Remember how Bill Clinton told a grand jury he wasn’t lying about his relations with Monica Lewinsky because it all boils down to what the meaning of “is” is?
Facebook’s pulling the same semantics shtick with the meaning of the term “share” vs. “commingle”, and it’s looking like the personal data of ‘Moves’ app users will get squished somewhere in between the two.
Moves is a fitness and activity tracking app that Facebook snapped up on 24 April. It does things like count how many steps you take every day, then presents it in a slick interface on your mobile phone.
Similarly, following the Moves acquisition announcement, a Facebook spokeswoman said that the two companies wouldn’t “commingle” data.
According to the Wall Street Journal, the spokeswoman reiterated that no-commingling position on Monday.
Nope, no canoodling, no commingling.
But, well, the companies do plan to share data, she said.
Imagine journalists across the land scampering to their online dictionaries. What in the world is the difference between “commingle” and “share?”
What it boils down to, a Facebook spokesperson told me, is that Facebook is going to get all the data that Moves has on its users, but that it would refrain from cross-referencing that with its own data to see what users the two companies have in common:
Commingling, or merging, data would allow us to identify Moves users who are also Facebook users – we have no plans to do that. In other words, Facebook is not adding Moves user data to a Facebook user’s Facebook account. But, Facebook will be providing support and services to the Moves app and to be able to do this, we have to have access to the data that Moves already collects from its users – which is ‘sharing’ data.
It’s not hard to see that Moves data would be very valuable to Facebook.
When you’re talking about personal data, this app is about as personal as the sweat dripping off your forehead.
Moves employs motion sensors inside Apple and Android phones and mixes it with GPS information to track a user’s location and activity throughout the day.
That means the app knows not only a user’s location, as in, pinpointed down to an exact building, but also whether he or she got there on foot, bike or bus.
That’s a lot to know about somebody.
In fact, it’s that type of personally identifiable information (PII) that researchers recently found leaking out of WhatsApp, which was calling out to Google Maps without using Secure HTTP (HTTPS) when users shared their location.
That’s scary, given that such a lack of security would allow attackers to sniff network traffic between phones and Google’s servers and to then pinpoint you as soon as you share your location with other WhatsApp users.
Now, with the Moves acquisition, Facebook will have that same kind of precise, location-based user PII.
Plus, Facebook will be kind of like a stalker who doesn’t have to leave his house to figure out whether you’re pedaling, on foot or riding the bus.
Should we get ready for new mobile phone ads that target our bicycle-related purchases?
At the very least, we should bear in mind that privacy policies are, shall we say, a tad ephemeral.Follow @NakedSecurity