andrewducker: (Default)
andrewducker ([personal profile] andrewducker) wrote2012-03-07 11:00 am

Interesting Links for 07-03-2012

[identity profile] spacelem.livejournal.com 2012-03-08 03:41 pm (UTC)(link)
Just because I can't let things go, here is some further information about this I found (quoting from someone on slashdot: it's probably correct, but I don't have time to check).

"Accessing another user's account is a violation of facebook's terms of service, even if that user gives them permission, which potentially makes it a violation of the Computer Fraud and Abuse Act (18 U.S.C. 1030), i.e. a felony.

"In addition, there are various other questions that employers cannot ask during interviews because doing so violates federal equal employment opportunity legislation, meaning that accessing a user's facebook account opens them up to lawsuits.

"There is however one valid legal use for asking users for their facebook accounts, namely screening out employees who'll create a security risk by being especially vulnerable to social engineering. If an employee will have access to sensitive user or employee account information, then you might reasonable ask them for their facebook account password. If they provide it, you politely tell them they have failed the interview, thank them for their time, and send them home early. If they refuse, then you tell them they answered that question correctly and continue with the interview."