a third party even though you may not want to have it.

What appears to be a grave privacy oversight at first glance actually makes sense when viewed through the lens of a wide variety of applications. For example, a Facebook client app for mobile devices or an app allowing groups of friends to coordinate events would be useless without access to the user’s friends’ posts, friendship status and likes.

Malicious actors may then take the data collected by legitimately authorized Facebook apps, save it and use it for further purposes.

Privacy thus quickly becomes complicated and much murkier than most users expect.

## What can be done to change this?

Rules and social norms governing data privacy are an evolving concept that will need more time to mature fully. However, three main elements play a role in better protecting user data from abuse.

## Limiting Authorization

In the early days of social networks, apps used to be authorized to either access all of a user’s data or none of it. Over time these authorizations have become more fine-grained to allow access to only basic information, only posts and so on. More fine-grained authorizations - especially such that allow users to opt-out of having their data shared by friends - may be necessary. However since these restrictions would break compatibility with existing apps and ultimately lead to a sharp decrease in user engagement, they are not popular with social network operators.

## Timing Authorization

While users are in theory able to deauthorize apps that they no longer use, this rarely happens in practice. Many users - especially those very active on social networks - have tens or even hundreds of apps authorized to access their data. Some of these apps may have been malicious from the start, have become abandoned and insecure or have been acquired by malicious actors. Automatic deauthorization of unused apps appears to be a reasonable step. However, the challenge of determining whether an app is being actively used will be tricky to implement well.

## Public Awareness

The last element is growing awareness of privacy and the impact that one’s actions may have on the privacy of friends and acquaintances. Since such awareness is rooted in social norms and cultural conventions, we cannot predict how it will evolve over time. However recent years have seen an increasing global trend towards awareness of - if not care for - privacy concerns.

## Summary

Data privacy is a constantly evolving topic which will gain in importance over the coming years. While much data privacy regulation focuses on preventing outright data breaches through cyber attacks, the prevention of authorized but unintended uses of personal data may play an even larger role in the long run. While this plays out, users will become considerably more attentive to precisely what the small print within their digital footprint actually means. And should user behaviour move faster than the social media platforms to address data privacy, then the consumer may well set the terms and pace of change ahead.

Topics: [Infrastructure](https://reflare.com/research/tag/infrastructure)

#### Share this

[Share on Twitter](https://twitter.com/share?url=https://reflare.com/research/on-the-grey-zones-of-privacy&text=On%20the%20Grey%20Zones%20of%20Privacy) [Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https://reflare.com/research/on-the-grey-zones-of-privacy&t=On%20the%20Grey%20Zones%20of%20Privacy) [Share on LinkedIn](https://www.linkedin.com/shareArticle?mini=true&url=https://reflare.com/research/on-the-grey-zones-of-privacy&t=On%20the%20Grey%20Zones%20of%20Privacy)

- Recent
- Topics
- Archive

Recent

Topics

- [Infosec Culture (113)](https://reflare.com/research/tag/infosec-culture)
- [Anatomy of a Breach (60)](https://reflare.com/research/tag/anatomy-of-a-breach)
- [Normal People and Infosec (42)](https://reflare.com/research/tag/normal-people-and-infosec)
- [High Tech (31)](https://reflare.com/research/tag/high-tech)
- [Infrastructure (21)](https://reflare.com/research/tag/infrastructure)
- [Capture the Flag (8)](https://reflare.com/research/tag/capture-the-flag)

See all

Archive

- [June 2026 (1)](https://reflare.com/research/archive/2026/06)
- [May 2026 (1)](https://reflare.com/research/archive/2026/05)
- [April 2026 (1)](https://reflare.com/research/archive/2026/04)
- [March 2026 (1)](https://reflare.com/research/archive/2026/03)
- [February 2026 (1)](https://reflare.com/research/archive/2026/02)
- [January 2026 (1)](https://reflare.com/research/archive/2026/01)
- [December 2025 (1)](https://reflare.com/research/archive/2025/12)
- [November 2025 (1)](https://reflare.com/research/archive/2025/11)
- [October 2025 (1)](https://reflare.com/research/archive/2025/10)
- [September 2025 (1)](https://reflare.com/research/archive/2025/09)
- [August 2025 (1)](https://reflare.com/research/archive/2025/08)
- [July 2025 (1)](https://reflare.com/research/archive/2025/07)
- [June 2025 (1)](https://reflare.com/research/archive/2025/06)
- [May 2025 (1)](https://reflare.com/research/archive/2025/05)
- [April 2025 (1)](https://reflare.com/research/archive/2025/04)
- [March 2025 (1)](https://reflare.com/research/archive/2025/03)
- [February 2025 (1)](https://reflare.com/research/archive/2025/02)
- [January 2025 (1)](https://reflare.com/research/archive/2025/01)
- [December 2024 (1)](https://reflare.com/research/archive/2024/12)
- [November 2024 (1)](https://reflare.com/research/archive/2024/11)
- [October 2024 (1)](https://reflare.com/research/archive/2024/10)
- [September 2024 (1)](https://reflare.com/research/archive/2024/09)
- [August 2024 (1)](https://reflare.com/research/archive/2024/08)
- [July 2024 (1)](https://reflare.com/research/archive/2024/07)
- [June 2024 (1)](https://reflare.com/research/archive/2024/06)
- [April 2024 (2)](https://reflare.com/research/archive/2024/04)
- [February 2024 (1)](https://reflare.com/research/archive/2024/02)
- [January 2024 (1)](https://reflare.com/research/archive/2024/01)
- [December 2023 (1)](https://reflare.com/research/archive/2023/12)
- [November 2023 (1)](https://reflare.com/research/archive/2023/11)
- [October 2023 (1)](https://reflare.com/research/archive/2023/10)
- [September 2023 (1)](https://reflare.com/research/archive/2023/09)
- [August 2023 (1)](https://reflare.com/research/archive/2023/08)
- [July 2023 (1)](https://reflare.com/research/archive/2023/07)
- [June 2023 (2)](https://reflare.com/research/archive/2023/06)
- [May 2023 (2)](https://reflare.com/research/archive/2023/05)
- [April 2023 (3)](https://reflare.com/research/archive/2023/04)
- [March 2023 (4)](https://reflare.com/research/archive/2023/03)
- [February 2023 (3)](https://reflare.com/research/archive/2023/02)
- [January 2023 (5)](https://reflare.com/research/archive/2023/01)
- [December 2022 (1)](https://reflare.com/research/archive/2022/12)
- [November 2022 (2)](https://reflare.com/research/archive/2022/11)
- [October 2022 (1)](https://reflare.com/research/archive/2022/10)
- [September 2022 (11)](https://reflare.com/research/archive/2022/09)
- [August 2022 (5)](https://reflare.com/research/archive/2022/08)
- [July 2022 (1)](https://reflare.com/research/archive/2022/07)
- [May 2022 (3)](https://reflare.com/research/archive/2022/05)
- [April 2022 (1)](https://reflare.com/research/archive/2022/04)
- [February 2022 (4)](https://reflare.com/research/archive/2022/02)
- [January 2022 (3)](https://reflare.com/research/archive/2022/01)
- [December 2021 (2)](https://reflare.com/research/archive/2021/12)
- [November 2021 (3)](https://reflare.com/research/archive/2021/11)
- [October 2021 (2)](https://reflare.com/research/archive/2021/10)
- [September 2021 (1)](https://reflare.com/research/archive/2021/09)
- [August 2021 (1)](https://reflare.com/research/archive/2021/08)
- [June 2021 (1)](https://reflare.com/research/archive/2021/06)
- [May 2021 (14)](https://reflare.com/research/archive/2021/05)
- [February 2021 (1)](https://reflare.com/research/archive/2021/02)
- [October 2020 (1)](https://reflare.com/research/archive/2020/10)
- [September 2020 (1)](https://reflare.com/research/archive/2020/09)
- [July 2020 (1)](https://reflare.com/research/archive/2020/07)
- [June 2020 (1)](https://reflare.com/research/archive/2020/06)
- [May 2020 (1)](https://reflare.com/research/archive/2020/05)
- [April 2020 (2)](https://reflare.com/research/archive/2020/04)
- [March 2020 (1)](https://reflare.com/research/archive/2020/03)
- [February 2020 (1)](https://reflare.com/research/archive/2020/02)
- [January 2020 (3)](https://reflare.com/research/archive/2020/01)
- [December 2019 (1)](https://reflare.com/research/archive/2019/12)
- [November 2019 (2)](https://reflare.com/research/archive/2019/11)
- [October 2019 (3)](https://reflare.com/research/archive/2019/10)
- [September 2019 (5)](https://reflare.com/research/archive/2019/09)
- [August 2019 (2)](https://reflare.com/research/archive/2019/08)
- [July 2019 (3)](https://reflare.com/research/archive/2019/07)
- [June 2019 (3)](https://reflare.com/research/archive/2019/06)
- [May 2019 (2)](https://reflare.com/research/archive/2019/05)
- [April 2019 (3)](https://reflare.com/research/archive/2019/04)
- [March 2019 (2)](https://reflare.com/research/archive/2019/03)
- [February 2019 (3)](https://reflare.com/research/archive/2019/02)
- [January 2019 (1)](https://reflare.com/research/archive/2019/01)
- [December 2018 (3)](https://reflare.com/research/archive/2018/12)
- [November 2018 (5)](https://reflare.com/research/archive/2018/11)
- [October 2018 (4)](https://reflare.com/research/archive/2018/10)
- [September 2018 (3)](https://reflare.com/research/archive/2018/09)
- [August 2018 (3)](https://reflare.com/research/archive/2018/08)
- [July 2018 (4)](https://reflare.com/research/archive/2018/07)
- [June 2018 (4)](https://reflare.com/research/archive/2018/06)
- [May 2018 (2)](https://reflare.com/research/archive/2018/05)
- [April 2018 (4)](https://reflare.com/research/archive/2018/04)
- [March 2018 (5)](https://reflare.com/research/archive/2018/03)
- [February 2018 (3)](https://reflare.com/research/archive/2018/02)
- [January 2018 (3)](https://reflare.com/research/archive/2018/01)
- [December 2017 (2)](https://reflare.com/research/archive/2017/12)
- [November 2017 (4)](https://reflare.com/research/archive/2017/11)
- [October 2017 (3)](https://reflare.com/research/archive/2017/10)
- [September 2017 (5)](https://reflare.com/research/archive/2017/09)
- [August 2017 (3)](https://reflare.com/research/archive/2017/08)
- [July 2017 (3)](https://reflare.com/research/archive/2017/07)
- [June 2017 (4)](https://reflare.com/research/archive/2017/06)
- [May 2017 (4)](https://reflare.com/research/archive/2017/05)
- [April 2017 (2)](https://reflare.com/research/archive/2017/04)
- [March 2017 (4)](https://reflare.com/research/archive/2017/03)
- [February 2017 (2)](https://reflare.com/research/archive/2017/02)
- [January 2017 (1)](https://reflare.com/research/archive/2017/01)
- [December 2016 (1)](https://reflare.com/research/archive/2016/12)
- [November 2016 (4)](https://reflare.com/research/archive/2016/11)
- [October 2016 (2)](https://reflare.com/research/archive/2016/10)
- [September 2016 (4)](https://reflare.com/research/archive/2016/09)
- [August 2016 (5)](https://reflare.com/research/archive/2016/08)
- [July 2016 (3)](https://reflare.com/research/archive/2016/07)
- [June 2016 (5)](https://reflare.com/research/archive/2016/06)
- [May 2016 (3)](https://reflare.com/research/archive/2016/05)
- [April 2016 (4)](https://reflare.com/research/archive/2016/04)
- [March 2016 (5)](https://reflare.com/research/archive/2016/03)
- [February 2016 (4)](https://reflare.com/research/archive/2016/02)

See all

### Subscribe by email

#### About Reflare

We help customers increase cyber resilience with the #1 hands-on IT security training platform.

Our developer, administrator, and non-technical user training programs enhance user skills, fulfil your compliance needs, and contribute to developing more secure technologies.

<https://x.com/reflarehq><https://www.linkedin.com/company/reflare-ltd.>

Legal

- [Terms of Service](https://reflare.com/terms)
- [Privacy Statement](https://reflare.com/privacy)
- [Cookie Info](https://reflare.com/cookies)
- [Copyright and Citation Enquiries](https://reflare.com/citation)
- [Contact](https://reflare.com/contact)

 © 2026 Reflare Ltd, and/or its affiliates.   /   In business since 2009.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Reflare Research Team",
    "url" : "https://reflare.com/research/author/reflare-research-team"
  },
  "dateModified" : "2023-11-21T13:45:10.871Z",
  "datePublished" : "2018-03-23T14:04:00.000Z",
  "headline" : "On the Grey Zones of Privacy",
  "image" : [ "https://reflare.com/hubfs/Blog%20image%20in%20post/On%20the%20Grey%20Zones%20of%20Privacy.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://reflare.com/research/on-the-grey-zones-of-privacy",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://reflare.com/hubfs/Reflare%20website%20images/Reflare%20Logos/logo.png"
    },
    "name" : "Reflare"
  }
}
```