[Part 1/3] How social networks trade your data: the price of your privacy for your daily connection

Image of the Rubik's cube representing the RRSS

Social networks have become the platforms par excellence that occupy most of today’s society’s attention. What started out as simple applications for socializing now offer a wide range of options to attract as many users as possible.

These platforms are used to stay in constant contact with friends and family, watch videos, read news, flirt, search for jobs or play online games with strangers.

With so much variety, it’s hard to imagine anyone not using them. Over the years, social networks have evolved from spaces for sharing photos and messages to true communication, entertainment and even e-commerce tools, with integrated stores and live broadcasts.

The truth is that today it is quite difficult to meet someone who does not use any social network, such as Facebook, TikTok, X, BlueSky, Instagram, LinkedIn or Tinder. However, there are those who decide not to use them as a result of assessing the risks involved in maintaining a presence on these platforms, something more common in individuals over 40 years old.

Its enormous appeal is undeniable, but so is the price: privacy and security.

The ability to connect with friends and family around the world and share content instantly is irresistible; the problem arises when that convenience translates into permanent exposure of personal data and habits.

This first article inaugurates a series of three installments. In this issue we analyze the business model and structural risks (leaks, contact book, mass collection). In the second we will look at the most common scams, social engineering and physical risks (doxing), with a special focus on LinkedIn, metadata and fake profiles. In the third we will address algorithmic manipulation (bots, sock puppets, “synthetic users”), social/psychological impacts, the regulatory landscape and close with practical checklists to regain control.

The hidden engine: data, tracking and ads

If sarcasm is allowed, we could say that social networks are the most successful implementation of surveillance capitalism.

Their logic is clear: the more data you give up, the better they profile you and the more money they make by offering targeted advertising.

Even respected tech voices have pointed out the hypocrisy of accusing a single platform of tracking you when the entire industry lives by the same thing. Against that backdrop, it’s worth taking on board an essential mantra: “what goes up on the Internet, NEVER comes down again”.

This model pushes platforms to ask you for more and more information: tastes, schedules, friends, location, voice, face… the business flourishes as the portrait of your life becomes sharper.

The result is not only surgical ad targeting, but more surface area for identity fraud and an ecosystem where any breach impacts millions at once.

Leaks and scraping: when “private” is no longer private

News of massive data breaches has become routine. In one of the most notorious Facebook leaks, hundreds of millions of records with phone numbers, names, gender, work activity, relationship status and location were exposed.

In other cases, no intrusion is even necessary: web scraping makes it possible to extract public data on a large scale using automated tools. LinkedIn has even sold information from some 500 million profiles obtained through scraping. Although such practices contravene platform policies, they are difficult to eradicate: attackers are constantly refining their techniques.

The underlying problem is that the privacy settings do not shield you.

Even if you limit who sees your number or address within the social network, if there is a breach or collection is automated, that data will end up circulating through forums, repositories or buying and selling channels.

***It is advisable to act as if all published information could one day be made public.

A particularly annoying example is the request for access to the contact book. In theory it “helps you find friends”; in practice, it allows them to copy the names, phone numbers, emails and private notes you have about the people you have in your phone’s address book and who, I assure you, never gave you their consent to share their data with those platforms.

If you are one of those people who keep passwords, IDs, etc. inside any of your contacts, all of them will also be exposed; so if after reading this, you give access to your contact book to any application, there is no doubt that you are a despicable person. I’m sure you won’t do it!

Once you voluntarily give data to an online application, you lose control: it can be sold to advertisers, shared with third parties or end up in government databases.

The recommendation is clear: do not grant such permission. Protecting your privacy also means protecting the privacy of those who trust you.

What you publish… and what metadata reveals

The fact that these platforms seem wonderful to us does not mean that they are free of dangers.

If you stop on Facebook or Instagram, you’ll see how common it is to upload personal photos-including those of third parties-without asking permission, share real-time locations, or opine on sensitive matters.ย 

Companies that evaluate candidates during their selection process review social media before hiring; just as fraudsters do the same to profile their victims. In addition, the metadata of an image (time, place, device) can reveal more than you intended.

Therefore, it is wise to wait to leave the location before posting about it, disable the camera’s geolocation and check the privacy of each platform regularly.

Remember: when you upload photos or videos, they are no longer under your control and can circulate beyond your circle.

A good rule of thumb is not to add strangers, especially profiles with “perfect**”** photos that look like something out of a catalog.

If someone wants to gain your trust or spy on you, they will design an eye-catching profile to increase the likelihood that you will accept their request.

Even on LinkedIn, where the tone is professional, check who you let in: there are almost complete resumes there with name, email, phone number, background and education, a treasure trove for social engineering.

My personal recommendation is to use non-real names in the RRSS.

It is true that it makes it more difficult for friends and family to find you, and slightly increases the risk of impersonation (with possible countermeasures), but it makes life more difficult for potential attackers. Personal security must come first.

My mantra: “all profiles on RRSS are fake until proven otherwise”.

Generative AI and its new profiles

With the rise of AI, sites have proliferated such as thispersondoesnotexist.com (photorealistic fictitious faces) and fakenamegenerator.com (coherent identities). The result: farms of profiles that are difficult to distinguish from real people.

Sometimes you will see a single “too perfect” photo or a mosaic where the face is never well distinguished. In those cases, be wary, it is the door to scams that often start with an innocent contact.

Stolen accounts and abandonment: the big mistake

Still, the most valuable loot is the real accounts. Millions have been stolen by not activating 2FA and repeating passwords.

Many victims do not report to the platform or to the police: they leave and open another one.

Wrong: these stolen accounts - with **hundreds of real friends -**are the perfect disguise that are then used to extort, defame, buy drugs or exchange illicit materials such as pedophile material that will be attributed to the former owner.

As I have said many times, one of the best self-protection measures, along with training and common sense, is to enable two-factor authentication (2FA) in all your social networks. This way, even if they guess your password or find it on the Internet as a result of a leak, they will need the second factor.

Add to this periodic reviews of the devices with open session and log out of all those that do not sound like yours. Also be wary of links or files received through the platform’s private messages, even if they “come” from friends (they could be compromised).

And, before you publish, ask yourself: does it add value or expose me now or in the future?

Addiction and the business of care

Platforms are masters at keeping us connected: the more time you spend inside, the more advertising revenue they generate .

As a collateral effect, cases of addiction, anxiety and depression linked to excessive consumption are increasing.

If you want to become aware, it is worth watching the Netflix documentary The Social Dilemma, which exposes the psychological mechanisms employed by these companies. They have no scruples! (especially Meta).

What is clear is that our habits have already changed: where we used to watch “whatever was on TV”, now we consume on demand.

Traditional television will remain just another medium. If you are surprised that young people watch hours of video games or dances without participating, ask yourself if you don’t also spend hours watching tennis or soccer without practicing them. The difference is generational and of format.

To close this first article, remember these suggestions for healthy use:

  1. Define time limits;
  2. Deactivate superfluous notifications;
  3. Review privacy (labeling, visibility, retention);
  4. Question what you share (imagine your former teacher or boss seeing it);
  5. Practice screen-free days to reset attention and mood.

In the next article (2/3) we will go into scams, social engineering, LinkedIn, doxing and metadata, and how to shield yourself in practice.

This has been article 1 of 3 on RRSS.