What I shared with my stalkers on social networks

One Thursday afternoon at the office in San Francisco, a person whose face was vaguely familiar approached me (Leah) at my desk with a knowing grin.

“Awww, man! You found me,” I said with a groan. The man proceeded to tell me where I live, where I had gotten lunch earlier that day, and what I had been up to over the weekend. Even though it was approaching 6:00 p.m., which is a little later than I usually stayed at work, he knew I was still in the building. He had no keycard to access our office, yet he followed someone in, and walked around until he recognized me.

This man and I don’t communicate with each other at all. We briefly worked in the same building a few years ago, but we aren’t regular friends, and we aren’t connected on Facebook or any other social network. He doesn't have my e-mail address, and I don't have his. Yet here he was standing at my desk at work, telling me what time my plane had landed when I visited Long Beach on a recent weekend.

How on earth was he able to find out so much about me? He simply used a few commonly available mobile and social apps and the social networks and services where I had signed up and left various bits of personal information and had used only the default privacy settings.

The TMI culture

Most of us are guilty of oversharing, and the social platforms we love and use on a regular basis make it so easy to do so—the "too much information" culture being one result. But one problem that many social users still don’t understand is how important it is to pay attention to privacy settings. Today’s mobile and social platforms make it possible to walk right up to the line of privacy invasion, and if you’re not careful, anyone could find out pretty much anything they want about you.

The "strange man" who approached my desk was one of two freelancers TechHive had hired to "stalk" me. Giving them only my first and last name and personal email address (which they could easily have found out on their own, as it’s publicly listed), we at TechHive asked freelancers Chris Holt and Sam Felsing to find out as much about me as they possibly could.

Here’s what they found, in their own words.

Stalker #1: Chris Holt, Social Detective

“Phil Michaels knocked on my door on a Friday. Chomping a cigar, the seasoned editor threw a file on my desk. ‘Holt, we got a job for you.’ I pushed back my fedora and told him that I had quit the force, but he told me that this would be worth my time.

Leah's Facebook timeline, as viewed by Chris Holt, who wasn't on her Friends list.

"I looked at the file. It was a tail job, but with an interesting twist: I had to track the subject using only social networks—with her account on all of them set to default privacy settings. I laughed. This would be like doing a stakeout with the blinds open. I took the case, grateful for the easy money.

"The first thing I did was search for the subject on Facebook. She was easy to find, with a unique last name, but I could have found Joe Anybody just as easily if I had their e-mail address. I now knew what she looked like and could access the 40 or so profile photos she had saved. I also knew basic info like her job (assistant editor), her favorite bands (No Doubt, Saves the Day), and her work experience (PC World intern, Urban Outfitters sales associate).

"With Google+, I got her education (NYU) and the places she's lived. I could also check out her photos and any posts she's had, though both at this point are empty. If she posted here more often than on Facebook, I'd imagine I'd have similar info.

"Since her Foursquare account was linked to her Facebook account, I knew some of her movements. The assignment was requiring less and less legwork for this gumshoe. The subject checked in at the Oakland Airport and declared on Facebook her intention to travel to Long Beach for the weekend, so I knew exactly where she was going to be. Unfortunately, this also meant she was out of range for People Around You and Highlight, two apps designed for close-range meeting up/stalking.

"So I settled in the office for a long night with my partner: a tall bottle of Jameson. I was quickly gaining more information for my growing dossier. I turned to Twitter to learn whatever treatises she could express in 140 characters or less, and to my surprise I simply had to search for her full name to gain access to her running life diary. By Friday afternoon I had a running commentary on her likes, plans, and opinions in addition to her whereabouts and basic information. Plus, a slight buzz.

"I wracked my brain trying to guess her Instagram account—with no success, until, on Saturday, unshaven and feverish, I followed a hunch: I checked some of her Twitter images, and sure enough, they included the name of her Instagram account. Now I had a full range of pictures that showed me what exactly she was doing. The game was afoot.

"When she went to the FYF Fest in L.A. on Saturday, she checked in with Foursquare and took a picture. Based on the photo, I could probably have figured out where she was within 10 feet—this, in a crowd of thousands. With her friends tagged, it was even easier. Who needed binoculars? This stakeout was cake.

"Because it was the Labor Day weekend, I figured that she would fly back on Sunday night. If I had wanted to, I could probably have looked up flights and known within a 3-to-4-hour window when she was arriving. But she never checked in at an airport, so I had to wait until she resurfaced on social media to know her whereabouts.

"I didn't have to wait long. On Tuesday morning, I had shaved and sobered up, and she had checked in at her favorite breakfast place in the Upper Haight on the way to work. Looking at the Foursquare map on her Facebook profile, I realized that the places where she had the highest concentration of check-ins was her place of work (in SoMa—south of Market) and home. She checked in at the same breakfast places and coffee shops (such as Peet's on 2nd) near her work on a regular basis. I also knew what her favorite lunch places were (Small Foods) and where her gym was (Crunch on New Montgomery). From this, it was easy to determine not only her neighborhood and work, but also her routes to and from these places, and her hours.

"The last part of my assignment was to physically find her, and I had to decide between her work and her home. Either way, I just had to keep my People Around Me and Highlight apps open, and I could drive within a radius of a few blocks and be alerted to her presence. I ultimately decided that her check-in patterns were more consistent near her work, so I'd start there. I drove to that neighborhood, and within three blocks, Highlight alerted me to which block the subject was on. (People Around Me was supposed to do something similar but kept crashing.)

"Making my way into her office, I confronted the subject and gave her the rundown, the whole yarn: where she was this weekend, what she was doing, who she was with, and other details: her favorite places to go after work, her hours, her gym. I knew it all. I could tell her within a three-block radius where she was for some 18 to 20 of the hours of the day.

"The truth of the matter was, Phil Michaels didn't need the services of Chris Holt, private detective. He could have gone with someone far less dashing. And honestly, anyone could have done what I did to learn about the subject. Aside from credit card and social security numbers, there was nothing that was unavailable to me... and that's frightening. I told Michaels that he didn't need to hire a detective to search someone on social media next time—he might as well ask to search the pockets of a naked person.

"And that's when he kicked me out of the office.”

Stalker #2: Sam Felsing, Web Sleuth

“What could a stranger find out about you simply by typing your name into Google? What could they find on your Facebook, Twitter, or Foursquare accounts, even if it’s someone you’re not connected to? Could they find your address, your mother’s maiden name, your date of birth, or your favorite coffee place through examining your digital footprint?

"It’s totally possible. I found all these details about a person I had met only briefly more than two years ago.

If you're not careful, a stranger could potentially see a map of your Facebook check-ins.

"For one week, I spent a couple hours a day stalking a female editor at a tech publication. I never hid outside her home, nor did I rifle through her garbage. Instead, I used my Internet savvy to find out as much as I could about her online. And I found a lot. I started the project with only her name and email address; I ended it with information that ten years ago would have been impossible to get by myself.

"I was never friends with the subject in real life, nor on any social media outlet, so I had to rely on Google to find most of her online information. But my Internet stalking was helped by a very uncommon trait about the subject: Very few people in the United States share her almost unique last name. In fact, a quick search on the How Many of Me website reveals that perhaps just one person with the subject’s name lives in the country.

"I found many of the subject’s social networking sites simply by typing her name into the search bar. Her accounts on Facebook, Google+, LinkedIn, and Twitter instantly appeared in my search results. I got her Foursquare and Instagram accounts using the information she publicly provides on the social media sites I found on Google.

"Much of the subject’s personal information was on Facebook. Her About section reveals where she grew up, where she went to college, and where she currently works. After typing this information into Google, I was easily able to find the addresses of her college and place of business.

Sam Felsing was able to find the subject's childhood home through Google.

"Though the subject doesn’t list a lot of information about herself in her Facebook About section, her friends have left a substantial amount of personal information on her Wall. Using Facebook’s Timeline feature, I was able to scroll through her old Wall posts to find her birthday, her cousin’s name, and her travel history. I used this information to expand my Google search parameters, which allowed me to find a couple of her old travel blogs.

"Finding the name of the subject's hometown on her Facebook page led to much, much more information. I typed the subject’s name and her hometown into various search engines, like Spokeo and Whitepages, and was able to uncover her parents’ address and phone number. Spokeo actually has an attached Google street view of her parents’ house.

"Both Spokeo and Whitepages list the names of the editor’s immediate family members. Using that information, I found the social media sites of her mom, dad, and sister. The family’s social media sites in turn revealed a great deal about her (like her mother's maiden name and her parents’ anniversary), and included links to her Tumblr blog and an abandoned Twitter account.

"The subject's Tumblr page was also very revealing: That’s where I found her Instagram info. Pictures of food and guinea pigs didn’t give too much away, but Instagram keeps records of where photos are taken. It doesn’t give addresses, but it does put markers nearby or in front of the areas where the pictures were taken. I was able to click on her blog’s past Instagram pictures, see on Google maps where they were taken, then use the comments that the editor and her friends had left on the pictures, to identify where the editor currently lives. Instagram’s new PhotoMap feature also makes this easy."

The victim’s perspective

Although the stalking in this case was just for fun, the dirt that both Chris and Sam were able to dig up left me feeling very vulnerable. If Chris was, say, a burglar or a car thief, he had all the information he needed to heist my ride or break into my home while I was away for the weekend. And if Sam was some creepy guy I met at gathering last week, he’d have everything he needs to pester me in person when I refuse to text him back.

After reading my stalkers' findings, I took action. My settings across every social platform I’m on (except Twitter) are now restricted, so people that I don’t know or haven’t approved of can’t view my posts or information. However, I had to tweak these settings myself, because most social sites make your personal information public by default. If you're not careful and use those sites frequently, location-enabled settings can really get you in trouble—so fix those settings.

Much of what Sam was able to find out about me on the Web, I can’t really erase. My digital footprint is pretty unshrinkable, especially because of my unique name, which I’m kind of attached to. It would also take some work to erase my parents’ information that is listed on public records sites like White Pages—data such as their landline number and the address of the home that they own. I can, however, show them how to update their privacy settings on Facebook to restrict what others can see, and use some restraint myself when posting.

Here’s how to change your privacy settings on a few popular social networks:

Facebook: On your main News Feed page, click the down arrow next to your name and the Home button in the top right corner, and then select Privacy Settings from the drop-down menu. Under the Control your Default Privacy section, select your desired level of privacy. The "Friends" option is probably a good place to start, but for more control, select Custom. Continue on through the list of Privacy Settings, and edit each one to the level you prefer. Take special notice of the Ads, Apps, and Websites section—if you post to Facebook from other apps you use, that information might be publicly available to others as well. My Foursquare posts appeared public because they were listed as public in this section.

Twitter: If you’d prefer, you can make all of your Tweets private, meaning you must approve of all followers before they can see what you Tweet. To set this, go to your profile settings from the drop-down menu next to the Search bar. Select the "Protect my Tweets" box in the "Tweet privacy" section to prevent your posts from being publicly available. To keep your Tweets public, but without location information, uncheck the "Add a location to my Tweets" box in the "Tweet location" section. (Or, you can keep this box checked and opt out of including location info in individual Tweets, which Twitter provides an option for.)

Foursquare: Surprisingly, Foursquare has a pretty solid privacy plan, considering that it's a service entirely based upon sharing your location. By default, only people on your Foursquare friends list can see your check-ins. However, if you decide to publish your check-ins to other social sites, like Facebook or Twitter, the privacy settings are different. When I linked Foursquare to my Twitter account and opted ot Tweet my Foursquare check-ins, those check-ins were now public via Twitter. Facebook was similar—anyone with a Facebook account could see my Foursquare check-ins, even if we weren't connected. Take a look at Foursquare's privacy settings by going to the drop down Profile Settings page; Facebook's settings for linked apps can be changed in the Ads, Apps, and Websites section.

Instagram: You can opt to keep your Instagram feed private and available only to those followers with whom you've approved. From your profile page, click the Edit Your Profile button, then hit the Preferences cog wheel. Scroll down to the Account settings, and slide the switch that reads Photos Are Private from off to on.

Subscribe to the Best of PCWorld Newsletter