Sophos Naked Security calls for Facebook to implement three-point plan to improve safety online

Sophos’s Naked Security site has written an open letter to Facebook, calling upon the social networking giant to address three security issues.  Sophos urges Facebook to create a safer environment for its 500+ million users and show its commitment to improve privacy and safety on the internet.

 In the open letter, Sophos proposes the following three-point security plan and asks Facebook to commit publically to a timetable for its implementation:



No more sharing of information without your express agreement (OPT-IN). Whenever Facebook adds a new feature to share additional information about you, Facebook should not assume that you want this feature turned on.


Only vetted and approved third-party developers should be allowed to publish apps on the Facebook platform. With over one million app developers already registered on the Facebook platform, it is hardly surprising that Facebook’s service is riddled with rogue applications and viral scams.


In a welcome first step, Facebook recently introduced an HTTPS option, but left it turned off by default. Worse, Facebook only commits to provide a secure connection “whenever possible”. Facebook should enforce a secure connection all the time, by default. Without this protection, users are at risk of losing personal information to hackers.

“Facebook is no stranger to making headlines for all the wrong reasons when it comes to security and privacy. The Sophos three-point plan would turn Facebook into the good guys and also be a real safety step-up for its 500 million users,” said Graham Cluley of Sophos Naked Security. “Facebook is popular and successful and is not going away. So it is essential that Facebook takes proper care of its users by making their security and privacy a top priority.”

“Our question to Facebook is this – why wait until regulators force your hand on privacy? Act now for the greater good of all,” urged Cluley.

Sophos Naked Security experts will be at the Infosec 2011 show at Earls Court, London this week, discussing this three-point plan and the security and privacy issues on Facebook.

Sophos Naked Security full open letter is published at

Graham Cluley is available for comment at +44 (0)1235 544114 or +44 (0)7990 552181

About Sophos Naked Security

Naked Security is Sophos’s award-winning  website that focuses on security news, opinion, advice and research. Written by leading industry experts, Naked Security is an unrivalled source of timely information about today’s online threats. Naked Security has won a number of awards and was voted the Most Educational Security Blog at the RSA 2011 conference in San Francisco. Visit Naked Security at

About Sophos

More than 100 million users in 150 countries rely on Sophos as the best protection against complex threats and data loss. Sophos is committed to providing security and data protection solutions that are simple to manage, deploy and use and that deliver the industry’s lowest total cost of ownership. Sophos offers award-winning encryption, endpoint security, web, email, and network access control solutions backed by SophosLabs – a global network of threat intelligence centres. With more than two decades of experience, Sophos is regarded as a leader in security and data protection by top analyst firms and has received many industry awards.

Graham Cluley, senior technology consultant, Sophos.

Twitter: @gcluley

Press Contacts:

Nirmala D’souza

OAK Consulting FZC


About the Author

Copyright © 2019 OAK Consulting.
All rights reserved.