My keynote talk given to the SEMAFOR (Security, Management, Audit Forum, presented by ISSA) in Warsaw, Poland on February 24, 2012. I look at the various ways social networking sites are (ab)using private client data, without the user’s consent, and highlight methods users can take to protect themselves.