1 / 330100%
INFORMATION SECURITY OF PERSONAL DATA ON SOCIAL
MEDIA
Introduction
The development of information technology and the internet today has changed the
way humans communicate. One of them is the development of social media, social media
has become part of life to obtain, share and disseminate information. Social media is one of
the most popular media today because it provides convenience and speed that allows a
person to create and distribute information. The current era of information technology is not
only for replying to messages and exchanging information but also provides convenience in
doing everything. Many benefits are derived from advances in information technology. Of
course, the use of information technology has also experienced rapid development, one of
which occurs in the field of communication. With the development of social media,
information security and privacy issues are also important today. Social media as a source of
leaking confidential information has become common today [1]. Privacy is personal
discretion. Privacy is inherent in every human being and should be respected. In this era of
information technology, data about a person's privacy has been widely spread on the
internet. Without realizing it, a lot of data about someone's privacy has been leaked on the
internet. Scattered privacy data can be caused by negligence or service providers [2].
Information system security is an important thing in social media, this security problem
often gets less attention from the owners and managers of information systems. The
development of social media which originally functioned to make it easier for users to carry
out social interactions using technology via the internet so that it changed the previous way
of disseminating information which was the dissemination of information that could be
received by many users who used social media such as social media facebook, Instagam,
twitter, whatsapp and other social media [3].
A research in 2019 by media company We Are Social in collaboration with
Hootsuite, which released data on the development of the number of internet users in United
States which stated that the rapid increase in internet users was 20 percent compared to the
number in 2018, in the release stated that there were 150 million social media users in
United States. In the previous year, 2018, the online community was shocked by the news of
the leak of 87 million personal data of Facebook users stolen by the Cambridge Analytica
Firm, moreover, about one million of the stolen personal data came from United States. The
CSIS survey results in August 2017 stated that 54.3 percent of millennials use online media
every day, 81.7 percent of millennials use Facebook, 70.3 percent use Whatsapp and 54.7
percent use Instagram. This makes the role of social media very crucial to persuade and at
the same time also provide vulnerability to the millennial generation."[4]
Social networking sites are online places where users can create a profile and
personal network that can connect with other users. For modern society, social media has
become a part of life to obtain or share information. Social media is one of the trending
media today, because it provides convenience and speed that allows a person to create and
distribute content. Social media is defined as a group of Internet-based applications that
build on the ideological and technological foundations of Web 2.0, and enable the creation
and exchange of user-generated content [4]. The Internet of Things is defined as a dynamic
global network infrastructure with self-configuration and interoperable communication. In
simple terms, IoT means the ability to make everything around us ranging from (e.g.
machines, devices, mobile phones, and cars) to even (cities and roads) can be connected to
the Internet with intelligent behavior and taking into account the existence of autonomy and
privacy types.
The advancement of information and communication technology, generates an
incredible amount of data. The data generated would be of no value if they could not be
analyzed, interpreted and understood. Meanwhile, according to Boyd, social networking
sites are web-based services that allow individuals to (1) create public or semi-public
profiles in the system, (2) articulating a list of other users with whom they can share
connections, and (3) viewing and searching their list of connections and those made by
others in the system. Furthermore, Kaplan and Haenlein define social media as "a group of
Internet-based applications that build on the ideological and technological foundations of
Web 2.0, and enable the creation and exchange of user-generated content". Social media
Information itself can be divided into several groups, including collaborative projects (e.g.
Wikipedia), blogs and microblogs (e.g. Twitter), social networking sites (e.g. Facebook,
LinkedIn, MySpace), content communities (e.g. YouTube, Flickr), virtual social worlds (e.g.
Second Life) [5][6]. Along with the openness of data and information, the protection of
information becomes mandatory. In recent years, rapid developments and lower costs in
information and communication technology have made it more accessible and convenient.
As a result, the number of internet users has exploded. Data misuse is also a particular
concern. Many data breaches occur due to poor implementation or absence of security
controls in both private companies and government organizations. Many countries are trying
to improve security requirements and implement them in their laws. However, most security
frameworks are reactive and do not address the relevant threats. Some of the reasons why
personal data is important to protect are
Personal data involves human rights and privacy that must be protected, as stated in:
Universal Declaration of Human Rights, 1948;
Law Number 12 Year 2005 on the Ratification of the International Covenant on Civil and
Political Rights;
Law No. 36/2009 on Health regulates the confidentiality of patients' personal conditions;
Law No. 10 of 1998 on Banking regulates personal data about depositors and their deposits.
Data is a high-value asset or commodity in the era of big data and the digital economy,
Data volume in 2015 is expected to reach 8 trillion GBs and will increase 40-fold by 2020.
(OECD, 2018);
Data-driven AI applications are projected to contribute US$13 trillion to the global economy
by 2030 (McKinsey, 2018).
Breach privacy and misuse of personal data are becoming more common,
Examples of activities: digital dossier, direct selling, location-based messaging;
Case in point: Cambridge Analytica (2018).
People are not yet fully aware of the importance of protecting personal data,
The number of internet users in United States continues to increase, but not all of them
realize the importance of personal data protection;
More than 30% of United States internet users are not aware that data can be retrieved
(APJII, 2017)[7].
Studies in the field of information security are ongoing and this is the foundation of
research that may be developed by looking at several advanced studies, involving not only
related fields of science such as computer systems, information systems, computer science,
informatics engineering, and information technology, but jointly according to the need to
involve other fields of science, such as management, social science, law and ethics [8].
Methodology
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Information System Security
Information system security is an asset that must be protected. Security is generally
defined as "the quality or state of being secure to be free from danger". To be secure is by
being protected from enemies and dangers with the following overview:
Physical Security which focuses on strategies to secure workers or organization
members, physical assets, and the workplace from various threats including fire
hazards, unauthorized access, and natural disasters.
Personal security overlaps with physical security in protecting people in the
organization.
Operation for a specific purpose, specific to the data owner at the time this
information is collected. Privacy ensures data security for the owner of the
information from others.
Identification
An information system has identification characteristics if it can recognize its use.
Identification is the first step in obtaining access rights to secured information.
Identification security is generally done with the use of user names and user IDs.
Authentication
Authentication occurs when the system can prove that the user is really the person
with the claimed identity.
Authorization
After identity user focuses the strategy to be authenticated, a process called
authorization provides assurance that users (human and computer) have been
specifically and clearly authorized to access, modify, or delete the contents of the
information.
Accountability
This characteristic is fulfilled if a system can present data on all activities against the
information that has been performed, and who performed those activities. Security
secures the ability of an organization or company to work without interruption.
Communications Security which aims to secure communication media,
communication technologies and their contents, as well as the ability to utilize these
tools to achieve organizational goals.
Network Security which focuses on securing the organization's data network
equipment, its network and its contents, and the ability to use the network to fulfill
the organization's data communication functions. Protection of the information is
done to fulfill the information security aspect.
Aspects of information security should be controlled for the protection of information
related to information security, namely:
Privacy
Information collected, used, and stored by the organization is used only information consists
of protection against aspects of Confidentiality, Integrity and Avalability namely:
Confidentiality
Aspects that guarantee the confidentiality of data or information, ensuring that information
can only be accessed by authorized persons and guaranteeing the confidentiality of data sent,
received and stored.
Integrity
Aspects that ensure that data is not changed without the permission of the authorized party
(authorized), maintaining the accuracy and integrity of information and process methods to
ensure this integrity aspect.
Availability
Aspects that guarantee that data will be available when needed, ensuring that authorized
users can use the information and related devices [3]. Protection is a prerequisite for online
self-disclosure, but self-disclosure is also a necessity reducing privacy by expanding the
measure of online data that different clients can access. Trust is characterized as the belief
that a person, gathering, or company can be trusted. It frequently has an opposite
relationship with protection, in view of the fact that individuals need to know the data of
others for the purpose end to trust him[9]
Previous Research
Majority informants have been using social media for more than 10 years, and the
longest has been using social media for 19 years, this illustrates that social media users have
been using social media since the platform first appeared, this indicates the Technology
Acceptance Model (TAM) theory which states the ease of use and perceived usefulness of
technology which determines the use of the technology, it can be concluded that the majority
of users find social media useful and easy to use among the millennial generation. This
shows that the majority of social media users are very familiar with social media. However,
the length of time users have been using social media over the years without using
passwords is very low as none of the users update their passwords regularly. Even more
worrying results are about millennials' concern for the importance of security procedures in
perceived ease of use as indicated by the statement that almost half of the respondents would
skip security procedures on social media if they were too complicated and would even use
an insecure website as long as it could help. In terms of security settings, the results show
that individuals who are more conscious of their password settings generally have a higher
level of awareness of their passwords. This is reflected in their intention to pay further
attention in creating more complex passwords to behave safely while using social media."[4]
The results of the analysis conducted by [1] show that some students who have
received information security courses have implemented actions in maintaining information
security on social media. However, students who have not gained a deep understanding of
information security still take actions that do not reflect the preservation of information on
social media. Another thing that can be seen is that Information Systems Study Program
students have understood the importance of information security but their behavior does not
reflect information security, they also have not taken advantage of privacy settings on social
media [1].
Privacy is a very crucial thing especially in the current era of Information
Technology. Personal data is data in the form of a person's personal identity and markers
that are personal. In various countries, the term personal information or privacy is also used.
As for the protection of privacy (in various forms), it is very important in the current Internet
era and is also certainly an important consideration for people who have the purpose of
conducting research using the Internet. However, the rapid development of society has led to
privacy-related challenges due to the increasing need for self-disclosure at the interpersonal
and organizational levels. There is a need for specific laws governing privacy in United
States. Various developed countries already have specific regulations on the protection of
personal data, but until now United States has no such regulations. This issue is only
regulated in Article 26 of the ITE Law and several other articles [2].
Research by [10] to measure respondents' awareness of the risks that can occur from
personal information leakage. Respondents were asked whether they post real personal
information on their accounts, the data showed that two-thirds (66%) of respondents were
concerned about the misuse of personal information on social media accounts. In addition,
69% of the respondents do not want strangers to see their personal information. respondents
were also asked if their account providers share their profile information with other
websites. The data shows that one-third (35%) answered yes. This highlights the need to
develop a framework that gives users the authority to allow or prohibit websites from using
personal data information. Results show that users are cautious about accepting friend
requests from strangers. While 71 percent of respondents accepted invitations to add
strangers as friends, 68 percent declined these requests.
Research Methods
The research method carried out is using the blended method. This research was
conducted by searching, reading, studying, and understanding literature or related to
information security on social media, as well as by library research. In general, mixed
methods research is research that involves the collection, analysis, and interpretation of
quantitative and qualitative data in a single study or in a series of studies investigating the
same underlying phenomenon.[11] Mixed methods research is a research design with
philosophical assumptions as well as methods of inquiry. As a methodology, it involves
philosophical assumptions that guide the direction of data collection and analysis and a mix
of qualitative and quantitative data in a single study or series of studies. This combination
can provide a better understanding of the problem research rather than using a single
approach[12]
Results And Discussion
Privacy refers to the English equivalent of privacy is the ability of one or a group of
individuals to defend their lives and personal affairs from the public, where one controls the
flow of information about oneself. Another description of privacy is an individual's right to
determine whether and to what extent one is willing to reveal oneself to others.
Privacy Function
There are three functions of privacy, namely:
Organizer and controller of interpersonal interactions which means the extent to which
relationships with others are desired.
Planning and strategizing for relationships with others, which includes intimacy or
distance in relationships with others.
Clarify the source's self-identity
Data Privacy
Data can be said to be personal data if the data can be used to recognize or identify someone,
an example of personal data is a student's identity number and the student's name on the
attendance sheet. The identity number can be used as a way to identify the student.
However, if the attendance sheet only contains a collection of student identity numbers
without the student's name, then it is only called data. The reason is because the data cannot
be used to identify someone.
Communication Privacy
Communication is the sending and receiving of messages or news between two or more
people so that the intended message can be understood. Privacy Communication in
information technology discusses how people can communicate with each other through
information technology without being monitored by third parties. Because everyone has
private boundaries, therefore we must also respect these boundaries. Only through certain
laws and methods can the limitations on communication privacy be ignored [2].
Online Privacy
Various data and information are collected with increasing frequency and in different
contexts, making individuals more transparent. The social and financial costs of acquiring
and analyzing this data have risen sharply with technological advances. This phenomenon
raises issues such as privacy. There are concerns that the Internet can erode privacy [13] and
that privacy issues in offline or face-to-face social interactions are magnified in online
interactions. There are a number of specific threats when conducting transactions online
with regard to privacy. For example, the effect of surfing the Internet means that when we
go online, we indirectly leave a digital footprint in many areas of our lives that were
previously considered "offline". The rapid development of computing power, such as
processing speed, increasing storage capacity, wider communication connectivity, and the
size of connection capacity at low cost all ultimately affect privacy. Therefore, there are
important privacy issues associated with online activities. Of course, there are also benefits
to the described technological advancements such as (personalized service, convenience,
improved efficiency). Users can provide valuable information about themselves to take
advantage and benefit. Such activities as the American Life Survey (2001) reported that
more than two-thirds of users are willing to share their personal information under some
circumstances. In some situations, expressive privacy can be gained through the loss of
privacy information to third parties. For example, a person may disclose personal
information and credit card information for the convenience of completing an online
transaction. In this way, the collection of personal, privacy information can be considered a
"double-edged sword".
Freedom of Information
Freedom is a basic principle, which generally experts have the same conception that freedom
exists in every human being. Explicitly, freedom always has limits, both internal and
external weaknesses. Basically, freedom does not mean doing what you want, but there are
limits to recognizing and respecting the rights and obligations of every human being in
general. Information has introduced a new ethic, that every party who has information has
the instinct to always disseminate it to other parties, and vice versa. Information technology
promises that the 21st century community will have communication networks and multi-
media technology as its backbone. The respect for privacy in a globalized informatics
community is very different in a fiscal setting, as is the interest in data privacy. The need to
maintain the confidentiality of personal data and information appears to be a priority for
placing trust in the network of communication interactions.
Anonymity in Online Activities
Anonymity is not identity. For example, for people participating in elections, of course,
when voting, they do not write their names on the ballot paper. This is to ensure
confidentiality during elections. Privacy and anonymity are two closely related and similar
things. But the principle is that anonymity is for privacy while privacy does not necessarily
require anonymity, although it usually does. Privacy can be obtained by applying security
such as encryption. For example, when sending an e-mail that includes an address and name,
but the content is scrambled to prevent others from seeing the contents of the e-mail. In
digital media such as the internet, whatever service is used, at least someone has opened
their own identity. How and what about that person can be known by others. The following
steps can be taken to maintain privacy when surfing in cyberspace.
Change privacy or security settings. Understand and use this security setting feature to
its full potential.
Make your password as strong as possible. When registering online, it's best to use a
combination of upper and lower case letters, numbers, and symbols to avoid being
easily traced.
Keep your password secret.
Do not use questions regarding date of birth, address, mother's name as these are
almost always used as security questions for bank and credit card databases. This gives
hackers the opportunity to steal identities and steal money.
Always log out. Always remember to log out of your account, especially if you are
using a public facility computer.
Wi-FI. Create a password to use wi-fi, otherwise, there may be intruders who enter the
network.
Do not share sensitive information i.e. avoid sharing information of a personal nature.
Make it harder to log in to your account by choosing a strong and unique password,
and turning on two-factor authentication.
Use apps with end-to-end encryption This is a feature in chat apps to keep personal
data safe on social media.
Always check the application to make sure you understand the various accesses
required by the application[14].
The six main points that should be considered when using online application systems
related to data privacy are security and data protection, user awareness, control
settings, risk management, transparency, and ethics[15].
Conclusions
Issues of privacy and trust are crucial not only for the design of computer systems
but also for how research is conducted online. Some important points are security and data
protection, user awareness, control settings, risk management, transparency, and ethics.
System developers in agencies that manage personal information should implement
guidelines or SOPs to limit the amount of personal information collected and the role of
privacy policies that require self-disclosure on a Must Know basis, because based on the
general assumption that all information management administrators have full access to user
data, there is a possibility for the need for fairly strict regulations. It is necessary to build
trust into the design of Internet services, either through the design activities of managing a
system that prioritizes user priority. Possibly, users are given the option of a control
mechanism for whether or not they need to use the Internet in disclosing personal
information and its use.
Students also viewed