Lethe: Conceal Content Deletion from Persistent Observers

Open access


Most social platforms offer mechanisms allowing users to delete their posts, and a significant fraction of users exercise this right to be forgotten. However, ironically, users’ attempt to reduce attention to sensitive posts via deletion, in practice, attracts unwanted attention from stalkers specifically to those (deleted) posts. Thus, deletions may leave users more vulnerable to attacks on their privacy in general. Users hoping to make their posts forgotten face a “damned if I do, damned if I don’t” dilemma. Many are shifting towards ephemeral social platform like Snapchat, which will deprive us of important user-data archival. In the form of intermittent withdrawals, we present, Lethe, a novel solution to this problem of (really) forgetting the forgotten. If the next-generation social platforms are willing to give up the uninterrupted availability of non-deleted posts by a very small fraction, Lethe provides privacy to the deleted posts over long durations. In presence of Lethe, an adversarial observer becomes unsure if some posts are permanently deleted or just temporarily withdrawn by Lethe; at the same time, the adversarial observer is overwhelmed by a large number of falsely flagged undeleted posts. To demonstrate the feasibility and performance of Lethe, we analyze large-scale real data about users’ deletion over Twitter and thoroughly investigate how to choose time duration distributions for alternating between temporary withdrawals and resurrections of non-deleted posts. We find a favorable trade-off between privacy, availability and adversarial overhead in different settings for users exercising their right to delete. We show that, even against an ultimate adversary with an uninterrupted access to the entire platform, Lethe offers deletion privacy for up to 3 months from the time of deletion, while maintaining content availability as high as 95% and keeping the adversarial precision to 20%.

[1] Snapchat. https://www.snapchat.com/. (Accessed on February 2018).

[2] How tweet it is!: Library acquires entire twitter archive. http://blogs.loc.gov/loc/2010/04/how-tweet-it-is-library-acquires-entire-twitter-archive/, 2010. (Accessed on February 2018).

[3] 4chan raids: how one dark corner of the internet is spreading its shadows. http://www.theconversation.com/4chan-raids-how-one-dark-corner-of-the-internet-is-spreading-its-shadows-68394, 2016. (Accessed on February 2018).

[4] Art. 17, general data protection regulation, right to be forgotten. https://gdpr-info.eu/art-17-gdpr/, 2016. (Accessed on February 2018).

[5] Dust. https://www.usedust.com/, 2016. (Accessed on February 2018).

[6] Snl’s first latina cast member is caught out deleting thousands of tweets, some of which were ‘racist and offensive’. http://www.dailymail.co.uk/news/article-3805356/SNL-s-Latina-cast-member-caught-deleting-thousands-tweetsracist-offensive.html, 2016. (Accessed on February 2018).

[7] 24 tweets ed sheeran will probably delete soon. https://www.buzzfeed.com/mjs538/we-r-who-we-r-is-a-good-song-tho, 2017. (Accessed on February 2018).

[8] Politwoops’ archive of 1m deleted tweets from politicians is available again. https://thenextweb.com/twitter/2015/09/17/politwoops-archive-of-1m-deleted-tweets-from-politicians-is-available-again/, 2017. (Accessed on February 2018).

[9] Replies and retweets on twitter. https://sysomos.com/inside-twitter/twitter-retweet-stats/, 2017. (Accessed on February 2018).

[10] Resavr. https://www.resavr.com/, 2017. (Accessed on February 2018).

[11] Stackprinter. http://www.stackprinter.com/deleted, 2017. (Accessed on February 2018).

[12] The streaming apis. https://dev.twitter.com/streaming/overview, 2017.

[13] Twitter puts trillions of tweets up for sale to data miners. https://www.theguardian.com/technology/2015/mar/18/twitter-puts-trillions-tweets-for-sale-data-miners, 2017. (Accessed on February 2018).

[14] Twitter’s evolving plans to make money from its data stream. https://bits.blogs.nytimes.com/2015/04/11/twitters-evolving-plans-to-make-money-from-its-data-stream, 2017. (Accessed on February 2018).

[15] Uneddit. https://web.archive.org/web/20170824002119/http://uneddit.com/, 2017. (Accessed on February 2018).

[16] Almuhimedi, H., Wilson, S., Liu, B., Sadeh, N., and Acquisti, A. Tweets are forever: A large-scale quantitative analysis of deleted tweets. In CSCW’13.

[17] Ayalon, O., and Toch, E. Retrospective privacy: Managing longitudinal privacy in online social networks. In SOUPS’13.

[18] Bauer, L., Cranor, L. F., Komanduri, S., Mazurek, M. L., Reiter, M. K., Sleeper, M., and Ur, B. The post anachronism: The temporal dimension of facebook privacy. In ACM WPES ‘13.

[19] Boyd, D., Golder, S., and Lotan, G. Tweet, tweet, retweet: Conversational aspects of retweeting on twitter. In System Sciences (HICSS), 2010 43rd Hawaii International Conference on (2010), IEEE, pp. 1–10.

[20] Casella, G., and Berger, R. L. Statistical Inference, 2nd ed. Duxbury Press, 2002.

[21] Castelluccia, C., De Cristofaro, E., Francillon, A., and Kaafar, M.-A. Ephpub: Toward robust ephemeral publishing. In ICNP’11.

[22] Conover, M., Ratkiewicz, J., Francisco, M. R., and Gonçalves, B. Political polarization on twitter.

[23] Dwork, C. Differential privacy. In ICALP’06.

[24] Geambasu, R., Kohno, T., Krishnamurthy, A., Levy, A., Levy, H. M., Gardner, P., and Moscaritolo, V. New directions for self-destructing data. Tech. Rep. UWCSE-11-08-01, University of Washington, 2011.

[25] Geambasu, R., Kohno, T., Levy, A. A., and Levy, H. M. Vanish: Increasing data privacy with self-destructing data. In USENIX Security Symposium ‘09.

[26] Geambasu, R., Levy, A. A., Kohno, T., Krishna-murthy, A., and Levy, H. M. Comet: An active distributed key-value store. In OSDI’10.

[27] Gomez-Rodriguez, M., Gummadi, K. P., and Schölkopf, B. Quantifying Information Overload in Social Media and Its Impact on Social Contagions. In ICWSM’14.

[28] Hine, G. E., Onaolapo, J., De Cristofaro, E., Kourtellis, N., Leontiadis, I., Samaras, R., Stringhini, G., and Blackburn, J. Kek, cucks, and god emperor trump: A measurement study of 4chan’s politically incorrect forum and its effects on the web. In ICWSM (2017), pp. 92–101.

[29] Krishnamurthy, B., Naryshkin, K., and Wills, C. Privacy leakage vs. protection measures: the growing disconnect. In WEB 2.0 SECURITY & PRIVACY 2011.

[30] Krishnamurthy, B., and Wills, C. E. On the leakage of personally identifiable information via online social networks. In WOSN’09.

[31] Maddock, Jim, K. S., and Mason, R. M. Using historical twitter data for research: Ethical challenges of tweet deletions. In CSCW ‘15 Workshop on Ethics.

[32] Mondal, M., Messias, J., Ghosh, S., Gummadi, K. P., and Kate, A. Forgetting in social media: Understanding and controlling longitudinal exposure of socially shared data. In USENIX SOUPS ‘16.

[33] Nair, S. K., Dashti, M. T., Crispo, B., and Tanenbaum, A. S. A hybrid PKI-IBC based ephemerizer system. In SEC’07.

[34] Perlman, R. The ephemerizer: Making data disappear. Tech. Rep. SMLI TR-2005-140, Sun Microsystems, Inc., 2005.

[35] Politwoops. http://politwoops.sunlightfoundation.com/. (Accessed on February 2018).

[36] Reimann, S., and Dürmuth, M. Timed revocation of user data: Long expiration times from existing infrastructure. In WPES’12.

[37] Srivastava, A., and Geethakumari, G. Measuring privacy leaks in online social networks. In ICACCI’13.

[38] van Liere, D. How far does a tweet travel?: Information brokers in the twitterverse. In MSM ‘10.

[39] Walck, C. Handbook on statistical distributions for experimentalists.

[40] Weber, R. H. The right to be forgotten more than a pandora’s box? jipitec 2, 2 (2011).

[41] Xue, M., Magno, G., Cunha, E., Almeida, V., and Ross, K. W. The right to be forgotten in the media: A data-driven study. PoPETs 2016, 4 (2016), 389–402.

[42] YouTomb. https://web.archive.org/web/20141029040225/http://youtomb.mit.edu/, 2017. (Accessed on February 2018).

[43] Zarras, A., Kohls, K., Dürmuth, M., and Pöpper, C. Neuralyzer: Flexible expiration times for the revocation of online data. In ACM CODASPY ‘16.

Journal Information


All Time Past Year Past 30 Days
Abstract Views 0 0 0
Full Text Views 988 988 34
PDF Downloads 31 31 14