HOW NOT TO GET HACKED ON FACEBOOK
from the article 'Facebook Users: How Not to Get Hacked'
By Kimberly Weisul | May 10, 2011
There are plenty of things Facebook users, and others, can do to protect their personal information online. Consumer Reports recommends:
Keep tabs on your kids’ accounts. Some kids won’t ‘friend’ their parents, of course, but they just might fork over their user name and password. Other parents can keep up on their children’s online activities via siblings or other friends.
Use privacy controls. Consumer Reports found that one in five adult Facebook users don’t use privacy controls. Whenever Facebook gives you a choice, set the information to be visible only to your friends. Otherwise your profile picture, friends list, activities, and other info can be seen by anyone who does a public search on your name.
Turn off Instant Personalization. Instant personalization shares your location information with sites such as Yelp and TripAdvisor (and the list is growing). The default setting for “instant personalization” is “on,” but you can turn it off.
Be careful with apps. In most cases, you can decide which information an app can see. Facebook says it doesn’t share identifiable information with advertisers, but using an app does make general information available.
Set a PIN number for your phone. Most smartphones allow you to set a four-digit PIN for your phone, but only about 20 percent of people-even those who store sensitive information on their phones-actually do this.
Protect your phone. The PIN is just the start. Many manufacturers offer over-the-air backup, remote phone locating, remote phone locking, and erasing of data and account info. You can also get software to lock your phone or erase data remotely. Turn off the phone’s GPS feature if you don’t need it.
MY THOUGHTS
I never liked the apps.
Saturday, May 14, 2011
Monday, April 11, 2011
SOCIAL NETWORKING "FRENEMIES"
Social Networking Leads to "Frenemies" For Women
Author: Ayra Moore
Published: March 31, 2011 at 6:47 pm
So,you hear time and time again how “great” the social network is, right? Well, for some, it is.
A majority of women, however, have become quite disgusted with the “friends” they have collected on Facebook, finding them very bothersome at times.
According to an article posted on Networkworld.com, Eversave, a company dealing in coupons, recently conducted a survey centered on how social networking influences shopping and the use of deals. They got a lot more info than they expected apparently.
Woman, who still admit they communicate more frequently and readily thanks to social networking, are also complaining about their Facebook pals. The women are getting tired of seeing status updates from their newfound “frenemies” regarding personal complaints, praise for their children, grandchildren, political views and bragging about their lives in general.
The result, in my opinion, to these,very amusing, recent findings is simple: No matter what outlet women use to attempt to communicate, we will always find that the company of other women will grow annoying and tiresome if it lasts too long. What is the saying regarding “too much of a good thing”? It may very well do you harm. Women and their “frenemies” should take note.
Read more: http://technorati.com/lifestyle/article/social-networking-leads-to-frenemies-for/#ixzz1INa62MAn
MY THOUGHTS
What bothers me about Facebook is that you are 'friends' with people who are not really your friends. If you are, why would status updates about family annoy you? Why would you consider 'happy news' as 'bragging'? Why won't you want to know more about your 'friend' through their 'political views'?
My biggest question is - why are you on Facebook if things like these annoy you?
Author: Ayra Moore
Published: March 31, 2011 at 6:47 pm
So,you hear time and time again how “great” the social network is, right? Well, for some, it is.
A majority of women, however, have become quite disgusted with the “friends” they have collected on Facebook, finding them very bothersome at times.
According to an article posted on Networkworld.com, Eversave, a company dealing in coupons, recently conducted a survey centered on how social networking influences shopping and the use of deals. They got a lot more info than they expected apparently.
Woman, who still admit they communicate more frequently and readily thanks to social networking, are also complaining about their Facebook pals. The women are getting tired of seeing status updates from their newfound “frenemies” regarding personal complaints, praise for their children, grandchildren, political views and bragging about their lives in general.
The result, in my opinion, to these,very amusing, recent findings is simple: No matter what outlet women use to attempt to communicate, we will always find that the company of other women will grow annoying and tiresome if it lasts too long. What is the saying regarding “too much of a good thing”? It may very well do you harm. Women and their “frenemies” should take note.
Read more: http://technorati.com/lifestyle/article/social-networking-leads-to-frenemies-for/#ixzz1INa62MAn
MY THOUGHTS
What bothers me about Facebook is that you are 'friends' with people who are not really your friends. If you are, why would status updates about family annoy you? Why would you consider 'happy news' as 'bragging'? Why won't you want to know more about your 'friend' through their 'political views'?
My biggest question is - why are you on Facebook if things like these annoy you?
Labels:
emotional fitness,
facebook,
facebook overshare,
facebook. facebook habits,
relationships,
social networking tips
Thursday, April 7, 2011
SOCIAL NETWORKS FOR KIDS
Top 3 Kid-safe Social Networks
By helle Hainer
Every Day Connected
When Rachel Sarah of Oakland, Calif., first heard about Club Penguin, a social networking site for kids, she had no idea what it was. "My daughter kept asking me if she could use it," recalls Sarah. Not sure whether her daughter, who's under 13, was too young to be on the Web, Sarah decided to check it out herself. "There aren't any ads, and the site seems really fun and innocent," says Sarah.
But how can you be sure a site is really what it seems? We’ve done the legwork for you and found the top three social networks for kids. Here’s how they keep kids entertained while making their safety a top priority:
CLUB PENGUIN
Kids are given a penguin avatar that can interact with the other penguins on the site, play games and earn coins to buy accessories for their penguin or furniture for their igloo. Membership is $5.95 per month for premium access, which allows kids to customize their penguins.
Age group: 8 to 14, although older kids can join too. Parents register kids who are under 13.
What kids love: The penguins are simple and cute. Kids can get creative when customizing the look of their penguin and igloo, and meet other penguin friends for coffee or tea.
Privacy and safety features: Parents can choose between the Standard Safe-Chat, which allows kids to type their own chat messages, or Ultimate Safe-Chat, which restricts them to prewritten words or phrases, like "Hello" or "What's up?" "Club Penguin has really strong filters, so you won't need to worry about kids swearing or going crazy," says Anastasia Goodstein, author of Totally Wired: What Teens and Tweens Are Really Doing Online.
MY THOUGHTS
I hope moms and dads with kids under 13 would check out these sites.
By helle Hainer
Every Day Connected
When Rachel Sarah of Oakland, Calif., first heard about Club Penguin, a social networking site for kids, she had no idea what it was. "My daughter kept asking me if she could use it," recalls Sarah. Not sure whether her daughter, who's under 13, was too young to be on the Web, Sarah decided to check it out herself. "There aren't any ads, and the site seems really fun and innocent," says Sarah.
But how can you be sure a site is really what it seems? We’ve done the legwork for you and found the top three social networks for kids. Here’s how they keep kids entertained while making their safety a top priority:
CLUB PENGUIN
Kids are given a penguin avatar that can interact with the other penguins on the site, play games and earn coins to buy accessories for their penguin or furniture for their igloo. Membership is $5.95 per month for premium access, which allows kids to customize their penguins.
Age group: 8 to 14, although older kids can join too. Parents register kids who are under 13.
What kids love: The penguins are simple and cute. Kids can get creative when customizing the look of their penguin and igloo, and meet other penguin friends for coffee or tea.
Privacy and safety features: Parents can choose between the Standard Safe-Chat, which allows kids to type their own chat messages, or Ultimate Safe-Chat, which restricts them to prewritten words or phrases, like "Hello" or "What's up?" "Club Penguin has really strong filters, so you won't need to worry about kids swearing or going crazy," says Anastasia Goodstein, author of Totally Wired: What Teens and Tweens Are Really Doing Online.
MY THOUGHTS
I hope moms and dads with kids under 13 would check out these sites.
Saturday, April 2, 2011
CAN YOU SAVE THROUGH FACEBOOK?
Can Facebook Help You Spend Less?
How to use social networking to find great fashion and beauty deals
Lynn Strong ON Mar 17, 2011 at 11:52PM
www.ivillage.com
It's wild how social media sites like Facebook have taken over the world, isn't it? Everybody's online these days, and companies everywhere are figuring out how they can use Facebook to promote their businesses and make more money. That makes it high time to follow their lead and start using Facebook to your own advantage to actually save money on what you buy. It can be done!
Now that more and more fashion brands are creating Facebook pages, all you really have to do is “Like” a brand's page and you'll have instant access to special sale alerts, coupon codes, insider deals, and more. You'll also be the first to learn about new products or special store-only events. Liking a page is like gaining access to a special members-only fan club for a particular clothing or beauty line. What could be better?
If you're not convinced, check out a few Facebook promotions I came across this week:
Sample Saturdays: Simply by Liking Nordstrom Beauty's page, you'll be part of Sample Saturdays. Each Friday one product sample is revealed and the sample is available in the cosmetics and fragrance departments in all Nordstrom stores the following day, exclusive to Facebook (and Twitter) followers.
Drugstore.com: I was surprised to learn that Drugstore.com is on Facebook offering specials to shoppers -- everything from free shipping (no matter how much you ordered) to discounts on gift cards and more -- just for Liking the page.
For Shoe Lovers: You'll also have access to flash sales and limited-time-only offers. Via Spiga (amazing shoes!), which posts different contests and deals on Facebook frequently, this week posted a special spring sale coupon code for 20 percent off all purchases. Only Facebook fans got the memo!
It takes just a few seconds to find your favorite brands on Facebook and become a fan of their pages -- and the savings will really add up. Give it a try!
MY THOUGHTS
Worth a try? Maybe. Maybe not. What have you got to lose?
How to use social networking to find great fashion and beauty deals
Lynn Strong ON Mar 17, 2011 at 11:52PM
www.ivillage.com
It's wild how social media sites like Facebook have taken over the world, isn't it? Everybody's online these days, and companies everywhere are figuring out how they can use Facebook to promote their businesses and make more money. That makes it high time to follow their lead and start using Facebook to your own advantage to actually save money on what you buy. It can be done!
Now that more and more fashion brands are creating Facebook pages, all you really have to do is “Like” a brand's page and you'll have instant access to special sale alerts, coupon codes, insider deals, and more. You'll also be the first to learn about new products or special store-only events. Liking a page is like gaining access to a special members-only fan club for a particular clothing or beauty line. What could be better?
If you're not convinced, check out a few Facebook promotions I came across this week:
Sample Saturdays: Simply by Liking Nordstrom Beauty's page, you'll be part of Sample Saturdays. Each Friday one product sample is revealed and the sample is available in the cosmetics and fragrance departments in all Nordstrom stores the following day, exclusive to Facebook (and Twitter) followers.
Drugstore.com: I was surprised to learn that Drugstore.com is on Facebook offering specials to shoppers -- everything from free shipping (no matter how much you ordered) to discounts on gift cards and more -- just for Liking the page.
For Shoe Lovers: You'll also have access to flash sales and limited-time-only offers. Via Spiga (amazing shoes!), which posts different contests and deals on Facebook frequently, this week posted a special spring sale coupon code for 20 percent off all purchases. Only Facebook fans got the memo!
It takes just a few seconds to find your favorite brands on Facebook and become a fan of their pages -- and the savings will really add up. Give it a try!
MY THOUGHTS
Worth a try? Maybe. Maybe not. What have you got to lose?
Sunday, February 27, 2011
FACEBOOK AT WORK
Facebook and the Law: The NLRB Got It Right
By Suzanne Lucas | February 10, 2011
The National Labor Relations Board (NLRB) issued a press release about the much talked about Facebook Case. The press release states:
Under the terms of the settlement approved today by Hartford Regional Director Jonathan Kreisberg, the company agreed to revise its overly-broad rules to ensure that they do not improperly restrict employees from discussing their wages, hours and working conditions with co-workers and others while not at work, and that they would not discipline or discharge employees for engaging in such discussions. (Emphasis is mine.)
You know what this is? Nothing new and nothing exciting. This is right in line with previous decisions regarding the rights of employee to talk about their salaries, hours and working conditions. It makes perfect sense to consider Facebook and other social media as talking. Because that is precisely what it is.
Now, this does not mean that the internet becomes a free-for-all. If you could be fired for talking about it before, you can still be fired now for posting about it. (And remember this is a union case, and doesn’t necessarily apply to the majority of American workers.)
This will not be the last we hear of Facebook and the law. Other Facebook related cases are pending. You would be smart to be cautious about what you say and post on the internet, because unless you are saying something that is explicitly protected, your boss can still fire you.
UPDATE: I got an e-mail from Nancy Cleeland, NLRB’s Director of Public Affairs. She gave me permission to post her e-mail for further clarification:
Thanks for your post on the Facebook settlement, which someone just forwarded to me. I just wanted to point out that even though the employee was represented by a union, our concerns related to the company’s social media policies and her postings were not union-related and would apply to any private-sector workplace that is under the NLRB’s jurisdiction.
So, this is farther reaching than I originally said. I’ll be keeping my eye on any Facebook (and other social media) cases, and now I have a contact at the NLRB.
MY THOUGHTS
this is not local news and i have not heard of any local case like this one. but i'm pretty sure this subject has caused companies (and individuals) headaches. a lot of people are not mature enough to handle the freedom.
i had a short project with a company whose employees are spending so much time on FB and youtube and all those internet sites. we had to hire someone to block certain sites. of course it caused some uproar. and i did not totally agree with the way it was handled. but it had to be done.
i think companies should immediately draw up internal policies on social networking while at work. don't wait for it to fester. and come-up with some way for people to still do social networking during break time. a kiosk would work.
By Suzanne Lucas | February 10, 2011
The National Labor Relations Board (NLRB) issued a press release about the much talked about Facebook Case. The press release states:
Under the terms of the settlement approved today by Hartford Regional Director Jonathan Kreisberg, the company agreed to revise its overly-broad rules to ensure that they do not improperly restrict employees from discussing their wages, hours and working conditions with co-workers and others while not at work, and that they would not discipline or discharge employees for engaging in such discussions. (Emphasis is mine.)
You know what this is? Nothing new and nothing exciting. This is right in line with previous decisions regarding the rights of employee to talk about their salaries, hours and working conditions. It makes perfect sense to consider Facebook and other social media as talking. Because that is precisely what it is.
Now, this does not mean that the internet becomes a free-for-all. If you could be fired for talking about it before, you can still be fired now for posting about it. (And remember this is a union case, and doesn’t necessarily apply to the majority of American workers.)
This will not be the last we hear of Facebook and the law. Other Facebook related cases are pending. You would be smart to be cautious about what you say and post on the internet, because unless you are saying something that is explicitly protected, your boss can still fire you.
UPDATE: I got an e-mail from Nancy Cleeland, NLRB’s Director of Public Affairs. She gave me permission to post her e-mail for further clarification:
Thanks for your post on the Facebook settlement, which someone just forwarded to me. I just wanted to point out that even though the employee was represented by a union, our concerns related to the company’s social media policies and her postings were not union-related and would apply to any private-sector workplace that is under the NLRB’s jurisdiction.
So, this is farther reaching than I originally said. I’ll be keeping my eye on any Facebook (and other social media) cases, and now I have a contact at the NLRB.
MY THOUGHTS
this is not local news and i have not heard of any local case like this one. but i'm pretty sure this subject has caused companies (and individuals) headaches. a lot of people are not mature enough to handle the freedom.
i had a short project with a company whose employees are spending so much time on FB and youtube and all those internet sites. we had to hire someone to block certain sites. of course it caused some uproar. and i did not totally agree with the way it was handled. but it had to be done.
i think companies should immediately draw up internal policies on social networking while at work. don't wait for it to fester. and come-up with some way for people to still do social networking during break time. a kiosk would work.
Labels:
barring facebook,
productivity,
social networking
Wednesday, February 9, 2011
SOCIAL NETWORKING SITES FOR PARENTS
Social Networks For Parents: Some of the best
January 21, 2011 | Debbie Turner
The world of social networking is increasingly commonplace and although it has great benefits it’s fair to say some negative points have also been made. For example recently we were told how it’s now natural for many parents and their teens to extend their relationship on Facebook and it can be a valuable line of communication.
Earlier today though, we also told of a Facebook scam that targets children. As a parent, it can sometimes seem like a minefield to negotiate the right path to bring up our children but online resources can be extremely useful and there are some great social networks, specifically for parents. Sarah Kessler over on Mashable has been doing some research into parenting social networks and has 6 suggestions of valuable sites.
It’s fair to say that no matter how good the advice, a good site should also have an active community and CafĂ©mom received particular praise for this. Users can make journal entries and blog posts and the discussion isn’t always based around parenting but forums cover other topics too. You can also introduce yourself to other moms and of course find the usual advice on potty training, relationships, baby names and much, much more.
For those who wonder where the parenting sites are that don’t revolve around moms you might like Minti, which has a vast amount of information but not so much in the way of an active community. However there’s plenty of archived advice from other parents and users are encouraged to write blog posts. Take a look at the Mashable link above to see all the other ideas suggested.
You may also be interested in an article on The Merrimack Journal by Wendy Thomas that tells of one parent group that uses Facebook as a tool to provide local parents with information, advice and resources in an attempt to assist them to be a positive influence for their kids.
Have you tried any of the Mashable suggestions for social networks for parents or have you any others that you’d like to suggest to our readers? Why not send us your comments to let us know.
MY THOUGHTS
moms, check out the Cafemom site. don't bother about Minti. not available in our country.
January 21, 2011 | Debbie Turner
The world of social networking is increasingly commonplace and although it has great benefits it’s fair to say some negative points have also been made. For example recently we were told how it’s now natural for many parents and their teens to extend their relationship on Facebook and it can be a valuable line of communication.
Earlier today though, we also told of a Facebook scam that targets children. As a parent, it can sometimes seem like a minefield to negotiate the right path to bring up our children but online resources can be extremely useful and there are some great social networks, specifically for parents. Sarah Kessler over on Mashable has been doing some research into parenting social networks and has 6 suggestions of valuable sites.
It’s fair to say that no matter how good the advice, a good site should also have an active community and CafĂ©mom received particular praise for this. Users can make journal entries and blog posts and the discussion isn’t always based around parenting but forums cover other topics too. You can also introduce yourself to other moms and of course find the usual advice on potty training, relationships, baby names and much, much more.
For those who wonder where the parenting sites are that don’t revolve around moms you might like Minti, which has a vast amount of information but not so much in the way of an active community. However there’s plenty of archived advice from other parents and users are encouraged to write blog posts. Take a look at the Mashable link above to see all the other ideas suggested.
You may also be interested in an article on The Merrimack Journal by Wendy Thomas that tells of one parent group that uses Facebook as a tool to provide local parents with information, advice and resources in an attempt to assist them to be a positive influence for their kids.
Have you tried any of the Mashable suggestions for social networks for parents or have you any others that you’d like to suggest to our readers? Why not send us your comments to let us know.
MY THOUGHTS
moms, check out the Cafemom site. don't bother about Minti. not available in our country.
Monday, February 7, 2011
HOW SECURED IS FACEBOOK
Facebook defends security strategy
Shy social network responds to criticism
By John Leyden • Get more from this author
Posted in Malware, 21st January 2011 16:01 GMT
Analysis Facebook has defended its record in thwarting rogue applications and other security in the face of criticism from security firms that it ought to adopt tighter application controls.
The dominant social network disputes findings from a threat report by UK-based net security firm Sophos, released earlier this week, that spam, malware and other attacks have become more effective against Facebook users over the last year.
Facebook reckons the opposite is true while disputing the methodology adopted by Sophos which it said looked, for example, at the volume of spam sent to Facebook users instead of the volume that reached their in-boxes.
Facebook said: "If your spam filter catches all the spam, does it matter that your filter caught 10 per cent more?"
The social networking site reckons less than three per cent of communications on Facebook are spam, compared to industry estimates that email spam makes up 90 per cent of all electronic messages. The implication is that Sophos is focusing on the wrong problem.
Unfriending rogues
Survey scams have become an almost daily occurrence on Facebook over recent months. Typically they use the lure of an application that a potential victim's friend has been tricked into installing, such as a 'Dislike' button or a link to shocking (invariably bogus) news about a celebrity.
Instead of getting the promised content, victims are invited to navigate their way through a thicket of time-wasting surveys. Scammers earn a kick-back for each victim as affiliates of unethical marketing firms.
More ambitious (and lucrative) scams attempt to trick victims into supplying their mobile number, before signing up to a premium rate text messaging service of questionable utility.
The scams take advantage of human stupidity rather than web security vulnerabilities. Both Sophos and Facebook agree that user education is part of the solution, but the two are split on whether Facebook itself could do more to tighten up its controls on how applications are released onto its platform.
In a statement responding to Sophos' report, Facebook said it has plenty of controls already that limit access to information.
We have built extensive controls into the product, so that now when you add an application it only gets access to very limited data and the user must approve each additional type of data (so we do more than anyone else to educate users about passage of data, and force disclosure and user consent for each category beyond the basics).
We have a dedicated team that does robust review of all third party applications, using a risk based approach. So, that means that we first look at velocity/number of users/types of data shared, and prioritise. This ensures that the team is focused on addressing the biggest risks, rather than just doing a cursory review at the time that an app is first launched.
We make sure that we act swiftly to remove/sanction potentially bad applications before they gain access to data, and involve law enforcement and file civil actions if there is a problem.
Down with this sort of thing
Facebook said it is constantly improving the level of account protection offered to users, citing its introduction of one-time passwords back in October 2010, a development designed to make it safer for users to use public computers to access the service.
The social network goes on to list its user education programmes, which are geared to improving the security awareness levels of users.
These initiatives include updating the 3.6 million people who have liked the Facebook Security Page, hundreds of thousands of which have taken our "Stop. Think. Connect." quiz on the Page, which we developed with National Cyber Security Alliance and the Anti-Phishing Working Group; as well as the education we do through the product, for example, when we detect that an account is compromised by phishing or malware, we put the owner through a remediation/education process that includes a free McAfee virus scan.
When a person clicks on a link that we can't verify, or that we think might be suspicious, we pop an interstitial warning.
We put these points to Sophos, which said it stood by the main findings of its original report, and argued that the social network could and should do more to improve the security of its users.
"I definitely feel that Facebook could be doing more to both better secure their users, and to ensure that privacy is treated as a higher priority," Graham Cluley, senior technology consultant at Sophos, told El Reg.
Facebook may talk a good game but a quick search (viewable only if logged into Facebook and safe providing you don't click on the links) shows hundreds of victims have installed a rogue app that falsely promises the ability to "see who has viewed your profile".
Facebook ought to have someone searching for such scams and stamping them out, something that isn't happening as yet. "Often I see these scams spreading for days on end, with no obvious action taken by Facebook," Cluley said.
Careful now
According to Sophos, the social network could employ a round-the-clock security response team. Some have suggested Apple-style pre-approval of apps would drastically reduce, if not eliminate, the volume of crud circulating on Facebook. However, Cluley said such an approach was hard to apply to Facebook's platform.
"Pre-approval of apps is tricky, because they are web-based and contain content that is not hosted on Facebook's own servers," Cluley explained. "In other words, the bad guys could change it any time - turning a good app into a rogue one."
What might work better is some form of white-listing or restricting the ability to access sensitive data to already trusted developers, Cluley explained.
"Each app could be submitted for profiling to Facebook, who would create a matrix of what data it requested to access from the user, and which webpages it uses content from. If these changed at any point then the app would no longer be approved, and be sent back to Facebook's sinbin team for checking.
"Better than that would be for Facebook to only allow apps that came from approved developers to access sensitive information or post to users' walls."
Cluley said Facebook introduced an optional app verification program in November 2008, only to quietly kill it off a year later.
Facebook ought to consider reviving the program, said Cluley. "If developers had to pay to become official developers for the Facebook platform, and if not being an official developer meant you weren't able to hit Facebook users, then we'd see an instant dramatic drop in the attacks."
Sophos suggested that Facebook ought to be more proactive in using its security page as an early warning system on scams, as part of a broader program targeted at curtailing rogue apps and other security threats.
"There's a sliding scale of things that Facebook could do to counter the problem of rogue apps - ranging from faster response to stricter conditions about who and who can't write Facebook applications," Cluley concluded. "What's clear is that their current approach isn't working." ®
MY THOUGHTS
we have a choice, as always. if we're so heated up about our security and privacy there are, at least, 2 things we can do. one is to stop using facebook altogether.or be a responsible user.
Shy social network responds to criticism
By John Leyden • Get more from this author
Posted in Malware, 21st January 2011 16:01 GMT
Analysis Facebook has defended its record in thwarting rogue applications and other security in the face of criticism from security firms that it ought to adopt tighter application controls.
The dominant social network disputes findings from a threat report by UK-based net security firm Sophos, released earlier this week, that spam, malware and other attacks have become more effective against Facebook users over the last year.
Facebook reckons the opposite is true while disputing the methodology adopted by Sophos which it said looked, for example, at the volume of spam sent to Facebook users instead of the volume that reached their in-boxes.
Facebook said: "If your spam filter catches all the spam, does it matter that your filter caught 10 per cent more?"
The social networking site reckons less than three per cent of communications on Facebook are spam, compared to industry estimates that email spam makes up 90 per cent of all electronic messages. The implication is that Sophos is focusing on the wrong problem.
Unfriending rogues
Survey scams have become an almost daily occurrence on Facebook over recent months. Typically they use the lure of an application that a potential victim's friend has been tricked into installing, such as a 'Dislike' button or a link to shocking (invariably bogus) news about a celebrity.
Instead of getting the promised content, victims are invited to navigate their way through a thicket of time-wasting surveys. Scammers earn a kick-back for each victim as affiliates of unethical marketing firms.
More ambitious (and lucrative) scams attempt to trick victims into supplying their mobile number, before signing up to a premium rate text messaging service of questionable utility.
The scams take advantage of human stupidity rather than web security vulnerabilities. Both Sophos and Facebook agree that user education is part of the solution, but the two are split on whether Facebook itself could do more to tighten up its controls on how applications are released onto its platform.
In a statement responding to Sophos' report, Facebook said it has plenty of controls already that limit access to information.
We have built extensive controls into the product, so that now when you add an application it only gets access to very limited data and the user must approve each additional type of data (so we do more than anyone else to educate users about passage of data, and force disclosure and user consent for each category beyond the basics).
We have a dedicated team that does robust review of all third party applications, using a risk based approach. So, that means that we first look at velocity/number of users/types of data shared, and prioritise. This ensures that the team is focused on addressing the biggest risks, rather than just doing a cursory review at the time that an app is first launched.
We make sure that we act swiftly to remove/sanction potentially bad applications before they gain access to data, and involve law enforcement and file civil actions if there is a problem.
Down with this sort of thing
Facebook said it is constantly improving the level of account protection offered to users, citing its introduction of one-time passwords back in October 2010, a development designed to make it safer for users to use public computers to access the service.
The social network goes on to list its user education programmes, which are geared to improving the security awareness levels of users.
These initiatives include updating the 3.6 million people who have liked the Facebook Security Page, hundreds of thousands of which have taken our "Stop. Think. Connect." quiz on the Page, which we developed with National Cyber Security Alliance and the Anti-Phishing Working Group; as well as the education we do through the product, for example, when we detect that an account is compromised by phishing or malware, we put the owner through a remediation/education process that includes a free McAfee virus scan.
When a person clicks on a link that we can't verify, or that we think might be suspicious, we pop an interstitial warning.
We put these points to Sophos, which said it stood by the main findings of its original report, and argued that the social network could and should do more to improve the security of its users.
"I definitely feel that Facebook could be doing more to both better secure their users, and to ensure that privacy is treated as a higher priority," Graham Cluley, senior technology consultant at Sophos, told El Reg.
Facebook may talk a good game but a quick search (viewable only if logged into Facebook and safe providing you don't click on the links) shows hundreds of victims have installed a rogue app that falsely promises the ability to "see who has viewed your profile".
Facebook ought to have someone searching for such scams and stamping them out, something that isn't happening as yet. "Often I see these scams spreading for days on end, with no obvious action taken by Facebook," Cluley said.
Careful now
According to Sophos, the social network could employ a round-the-clock security response team. Some have suggested Apple-style pre-approval of apps would drastically reduce, if not eliminate, the volume of crud circulating on Facebook. However, Cluley said such an approach was hard to apply to Facebook's platform.
"Pre-approval of apps is tricky, because they are web-based and contain content that is not hosted on Facebook's own servers," Cluley explained. "In other words, the bad guys could change it any time - turning a good app into a rogue one."
What might work better is some form of white-listing or restricting the ability to access sensitive data to already trusted developers, Cluley explained.
"Each app could be submitted for profiling to Facebook, who would create a matrix of what data it requested to access from the user, and which webpages it uses content from. If these changed at any point then the app would no longer be approved, and be sent back to Facebook's sinbin team for checking.
"Better than that would be for Facebook to only allow apps that came from approved developers to access sensitive information or post to users' walls."
Cluley said Facebook introduced an optional app verification program in November 2008, only to quietly kill it off a year later.
Facebook ought to consider reviving the program, said Cluley. "If developers had to pay to become official developers for the Facebook platform, and if not being an official developer meant you weren't able to hit Facebook users, then we'd see an instant dramatic drop in the attacks."
Sophos suggested that Facebook ought to be more proactive in using its security page as an early warning system on scams, as part of a broader program targeted at curtailing rogue apps and other security threats.
"There's a sliding scale of things that Facebook could do to counter the problem of rogue apps - ranging from faster response to stricter conditions about who and who can't write Facebook applications," Cluley concluded. "What's clear is that their current approach isn't working." ®
MY THOUGHTS
we have a choice, as always. if we're so heated up about our security and privacy there are, at least, 2 things we can do. one is to stop using facebook altogether.or be a responsible user.
Subscribe to:
Posts (Atom)