Even Meta’s Oversight Board Thinks Its Rules For Banning Accounts Are Baffling



Over the last five years, Meta’s Oversight Board has weighed in on everything from Donald Trump’s Facebook suspension to AI deepfakes. Now the board is wading into another thorny issue: Meta’s rules for disabling users’ accounts.

The board announced earlier this year that it would look into improving transparency around the process, which is often frustratingly opaque. The oversight group dug into the issue following a referral from Meta regarding an Instagram account with 70,000 followers that was banned after making threatening posts targeting a journalist.

In its decision, the Oversight Board says that Meta was correct to ban the account, but the case raised “serious questions” about the company’s handling of such behavior and “due process concerns” around how it disables accounts. Because this is something of a test case, the board isn’t making formal recommendations to Meta, though it does highlight a number of potential improvements. Its analysis also highlights the confusing patchwork of rules and penalties that lead to bans on Meta’s platform, and the vast amount of frustration it’s caused for users.

For example, the board notes that Meta has strikingly different processes for Facebook and Instagram. While both platforms penalize accounts with “strikes,” repeated strikes can have different outcomes. On Facebook, accounts may receive temporary suspensions for repeated violations before an outright ban. But no such penalty exists on Instagram, the board says. Instead, Meta restricts accounts from Instagram’s livestreaming feature or will remove their account from recommendations (which Instagram users often refer to as a “shadowban”).

The Oversight Board rightfully points out how bizarre it is that restricting livestreaming is one of the main “intermediate” penalties on Instagram when the feature isn’t even available to all accounts (it requires a minimum of 1,000 followers). “For violations in permanent posts, a penalty that directly corresponds to violating behavior by suspending a user’s ability to post (e.g., by putting their account in read-only mode for a set period) would have a greater chance of influencing behavior,” the board notes.

The board also touches on the long-simmering frustration among Facebook and Instagram users who have accounts disabled. The group says it received more than 750 public comments in the case, in addition to the “innumerable” complaints individual board members regularly get from people who have had their accounts disabled.

“Many commenters wrote about systems failing to work, saying they were unable to appeal Meta’s decision to disable their account, that they never received any explanation for why their account was disabled or that they were unable to download their content,” the board wrote. “Many of these users also noted that the decisions appeared to have been made automatically, with no human oversight, even on appeals against the disabling of longstanding and widely followed accounts.”

In its guidance to Meta, the board suggests that the company should provide users with a better appeals process that allows them to provide written explanations and that users should be notified when AI is used to penalize their account. The board proposes that information about account bans could be added to Meta’s transparency reports for additional visibility. The group also advises that Meta provide a dedicated channel where “high-risk targets of violence and their representatives” can report serious threats against them.

Given that this case is described as a “pilot,” it’s unclear whether Meta plans to make any substantial policy changes in response to the board’s critique. But there is still some hope for those who want Meta to make improvements. The board says it plans to accept more cases in the future that deal with accounts being disabled, which would hopefully give them a better chance at influencing some reforms.



Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


CyberArk IAM – Table of Content

Cyberark IAM(Identity Access management)

Identity and Access Management (IAM) solutions are used by IT and security organizations to manage user identities and control access to enterprise resources. IAM solutions ensure that the right people have access to the right IT resources at the right time for the right reasons. They are an essential component of a defense-in-depth security strategy and are essential for defending IT systems against cyber attacks.

Now we will explore what is IAM security.

IAM Security

Identity and Access Management (IAM) security is an important part of overall IT security because it intends online identity as well as customer access to data, systems, and assets within a company. IAM security refers to the policies, programs, and technologies that a company uses to reduce identity-related access risks. IAM programs enable organizations to reduce risks, improve compliance, and increase revenue.

Become a CyberArk Certified professional  by learning this HKR CyberArk Training 

Benefits of IAM security

IAM is a cybersecurity best practice that allows for more control over user access. IAM security enhances the quality and productivity of access control throughout the business by recognizing, validating, and approving users while preventing unapproved ones.

  • It helps in improving the operational efficiencies.
  • Moreover security is improved to a great extent and also removes the risks.
  • Organizations must ensure data is closely monitored and demonstrate they are taking proactive steps to meet ongoing compliance requirements by leveraging strategic IAM security policies.

Companies today typically use best-of-breed IAM security tools provided by best-of-breed solution partners, ranging from identity governance solutions to privileged access management to access intelligence tools delivered on-premise, in the cloud, or via a hybrid model. These tools comprise the technology solutions that support the overall IAM security framework and are critical in establishing a strong foundation.

Become a CyberArk Certified professional  by learning this HKR CyberArk Training In Hyderabad !

CyberArk Training

  • Master Your Craft
  • Lifetime LMS & Faculty Access
  • 24/7 online expert support
  • Real-world & Project Based Learning

Key features of IAM

The key features of Cyberark IAM are:

  1. Single Sign-On (SSO) – The majority of IAM solutions support Single Sign-On (SSO) functionality, which allows users to access all of their business applications and services with a single set of login credentials. SSO increases user satisfaction by reducing password fatigue. It makes IT operations more efficient by centralizing and unifying administrative functions.It also improves security by removing risky password management practices, reducing attack surfaces, and closing security gaps.
  2. Multi-Factor Authentication (MFA) – Most IAM solutions include MFA functionality to protect against impersonation and credential theft. To gain access to a system using MFA, a user must present multiple forms of evidence, such as a password or fingerprint and an SMS code.Adaptive authentication methods are supported by modern MFA solutions, which use contextual information (location, time of day, IP address, device type, etc.) and administratively defined policies to determine which authentication factors to apply to a specific user in a specific situation.
  3. User provisioning and lifecycle management – The majority of IAM solutions include administrative tools for onboarding new users and managing their access privileges throughout their employment. They provide self-service portals that allow users to request access rights and update account information without requiring assistance from the help desk.They also offer monitoring and analysis abilities to assist corporate IT and security teams in supporting compliance audits and forensics investigations.

Want to know more about CyberArk , visit here CyberArk Tutorial.

Identity Management as a Service Alternatives Provide Cloud Economical and Agility

Most companies have traditionally used on-premises IAM solutions to manage user identities and access privileges. Many organizations now use Identity as a Service (IDaaS) offerings to streamline operations, shorten time-to-value, and support digital transformation initiatives.An IDaaS providing is an IAM solution delivered as a cloud-based service by a trusted third party.

IDaaS solutions combine all of the functions and benefits of an enterprise-class Identity and Access Management solution with the financial and operational benefits of a cloud-based service. They assist businesses in reducing risk, avoiding the cost and complexity of IT infrastructure, and accelerating digital transformation.

IDaaS services are ideal for the cloud-first, mobile-first IT model. They offer centralized, cloud-based identity management and access controls for SaaS and enterprise applications running in public or private clouds.They endorse identity federation standards such as SAML, Oauth, and OpenID Connect, which allow users to access all of their applications with a single set of credentials. They also make it simple for businesses to grant access to suppliers, business partners, and contract workers.

IDaaS solutions can also be used by companies to include remote access to traditional enterprise applications hosted in corporate data centers. Leading IDaaS solutions support app gateways, which enable remote workers to securely access traditional enterprise applications without the need for specialized VPN appliances or endpoint client software.

Acquire Cybersecurity certification by enrolling in the HKR Cybersecurity Training in Singapore!

Cyber Security & SIEM Tools, cyberark-iam-description-0, Cyber Security & SIEM Tools, cyberark-iam-description-1

Subscribe to our YouTube channel to get new updates..!

IDaaS solutions assist businesses in the following ways:

  1. Reduce costs and complexity – IDaaS solutions assist businesses in avoiding capital equipment expenses, simplifying IT operations, and freeing up IT staff to focus on core business initiatives.
  2. Accelerate time-to-value – Businesses can quickly and easily deploy IDaaS solutions, with little or no on-premises technology to deploy, configure, or maintain.
  3. Reduce risks – IDaaS solutions increase safety by removing risky password management practices and reducing vulnerabilities and attack surfaces.
  4. Improve user experiences – IDaaS offerings increase user satisfaction by removing password fatigue and allowing users to access all of their applications in a consistent manner using a single set of credentials.

CyberArk Training

Weekday / Weekend Batches

Conclusion

In the above blog post we had discussed the importance and key features, benefits of cyberark IAM. If you find anything not covered please drop your comments below. You will consider your requests.Happy learning!

Related Article:



Source link