Google Search

Showing posts with label Facebook. Show all posts
Showing posts with label Facebook. Show all posts

Thursday, December 25, 2014

Google and Facebook under fire from Dutch government over citizens' privacy

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Image of Dutch citizen thumbs up courtesy of ShutterstockThe Dutch government is clamping down on the way in which large organisations use its citizen's personal data.

The Dutch Data Protection Authority (DPA) threatened Google with a fine of €15m (£11.9m, $18.7m) on Monday, saying the search giant had breached various provisions of the Dutch data protection act via a privacy policy it introduced in 2012.

The company has been given until the end of February 2015 to change how it handles personal data, especially in regard to the tailoring of adverts based on keyword search queries, video viewing habits, location data and the content of email messages.

Jacob Kohnstamm, chairman of the Dutch DPA, said:

Google catches us in an invisible web of our personal data without telling us and without asking us for our consent. This has been ongoing since 2012 and we hope our patience will no longer be tested.

Kohnstamm explained how, under Dutch law, Google should have informed users that it was gathering data across a number of platforms - such as YouTube and Gmail - and obtained permission before combining or analysing that data.

The regulator has now demanded that Google obtains "unambiguous" consent from users before combining their data, "via a separate consent screen", rather than through its more generalised privacy policy.

It also ordered the company to add clarification to the policy so that users are better informed as to how each of the company's services is using their data.

Furthermore, Google is required to make it clear that YouTube is part of its setup, though the DPA did note that this already appeared to be underway.

Five other regulators - in France, Germany, Italy, Spain and the UK - have recently received a letter from Google detailing how it intends to comply with European privacy laws but the Dutch DPA says it has yet to establish whether the proposals will suffice within its own jurisdiction.

While the DPA's gripe with Google awaits resolution, it has now moved onto fellow data gatherer Facebook.

In another statement (in Dutch - view Google translate version) released on Tuesday it announced it would investigate Facebook's new privacy policy.

The social network announced last month that it intends to make changes to its policy, effective from 1 January 2015.

As Facebook has a physical presence in the Netherlands, the DPA says it is authorised "to act as supervisor", as per a European Court of Justice ruling on Google vs. Spain on 13 May 2014 (the 'right to be forgotten' case).

As such, it has asked Facebook to hold fire on its new privacy policy until it has had the chance to investigate how the changes may impact Dutch users, including how Facebook obtains permission for the use of their personal data.

The latest iteration of the policy states that Facebook can use:

your name, profile picture, content, and information in connection with commercial, sponsored, or related content (such as a brand you like) served or enhanced by us. This means, for example, that you permit a business or other entity to pay us to display your name and/or profile picture with your content or information, without any compensation to you. If you have selected a specific audience for your content or information, we will respect your choice when we use it.

Given how the key points of the policy have not changed since it was last revised in November 2013, it seems unlikely Facebook will comply with the DPA's wishes.

According to The Telegraph, the company responded by highlighting how it is "a company with international headquarters in Dublin", which routinely reviews its policies and procedures with its own regulator, the Irish Data Protection Commissioner.

Facebook said it is confident that its new privacy policy is compliant with all relevant laws.

Follow @Security_FAQs

Follow @NakedSecurity

Image of Dutch citizen courtesy of Shutterstock.


View the original article here

Tuesday, June 17, 2014

Facebook stupidity leads to largest gang bust in NYC history

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Image of Facebook style gun courtesy of ShutterstockKids can be street-smart and Facebook-stupid, to paraphrase how Vice News put it.

Police love that naive, completely misplaced trust in the supposed anonymity of social media postings.

In fact, it was a long trail of quite helpful Facebook postings about crimes that lead New York City police to what authorities are calling "the largest gang takedown in New York City's history".

After a 4-year-long investigation by the New York Police Department (NYPD), 103 gang members were indicted on Wednesday, thanks mostly to the evidence teenagers left on their Facebook profiles.

Five hundred NYPD officers descended on two housing projects in the NYC neighborhood of West Harlem Wednesday morning to arrest 40 of those who were indicted.

Police told reporters that 23 more alleged gang members are still being sought, while the rest were apprehended prior to the Wednesday bust.

Most of those arrested are between 15 and 20 years old, while some were as old as 30.

Prosecutors say the boys and men belong to three gangs: the two allied gangs of Make It Happen Boys and Money Avenue, and their rivals, 3 Staccs.

The gangs have waged war over the past four years, with the carnage now resulting in accusations of two homicides, 19 non-fatal shootings and about 50 other shooting incidents, according to a press release put out by Manhattan District Attorney Cyrus R. Vance, Jr.

According to the indictments (which can be read here and here), the gang members fought tooth and nail to control their territory - the two housing projects are only a block away from each other - and to climb the gangster hierarchy via shootings, stabbings, slashings, assaults, gang assaults, robberies, revenge shootings, and murders.

They were also busy chronicling it all via social media, posting hundreds of Facebook updates, direct messages, mobile phone videos, and calls made from Rikers Correctional Facility to plot the deaths of rival gang members.

They used postings to publicise and claim credit for - and to rub their enemies' noses in - their crimes, prosecutors say.

One of the gangs's victims - 18 year-old Tayshana "Chicken" Murphy - was a promising basketball star. Her father has said that she was being recruited by several colleges.

Ms. Murphy was gunned down in her building in September 2011. One of the gang members allegedly bragged about it on Facebook.

A second victim, Walter "Recc" Sumter, who owned the gun used to kill Ms. Murphy, was murdered that December in apparent retaliation.

Prosecutors say that two days after the death of Ms. Murphy, alleged gang member Davon "Hef" Golbourne wrote to a 3Staccs rival that they had "fried the chicken."

The rival, Brian "Pumpa" Rivera, replied "NOW IMAAA KILL YUHH."

In fact, investigators pored over more than 40,000 phone calls between gang members already in jail and those on the outside, hundreds of hours of surveillance video, and "more than a million social media pages," Vance said in his statement.

According to Vice News, the word "Facebook" shows up 162 times in one of the indictments and 171 in the second.

Rev. Vernon Williams, a Harlem pastor who has spent years trying to curb youth violence in the neighborhood and who personally knows many of the indicted teens, told Vice News that they're not the brightest bulbs on the tree when it comes to social media:

They are Facebook dummies.

Because the stuff that they were saying, that was gonna come back to bite them, especially admitting participating in crimes, admitting getting the weapons that were gonna be used in crimes, and then calling someone in a state prison and giving them a report of what they did.

But while the kids were undeniably stupid about Facebook, Williams also criticised the law for letting this battle wage for so long instead of stepping in earlier:

The indictment is almost 200 pages long and I would say 75-80 percent of [one of the indictments] is Facebook posts and similar activity.

The DAs office was helped by the accused. All [the police] did was watch and document it. I don’t know what took them so long, but once they had enough, they scooped them up.

That is a very good question. Why did police need four years to round these guys up when they had alleged criminals posting about it on social media?

Stupidity about social media is a gift to investigators. One would hope that the gift gets turned into protection for the community as fast as practicable.

Follow @LisaVaas

Follow @NakedSecurity

Image of Facebook gun courtesy of Shutterstock.


View the original article here

Friday, December 27, 2013

'Hack Facebook' works great - on YOU, not your intended victim

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Facebook. Image courtesy of ShutterstockWant to hack a friend's Facebook account?

That's exactly what the "Hacking Facebook" site* promises it can do for you.

Actually, though, it turns out that it's not so much that the site can hack for you, but it most certainly can do it to you.

Security researcher Joshua Long writes that he tracked down the site after getting spam flaunting its Facebook hacking services.

What it's really up to, he writes, is a spendy little scam that offers to let you watch a Real! Live! Facebook! Hack! ... which, if you want to continue with this supposed "hack," requires that you send two SMS text messages to a number for codes:

"In short, the site tricks wannabe hackers into sending texts to a premium SMS number (81073), which leads to charges on their next phone bill.

"The site may also collect login details that could later be used to try to hack into the would-be hacker's various online accounts (Facebook or otherwise), and of course once the spammers have your phone number they might also send you text message spam (or sell your number to other spammers)."

Long offers this rough translation of the promises made by Hack Facebook:

Our site offers recovery services for the social network Facebook, our tool ensures you to hack a facebook account without software assistance.

Hack-face uses the most advanced exploits as well as 5 methods of decryption, so it is possible in a few minutes to get the password for the targeted account. Instantly receive email logins on your choice so that you can get access.

SMS scam. Image courtesy of ShutterstockThe site mixes wording associated with legitimate security services with that of malicious hacking, Long notes, as it first offers "recovery services" for regaining account access (sounds benign, eh? Don't count on it, he says), then jumps to the promise of hacking an account "without software assistance" and using "the most advanced exploits" on top of "5 methods of decryption" to get a target's password.

Long says there's also a portion of the site that offers a "Facebook Penetration Testing Tool" that uses "new technologies such as the cloud and exploit kits" to "effortlessly" hack Facebook.

What a mess of duplicitous verbiage, Long muses:

"The term 'penetration testing' implies that the tool attempts to find security weaknesses in a system with permission from the owners or operators of that system.

"I think it's fairly obvious that Facebook does not want everyone in the world to be able to hack into everyone else's account."

Definitely read Long's full post for his hypothesis on how the site might be rigged to get your login details, on top of the premium text-messaging scam it's pulling.

Naked Security offers some tips on dealing with mobile SMS/text spam here and Long provides a list of instructions for how to opt out of receiving premium text messages or disputing charges for most US providers.

*No, sorry, I'm not including a link to this site. I love you too much to expose you to such peril. Besides, Long fuzzed out the URL.

Follow @LisaVaas

Follow @NakedSecurity

Image of Facebook page and SMS scam courtesy of Shutterstock.


View the original article here

Saturday, December 21, 2013

Facebook users worldwide (minus some mobile phones) now getting secure web browsing by default

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Facebook initially introduced full-time HTTPS (secure HTTP) as an option in January 2011.

Before that, the site protected your password during login using HTTPS, but left the rest of your session unencrypted.

The change came about because, back in October 2010, a Firefox plugin called Firesheep was released as a proof of concept that sniffing an unencrypted session after login was all an attacker needed to hijack your account.

This made Facebook's new option welcome, but being opt-in meant it really didn't go far enough.

So, in an open letter in April 2011, Naked Security asked Facebook to improve privacy and safety by turning on HTTPS for everything.

In November 2012, Facebook finally did move to make secure browsing a default, at least for users in North America.

And on Wednesday, Facebook announced that it is now using HTTPS by default for all users, so the rest of the world has finally caught up. (Well, almost. Some mobile phones and carriers don't fully support HTTPS.)

Why did it take so long?

Because it involved a lot of moving parts, explains Facebook software engineer Scott Renfro.

Namely, it involved getting third-party application developers to upgrade, getting web-browser cookies to be compliant, controlling referrer headers, and migrating users to HTTPS without disrupting "in-flight" sessions, i.e. upgrading people while they're actually using the site.

Performance has also been a huge challenge, Renfro says, given the extra hoops browsers have to jump through with HTTPS:

In addition to the network round trips necessary for your browser to talk to Facebook servers, https adds additional round trips for the handshake to set up the connection. A full handshake requires two additional round trips, while an abbreviated handshake requires just one additional round trip. An abbreviated handshake can only follow a successful full handshake.

Here's an example from Renfro of how that extra latency can make users with already-slow connections suffer yet more, and how Facebook has eased the pain:

If you're in Vancouver, where a round trip to Facebook's Prineville, Oregon, data center takes 20ms, then the full handshake only adds about 40ms, which probably isn't noticeable. However, if you're in Jakarta, where a round trip takes 300ms, a full handshake can add 600ms. When combined with an already slow connection, this additional latency on every request could be very noticeable and frustrating. Thankfully, we've been able to avoid this extra latency in most cases by upgrading our infrastructure and using abbreviated handshakes.

Facebook's work on secure browsing is most certainly not done, mind you: the company says it's still working with mobile phone vendors to make it happen there.

Renfro calls HTTPS by default a "dream come true" — a goal that the company's network, security, traffic, and security infrastructure teams have been working on for years.

When Facebook first rolled out HTTPS by default, Naked Security was stuck with a heap of "Dislike" t-shirts that didn't seem appropriate anymore, so the team gave them away to readers.

Sorry, I don't know of any plans to print up "Like" t-shirts over the news that HTTPS by default is finally, for the most part, a dream come true.

But, Facebook engineers, here are two big, virtual thumbs-up for the work you've done. Let's hope it works out well for the mobile outliers, as well.

Follow @LisaVaas

Follow @NakedSecurity


View the original article here

Monday, December 9, 2013

Who likes porn sites better than Facebook or Twitter?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Adults only. Image courtesy of Shutterstock.Read into this whatever cultural generalizations you will: recent numbers show that citizens of Germany, Spain, the UK, and the US have higher appetites for porn than anybody on the planet.

The Guardian recently got an exclusive peek at metrics from SimilarWeb, a web measurement company based in Tel Aviv that tracks clicks online (rather than total traffic volume).

The numbers show that in the UK, for one, traffic to legal porn sites outpaces even that for social media sites, such as Facebook. In fact, porn makes up 8.5% of all UK traffic.

Steamy sites also get more UK traffic than those for shopping, news, email, finance, gaming, travel, and business/industry.

The UK isn't the top porn-loving place, though. That honor goes to Germany, where a whopping 12.5% of traffic heads to the X-rated.

The top porn-surfing countries and how much of their traffic went to the internet's gazillion shades of grey during June 2013:

Germany 12.5%Spain 9.6%UK 8.5%US 8.3%Worldwide average 7.7%Ireland 7.5%France 7.3%Australia 7.0%

The only destinations more popular than porn in the UK were arts and entertainment (boosted, as it is, by YouTube traffic) at 9.5% and search engines at 15.7%.

The figures don't include traffic from mobile phones which might have told a different story.

Nor do they account for illegal searches for child abuse, which, as The Guardian notes, are typically hidden away in identity-masking networks such as Tor or peer-to-peer.

Daniel Buchuk, head of brand and strategy at SimilarWeb, told The Guardian that the world's preference for porn over chatting with our friends on social media sites - as in, not just a preference for porn over one social media site, but a preference for porn over all social media sites combined - is a tad remarkable:

"Traffic on adult sites represents a huge portion of what people use the internet for, not just in the UK but around the world ... It is astonishing to see that adult sites are more popular in the UK than all social networks combined."

Mind you, people aren't just fumbling their way into porn sites by mistyping, for example, Facebook as F**kbook, he says:

"People don't just 'stumble' upon adult content. More than 8% of Google UK searches led to adult sites in the past three months."

Of course, one doesn't want to pick on the UK, particularly given that its surfing predilections aren't the most sexy, by far.

Germany's about half as much more prone to porn surfing, for example.

But thanks to David Cameron, the UK lately has itself been introspective on the topic.

Computer porn. Image courtesy of Shutterstock.Last week, the Prime Minister gave a speech in which he announced new measures to protect children and challenged the internet's tech giants to shape up and do their part.

Upcoming changes to UK law include the criminalisation of possessing online pornography depicting rape and subjecting online videos to the same rules that pertain to those sold in licensed sex shops.

Beyond that, the more contentious changes include pervasive network-level filtering of adult content as a default position for internet access throughout the UK.

Is all this fuss warranted?

Well, kind of. Porn sites are, in fact, notoriously riskier than those serving vanilla content.

When the US Pentagon last August chewed out its missile defense workers for surfing porn on the job, a spokesman noted that the sites in question were known to have had virus and malware issues.

A government cybersecurity specialist also confirmed to Bloomberg at the time that many porn sites are infected.

Criminals and foreign intelligence services plant malware on such sites in order to gain access to and harvest data from government and corporate computer networks, the specialist explained.

So yes, porn sites carry a high risk of being boobytrapped (no pun intended).

But then again, so too do religious sites.

Nowadays, you’re reportedly more likely to get infected by visiting a church website than you are when you surf porn.

When it comes to minimizing malware infection, one could argue not only for the separation of church and state, as laid out by the founders of the US, but also for the further separation of church, state, business hours and booty.

Follow @LisaVaas

Follow @NakedSecurity

Images of computer porn and adults only courtesy of Shutterstock.


View the original article here

Thursday, November 28, 2013

Facebook, the early years: handing out a master password like candy

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Mark Zuckerberg. Image courtesy of Kobby Dagan / Shutterstock.You are not paranoid about surveillance - at least, not as far as Facebook is concerned.

It appears that Facebook founder Mark Zuckerberg and his minions, in the early days, had a master password with which they could sign in to any user account and poke at whatever data we entrusted to the site.

The Guardian gleaned this from Zuckerberg's former speechwriter, Katherine Losse.

Losse told the media outlet that users should be guarded with their private data on the site - a timely warning, given the launch of Facebook's social search tool graph search.

Losse - aka Facebook employee No. 51 - joined the company in 2005 as a customer support staffer and worked her way up to being Zuckerberg's ghostwriter. She left in 2010 and, according to the Guardian, is now regarded as a rogue former employee by Facebook itself.

In 2012, she released a book, The Boy Kings, about those early years.

Recent revelations about the US National Security Agency's (NSA's) voraciously hungry appetite for surveillance may have left many users of social networking sites fretting about the government sucking up our private data, but Facebook has been privy to that data - including our passwords - from its infancy, Losse told the Guardian.

As The Guardian's Siraj Datoo points out, that's a little scary, given that plenty of users likely have never changed their passwords since they first signed up.

To make matters worse, many people commit security blasphemy by using the same password on multiple sites.

To make matters spontaneously combust in worse-osity, Losse wrote in "The Boy Kings" that in its early years, Facebook passed out the master password like candy, without vetting any of the support staffers.

Here's an excerpt from the book, courtesy of coverage from CNet's Jennifer Van Grove:

"Jake introduced us to the hanky application through which users' e-mails to Facebook flowed. Once we learned how the software worked, Jake taught us, without batting an eyelid, the master password by which we could log in as any Facebook user and access all their messages and data... I experienced a brief moment of stunned disbelief: They just hand over the password with no background check to make sure I am not a crazed stalker?"

As Losse told The Guardian, social networking users tend to assume they're the only ones who can access the information they input, but at most companies, it's probably not true, given that "at least some of the staff need to have access to user accounts in order to do their jobs."

She said:

"There has to be a way for the staff to manage and repair user account issues, and for this reason user data within most startups, especially when they are young, is never completely locked up from company staff."

At any rate, Facebook doesn't hand out a master password anymore, it says.

Nowadays, the company told CNet, employees don't have password access:

"An audit by the Irish Data Protection Commission included a detailed review of the level of access to user data that employees have at Facebook and found that we have an appropriate framework in place. Facebook employees do not have access to users' passwords."

It is, of course, preferable that we have as clear a picture as possible of what companies do with our personal data, so this history of early data yahooism is welcome.

Facebook silhouette. Image courtesy of Shutterstock.If it helps Losse to sell more books by tying it in to concern about PRISM-like surveillance, that's OK, as far as I'm concerned.

The more light we shed on these formerly murky matters, the better.

Facebook from its start could watch us, listen to us, and, probably, make fun of us and our soppy, trivial and/or really embarrassing posts and data.

Now it can't, it assures us.

If that helps to ease your compulsive surveillance suspicions, paralyzing fear of electronic privacy violation, or even, to borrow the Joy of Tech's formal diagnosis, PRISM Anxiety Disorder, all the better.

Thank you, Ms. Losse, for letting us know.

Follow @LisaVaas

Follow @NakedSecurity

Images of Facebook silhouette and Mark Zuckerberg courtesy of Kobby Dagan / Shutterstock.com.


View the original article here

Wednesday, November 20, 2013

Facebook leak, Canadian spam, Opera breach - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

It's Saturday, and that means 60 Second Security, where we aim to touch on some of the more thought-provoking security topics of the past week in just one minute of video.

Why not give this week's video a go? [Higher resolution available directly from YouTube. Click the Captions icon for closed captions.]

Facebook suffers a data leakage crisis where information uploaded by X about Y may be downloadable by Z.Canada is the last G8 country to go for anti-spam legislation. Only it just got delayed again. Might be ready by 2014. Or 2017.A Korean graphical designer created an "anti-surveillance" font. It doesn't work, but, hey, it's the thought that counts.And Opera wrote up a "Security attack stopped" incident. Except it was more like "Security attack not stopped."

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, anti-spam, anti-surveillance, breach, browser, Canada, certificate, Code signing, data breach, Facebook, font, korean, leak, legislation, Malware, opera, PRISM, Spam, typeface, typography, zxx


View the original article here

Tuesday, November 19, 2013

Facebook leaks are a lot leakier than Facebook is letting on

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Remember last week, when Naked Security et al. told you that Facebook leaked email addresses and phone numbers for 6 million users, but that it was really kind of a modest leak, given that it's a billion-user service?

OK, scratch the "modest" part.

The researchers who originally found out that Facebook is actually creating secret dossiers for users are now saying the numbers don't quite match up.

The number of affected users Facebook noted in a posting on its security blog is far less than what they themselves found, and Facebook is also "hoarding non-user contact information - seen when it was also shared and exposed in the leak," writes ZDNet's Violet Blue.

The bug involved the exposure of contact details when using the Download Your Information (DYI) tool to access data history records, which resulted in access to an address book with contacts users hadn't provided to Facebook.

Selecting privacy settings in FacebookWhat that means is that even if you don't share details of your own personal information with Facebook, Facebook well may have gotten it through other people in your network who've let Facebook have access to their contact lists.

Facebook accidentally combined these "shadow" profiles with users' own Facebook profiles and then blurted both data sets out to people who used the DYI tool and who had some connection to the people whose data was breached.

It's understandable why Facebook users are steamed.

Facebook has gotten information you didn't choose to share, has retained it, and has inadvertently left it open for unauthorized access since at least 2012.

Some users, in fact, complained in comments that the bug persisted even after Facebook reportedly fixed it, according to Violet Blue.

Packet storm reported on Wednesday that its researchers, who had prior test data verifying the leak, were able to compare what they knew was being leaked with what Facebook reported to its users.

Packet Storm claims that Facebook didn't come clean about all the data involved.

From its posting:

"We compared Facebook email notification data to our test case data. In one case, they stated 1 additional email address was disclosed, though 4 pieces of data were actually disclosed. For another individual, they only told him about 3 out of 7 pieces of data disclosed. It would seem clear that they did not enumerate through the datasets to get an accurate total of the disclosure...

"Facebook claimed that information went unreported because they could not confirm it belonged to a given user. Facebook used its own discretion when notifying users of what data was disclosed, but there was apparently no discretion used by the 'bug' when it compiled your data. It does not appear that they will take any extra steps at this point to explain the real magnitude of the exposure and we suspect the numbers are much higher."

Not only is the extent of exposed data likely to expand, Packet Storm says, but the number of people affected is much higher than 6 million, given that Facebook has only contacted its users.

Here's how Facebook replied when Packet Storm asked about contacting non-users about the breach:

"We asked Facebook if they enumerated the information in hopes that their reporting had a bug but we were told that they only notified users if the leaked information mapped to their name.

"We asked Facebook what this means for non-Facebook-users who had their information also disclosed. The answer was simple - they were not contacted and the information was not reported. Facebook felt that if they attempted to contact non-users, it would lead to more information disclosure."

That's a "weak, circular" argument, Packet Storm complains.

To better protect users' contact and personal information, the researchers suggest that Facebook can simply adopt this suggested flow:

1. When a person uploads someone's contact information, Facebook should automatically correlate it to what they have shared on their profile (and obviously only suggest them as a friend if their settings allow it). If their settings do not allow it, they should treat it as a user not in Facebook (see #2). If the information uploaded includes data specific to an individual who does not already have that data included in their profile, Facebook should provide a notification along the lines of:

"You are attempting to add data about John Smith that he has not shared with Facebook. How do you want to handle this situation?"

Two options are provided:

A) "Ask John Smith's permission to add this information"

B) "Discard additional information"

If they choose option A, John Smith is notified by Facebook the next time he logs in and gets to decide what he wants to do with HIS data. Seems simple enough.

2. When a person uploads someone's contact information and it does not correlate to any Facebook user, they should be able to use it for the Invitation feature with the caveat that Facebook automatically deletes all data within 1 week. The invite to the person can say "this link will expire in 1 week", which it should anyways. When an individual uses the invitation link to sign up, THEY will decide what information to share with Facebook.

That does seem simple enough, but Facebook hadn't responded to the suggestion at the time of writing.

While we wait for Facebook to (maybe) fix a situation that seems far more widespread than originally reported, we can help each other out by immediately removing our imported contacts, to keep everybody's personal data out of this swamp.

If you haven't done so already, you can easily remove uploaded contacts here.

Follow @LisaVaas

Follow @NakedSecurity


View the original article here

Saturday, November 16, 2013

Facebook pays $20K for easily exploitable flaw that could have led to account hijackings

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Like money, image courtesy of ShutterstockFacebook has paid out $20,000 for a serious bug that could have allowed an attacker to hijack anyone's account with ease, with no user interaction on the part of the victim.

Jack Whitten, the UK-based application-security engineer (by day) and security researcher (by night) who discovered the flaw, said in a post mortem on Wednesday that he reported the hole to Facebook on 23 May and that it was fixed by 28 May.

The exploit was enabled by manipulating the way that Facebook handles updates to mobile phones via SMS.

As it is, Whitten explains, Facebook gives users the option of linking their mobile numbers with their accounts.

Users then can receive updates via SMS and can also login using their phone number rather than their email address.

Whitten found that when sending the letter F to Facebook's SMS shortcode - which is 32665 in the UK - Facebook returned an 8-character verification code.

After submitting the code into the activation box and fiddling with the profile_id form element, Facebook sent Whitten back a _user value that was different from the profile_id that Whitten modified.

Whitten says that trying the exploit might have led to having to reauthorize after submitting the request, but he could do that with his own password instead of trying to guess at his target's password.

After that point, Facebook was sending an SMS confirmation. From there, Whitten said, an intruder could initiate a password reset request on his targeted user's account and get the code back, again via SMS.

After a reset code is sent via SMS, the account is hijacked, Whitten wrote:

We enter this code into the form, choose a new password, and we're done. The account is ours.

Bandage on thumb, image courtesy of ShutterstockFacebook closed the security hole by no longer accepting the profile_id parameter from users.

This could have been a valuable flaw were it to fall into the hands of attackers who might have used it to steal personal data or send out spam.

As it is, one commenter on Whitten's post who obviously didn't understand the "it's now fixed" part of the story made the bug's value clear with his or her eagerness to figure out how to exploit it:

›khalil0777 • a day ago

someone explain me how to exploit it i am realyy need it i wait your helps friends :/

:/ oh well, ›khalil0777, looks like you're too late for that party.

I'd say better luck next time, but perhaps instead I'll save my good wishes for Mr. Whitten.

May he enjoy his $20,000.

It was well-earned, and it's a bargain for Facebook even were the reward to be doubled, considering the grief that could have been caused by such an easy exploit.

Follow @LisaVaas
Follow @NakedSecurity

Images of money and thumbs up courtesy of Shutterstock.


View the original article here

Sunday, November 10, 2013

Facebook issues data breach notification - may have leaked your email and phone number

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Facebook just published a data breach notification on its security blog.

You might not immediately notice that from the title of the article, which announces itself as an "Important Message from Facebook's White Hat Program."

But the social networking giant is, indeed, reporting a data leakage problem.

The silver lining is that the quantity of data wrongly disclosed due to Facebook's bug seems to be modest, at least by the standards of a billion-user service.

The cloud (bad pun intended) is that Facebook's systems made the fault possible in the first place.

Facebook, understandably, isn't giving the gory details of the bug and how it could have been exploited, which makes the big picture hard to see.

What it is saying, is this:

We recently received a report to our White Hat program regarding a bug that may have allowed some of a person’s contact information (email or phone number) to be accessed by people who either had some contact information about that person or some connection to them.

So let me tell you what I think the story is all about.

Bear with me, please: I'm going to take a while to set the stage first.

Imagine that Charlie Smith - one of thousands of people with that name - is on Facebook.

He's chosen to tell Facebook his email address, chazza@example.org, but not much more. He hasn't shared where he lives, the name of his employer or his phone number.

Alice joins up and decides to let Facebook at her contact lists. (Facebook squeezes you pretty hard to try to persuade you to upload as much as possible about your web of friends, for reasons that will become obvious in a moment.)

She knows a Charlie Smith; her Charles has a phone number of +1.500.555.5000, and an email address of chazza@example.org.

Facebook can now cross-match the email address and suggest that she might want to try to hook up with Charlie.

Chances are, of all the C. Smiths on Facebook, this is the one she knows.

She sends a Friend Request; it was the right Charlie, and he accepts it.

So far, so good.

Later, Bob comes along.

His contact list, which he yields up to the Facebook empire, identifies a chazza@example.org, known as Charlie Smith, currently living in Someplace, Pennsylvania, and working for the Acme Pointed Stick company.

Facebook likewise puts Bob in touch with Charlie, and thus indirectly with Alice, and the three of them end up as Facebook friends.

Alice is happy; Bob is happy; and, since he agreed to the Friend Requests, we assume Charlie is happy too.

Easy as A-B-C.

Of course, Facebook is the happiest of all, because it now knows (or can make a staggeringly likely guess at) a bunch of personal information about Charlie that he himself chose not to reveal.

Of course, as more people share more information about their contacts, and implicitly confirm the identity of those contacts through the Facebook friendships they forge, Facebook builds up an ever more detailed picture of everyone.

Welcome to the wonderful world of data mining.

You don't have to like this sort of thing, but there's not a lot you can do about it.

Even staying away from sites like Facebook, or "resigning" from them if you're already on, might not help very much.

After all, in our hypothetical example above, Charlie Smith only gave his name and email address; his address, employer and phone number were provided by other people, presumably with their informed consent.

? Alice and Bob may not have thought through the consequences of letting Facebook at their contact lists, but it was their their choice to populate their contact databases with the sort of detail they did, and their choice to let Facebook at that data.

What Facebook seems to be admitting to, in Friday's breach notification message, is that it was careless with the aggregated data accumulated from contact list uploads.

The problem, says Facebook, lay in its Download Your Information (DYI) feature, which exists so you can suck down everything you've previously entrusted to the social networking giant.

Ironically, DYI itself is an important security component of Facebook, because it helps to deal with two serious concerns about cloud-style services:

DYI improves availability, because it allows you to make your own off-site backup of everything you've stored on Facebook.DYI improves transparency, because it acts as a record of everything you've uploaded to Facebook over the years.

But there was a bug in DYI, of the data leakage/unauthorised disclosure sort.

Apparently, DYI was capable of letting you download more than you'd uploaded in the first place.

Using our example above, Bob might have ended up receiving Alice's contact data about Charlie, as well as his own, when he hit the DYI button.

In other words, Bob wouldn't just get back Charlie's address and workplace, which is what he himself uploaded, but might also have ended up with Charlie's phone number, courtesy of Alice.

That's not good at all.

It's especially bad for Charlie, who not only didn't open up his phone number to his Facebook friends, but chose not to upload it in the first place.

Facebook chose to release its statement about this breach on Friday evening, which has already raised the eyebrows of former Naked Security denizen Graham Cluley.

Friday nights, he argues, are the traditional time for burying the sort of announcements you make of necessity rather than by choice.

You can see why Facebook might want this to be a weekend story: there's a chance that it might cause some companies to rethink their "Facebook at Work" strategies, and go back to the old days where Facebook was blocked outright.

That would put a dent in Facebook's daytime traffic, for sure.

After all, if someone shares their contact list while they're at work, they might end up sharing a whole lot more, about many more people, than they really intended.

And Facebook just admitted that, somewhere in its cloud, was a bug that prevented it from taking proper care of that data.

Facebook turned off DYI once the bug was disclosed, fixed it, turned DYI back on again, and published its data breach notification.

Even if you take a cynical view of the timing and the title of the notification, I think you should be happy about some aspects of this cautionary tale:

Respect to the finder of the bug for disclosing it responsibly to Facebook so it could be fixed, even though he'd probably have got a lot more publicity if he'd told the world first.Thanks to Facebook for having a bug bounty programme so that the finder gets some sort of reward for doing the right thing.Well done to Facebook for taking the bug report seriously and fixing the problem.Congratulations to those jurisdictions that have passed strong data breach notification laws, so that this sort of problem can't just be swept under the carpet.Huzzah to those of you who take the stance of not sharing contact lists with social networking sites, on the principle that "if you don't share it, they can't lose it."

Follow @duckblog


View the original article here

Friday, October 25, 2013

#Facebook gets #hashtags, which does #WTF to your #privacy?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

facebook logoFor those Facebook users who are allergic to any notion of privacy whatsoever and would prefer that the entire world be privy to contents of their #dinner or antics of their adorable #children, Wednesday was a high and holy day indeed, for that was the day that Facebook embraced the hashtag.

The company announced that starting on Wednesday, users would be able to add clickable hashtags to posts, similar to Twitter (for whom user Chris Messina invented the hashtag back in 2007), Instagram, Tumblr, or Pinterest.

Clicking on a hashtag will lead you to a feed that shows what other people and pages are saying about the hashtagged subject.

Facebook hashtag example

As Messina said about his hashtag rationale, he wasn't interested in other people's talk about creating official groups on Twitter.

Rather, he was more interested in enabling eavesdropping:

I’m more interested in simply having a better eavesdropping experience on Twitter.

To that end, I focused my thinking on contextualization, content filtering and exploratory serendipity within the Twittosphere.

With hashtags, Facebook is also interested in eavesdropping, aka encouraging users to open up conversations to strangers. Likely, as pointed out by The Register's Kelly Fiveash, the aim is to "juice up more ad revenue."

As it is, Facebook is happy to point out, "roughly a Super Bowl-sized audience" engages with the social network every night, during "primetime television alone."

Take Game of Thrones, for example, for which the recent, remarkably gory episode "Red Wedding" got over 1.5 million mentions on Facebook. That's not too shabby, given that 5.2 million people watched it.

How will this impact your privacy? It shouldn't, if you avoid using hashtags to get Facebook Nation to follow your conversations.

#privacyCurrently, users control the audience for their posts, including those with hashtags.

Unfortunately, there have been far too many users who don't control who sees their posts, even in the pre-hashtag world.

As Consumer Reports reported a year ago, 13 million US Facebook users weren't using, or were oblivious to, privacy controls.

At the time, Consumer Reports found that in the prior 12 months, Facebook users "liked", updated their profiles, and posted status updates to produce these data points at these rates:

39.3 million identified a family member in a profile20.4 million included their birth date and year in their profile7.7 million "liked" a Facebook page pertaining to a religious affiliation4.6 million discussed their love life on their wall2.6 million discussed their recreational use of alcohol on their wall2.3 million "liked" a page regarding sexual orientation

If you want to ensure that hashtags don't get the privacy-oblivious into even hotter water, do them a favor and educate them on how to work Facebook privacy controls.

There's a great video from Consumer Reports here on how to do just that.

Oh, and if you want to hear the security latest news about Facebook, give the Naked Security Facebook page a 'like'.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Wednesday, October 2, 2013

Facebook kicks out rape jokes and gender hate speech

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

facebook logoUp until Tuesday, it was, apparently, OK to host a Facebook page titled "Fly Kicking Sl*ts in the Uterus" or " Violently Raping Your Friend Just for Laughs", but it was definitely not OK to post breastfeeding or post-mastectomy content.

I say "apparently" because those particular pages, pointed out by a women's coalition as examples of Facebook-condoned content regarding violence or hate speech against women, can no longer be found on the site.

Thanks to an open letter to Facebook from that coalition - which includes Women, Action & the Media, The Everyday Sexism Project and others - Facebook has confessed that it's been kind of asleep at the wheel when it comes to gender-based hate.

It also, apparently, has taken down the particularly offensive pages to which the coalition referred.

An excerpt from a statement posted Tuesday on the Facebook Safety page:

Statement from Facebook

In recent days, it has become clear that our systems to identify and remove hate speech have failed to work as effectively as we would like, particularly around issues of gender-based hate. In some cases, content is not being removed as quickly as we want. In other cases, content that should be removed has not been or has been evaluated using outdated criteria. We have been working over the past several months to improve our systems to respond to reports of violations, but the guidelines used by these systems have failed to capture all the content that violates our standards. We need to do better - and we will.

Facebook posted a bullet list of what it plans to do better, starting immediately.

Here's the nub of those action items:

Complete a review and update guidelines that its user operations team uses to evaluate reports of hate speech. Update training for the teams that review and evaluate reports of hateful speech or harmful content on Facebook.Increase accountability of the creators of content that might not qualify as actionable hate speech but is cruel or insensitive by insisting that the authors stand behind the content they create. A few months ago, Facebook began testing a new requirement that the creator of any content containing cruel and insensitive humor include his or her authentic identity for the content to remain on Facebook, with the goal of enabling users to hold the author accountable and directly object to the content. Work more directly with groups in this area, including women's groups, to assure expedited treatment of content that such groups believe violate Facebook standards. Facebook says it's invited representatives of Everyday Sexism, for example, to join the less formal communication channels Facebook has set up with other groups.Encourage anti-hate-speech groups Facebook already works with, such as the Anti-Defamation League’s Anti-Cyberhate working group, to include representatives of the women’s coalition, with the goal of identifying "how to balance considerations of free expression, to undertake research on the effect of online hate speech on the online experiences of members of groups that have historically faced discrimination in society, and to evaluate progress on our collective objectives."

Like button. Image courtesy of ShutterstockThe women's coalition that sparked the change says that those who participated in its campaign against gender-based hate speech on Facebook sent over 60,000 tweets and 5,000 emails.

Since the campaign launched, the coalition has grown to include over 100 women’s movement and social justice organizations.

In its open letter, the coalition called on Facebook users to contact the advertisers whose Facebook ads appeared next to content targeting women for violence, to ask that they withdraw their advertising until Facebook cleaned up its act.

From the letter:

Specifically, we are referring to groups, pages and images that explicitly condone or encourage rape or domestic violence or suggest that they are something to laugh or boast about...

...Your common practice of allowing this content by appending a [humor] disclaimer to said content literally treats violence targeting women as a joke.

The coalition applauded the changes Facebook outlined on Tuesday, saying that its latest move is in line with the company's prior history in battling hate speech:

Facebook has already been a leader on the internet in addressing hate speech on its service. We believe that this is the foundation for an effective working collaboration designed to confront gender-based hate speech effectively. Our mutual intent is to create safe spaces, both on and off-line. We see this as a vital and essential component to the valuable work that Facebook is doing to address cyber-bulling, harassment and real harm.

This is a good move on Facebook's part.

I'm glad to hear that the company plans to get less muddled when it comes to differentiating between violent, hateful content and that which constitutes justifiable free expression.

I'm glad that this has resulted in some truly offensive content getting fly-kicked right to the curb.

Follow @LisaVaas
Follow @NakedSecurity

Image of like button courtesy of Shutterstock.


View the original article here

Thursday, August 29, 2013

Facebook introduces Trusted Contacts, makes you ask, “How much do I trust my friends?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Losing access to your Facebook account is a big deal, especially if you use it to generate business as well as to keep up with your friends.

Getting control back over "lost" online accounts can be an even bigger deal.

It's not as though you went into a branch of Facebook, or Google, or Microsoft, and established your identity in a reliable and repeatable way when you opened your account.

And there's no-one at the branch you've never been to who would recognise you with certainty by your appearance, voice and mannerisms.

So you're stuck with unreliable methods, such as knowing the answer to various "security" questions, or sending in a scanned copy of a driving licence.

Neither of those approaches to account recovery are appealing from a security point of view, or terribly convincing as identification.

But what if there were someone who could speak up for you to the Facebooks of the world, and that you would trust to speak up for you because you selected them for that job in the first place?

That's the idea behind Facebook's just-announced Trusted Contacts feature.

You choose three to five trusted contacts that can request account recovery codes on your behalf, but you need to have three codes at the same time to complete the recovery process.

? To configure this feature, assuming it's available in your region and language, login to Facebook and go to the "gear wheel" dropdown menu. Choose Account Settings, go to the Security tab and click on Trusted Contacts, then Choose Trusted Contacts.

This is bit like setting up a corporate bank account so that it requires multiple signatures, to prevent a rogue director operating alone.

As Facebook points out in its evangelism of this new service:

With trusted contacts, there's no need to worry about remembering the answer to your security question or filling out long web forms to prove who you are. You can recover your account with help from your friends.

Will it work?

I'll give this approach a qualified "Yes."

I like the fact that this effectively decentralises your identity (or, more correctly, your right to assume a specific identity) on Facebook, and lets you take control of it yourself.

There are risks, however.

As Facebook points out, you need to "choose people you trust, like friends you'd give a spare key to your house."

But the company may be making a bit of a culutural leap there, because I'm not convinced that we yet treat access to other people's online accounts with the same gravity as we do access to their property.

Nick Statt, a Readwriteweb journalist who was still at college when Facebook came onto the social scene, wrote about this very issue under the headline, "Can You Really Trust Your Friends?"

His concern over Trusted Contacts lies mainly in the fact that he, and his friends, seem to have spent their formative adult years in a milieu in which "If anyone left their account open on any computer that wasn't their own that person's Facebook account was fair game."

And even if your friends don't share what Nick Statt calls the "joy of Facebook hacking," you have to be sure that your Trusted Contacts will heed Facebook's own warning:

Your trusted contacts should make sure it's you before giving you security codes.

In theory, three out of the three-to-five chums you choose to be your Trusted Contacts would need to collude to rip your account off.

But in practice, one turncoat "friend" might very well be able to collect three codes for himself by applying social engineering to two of your other friends.

For example, he could ask the others to generate recovery codes and send them to what he says is your new email account, and tell them that you weren't able to call everyone individually because you had to use a borrrowed phone.

Apple took a different approach when it introduced two-factor authentication recently, preferring instead to rely on a single recovery code so that only you can reset your password.

Apple reminds you to write down and keep somewhere safe - what you might do, in fact, with a spare key to your house.

That's an approach I think I prefer, but I can see why Facebook didn't want to rely on a single, long-lasting recovery code.

After all, the temptation to store the master password somewhere insecure (such as in an unencrypted file on your everyday computer) will just be too great for some users.

Worse still, if you lose that one-off master password, then you'll lose access to your account forever.

And that, if you remember, is the very problem we were trying to avoid at the top of the article.

Follow @duckblog


View the original article here

Saturday, July 20, 2013

Facebook Home - Great if you think privacy is dead

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

FacebookHome170Is Facebook Home the long rumored Facebook phone? Nope.

Rumors of a Facebook phone are nearly as common as OS X users who don't think they need anti-virus, but that doesn't make either one of them true.

Facebook is avoiding the hassles of designing and manufacturing its own hardware, but nevertheless making a land grab for control of the user experience.

The concept is simple: replace the lockscreen and application launcher on popular Android devices with a streamlined, Facebook-focused experience.

It is only available on a few devices at this time, including the Samsung Galaxy S3, Samsung Galaxy Note II, HTC First, HTC One X, and HTC One X+.

So I thought I would take a quick look at it from a security and privacy standpoint.

Modifying things like lockscreens can easily go sideways, as we've seen in the past with iOS.

In fact, without even considering how the app is designed to work, there are already reports of Home disabling the built-in Android pattern/passphrase lock on the new HTC First.

That isn't supposed to happen, of course, so I would think twice about enabling it until Facebook is able to release a fix.

CoverFeed170What Facebook Home is supposed to do is replace your plain vanilla lockscreen with a continuously-updated feed from your Friends, a feature they call Cover Feed.

You will see their photos, wall posts, comments, Likes, and more, all the time, in real time.

All of this information is visible without unlocking your phone and provides the opportunity to double-tap to Like the content you are viewing.

This is an interesting new take on the "lock" in "lockscreen," and while the always-logged-in "privacy is dead" angle won't be a surprise to Facebook fans, it raises worrying opportunities for abuse.

Just imagine what some of your friends might post to their walls simply to have it show up on your phone during a business meeting!

Even if you are not a Facebook Home user, you'll still be impacted.

When you post a photo or comment, you won't know when or where it will show up on your Friends' phones, or who might be around to see it.

And if you travel a lot, you may end up stuck with some heavy-duty roaming fees from downloading all of those photos, all of the time.

The Facebook Home Launcher component is largely uncontroversial.

It's uncomplicated, and while it steers you towards Facebook functionality and apps rather than Android ones, it seems perfectly functional.

ChatHeads170The feature people seem to like the best is called Chat Heads.

I have to admit, if I were a frequent Facebook chatter I would love this -- in fact I wish Google Talk worked more like Chat Heads.

The idea is your Friends' photos appear as little circles at the edge of your screen, popping out and displaying any chat messages, no matter what application you are using on your phone at the time.

My verdict?

If you are a heavy Facebook user and don't mind the privacy risks, I think you'll really like Facebook Home. (I'd wait until Facebook works out the lockscreen bypass problems, but otherwise it isn't inherently broken.)

But if you are a corporate user and enlisted in a BYOD program, I'd steer clear.

In fact if I were administering a BYOD program, I would disallow Facebook Home, as I feel there is too much room for information leakage for it to be a safe choice in a business environment.

My advice?

Take the time to think through the privacy implications before you install it.Be understanding if your employer doesn't let you use it on BYOD devices. Consider living without the Cover Feed option, even if you love the idea.Follow @chetwisniewski

View the original article here

Thursday, June 20, 2013

Bill Gates offers $5000 for Facebook sharing? It's just not that funny

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Bill Gates may be a billionaire, but if he's going to splash his cash around he's got better things to do with it than give it to people who simply share a photo of him on Facebook.

Bill Gates on Facebook message

That hasn't, however, stopped almost 400,000 people on Facebook from sharing an image of the Microsoft founder, holding an (obviously Photoshopped) message:

Hey Facebook,

As some of you may know, I'm Bill Gates. If you click that share link, I will give you $5,000. I always deliver, I mean, I brought you Windows XP, right?

Clearly, no-one is going to receive any money for sharing the image. And chances are that the picture was meant as a joke (although it would have been funnier if the message hadn said Windows Vista rather than Windows XP, or referenced Microsoft Bob, or reminded people of Bill Gates's claim that spam would be killed off by 2006).

On this occasion, the message being spread across is harmless. It doesn't trick users into clicking on a dangerous link, or fool them into installing a rogue application. It is, of course, adding to the general "noise" on Facebook and some might consider it unwanted spam.

But the more you share "jokes" like this, and the more used your friends and family become to you spreading such material, the more likely it is that you're fostering an atmosphere where forwarding chain letters, hoaxes and jokes is considered the norm.

And the more you share material like the picture above, the *less* out of place a *real* scam or malicious link will appear to your friends and family when your Facebook account gets compromised.

So, call me a kill-joy if you like, but jokes like this aren't necessarily going to end up with everyone amused.

Don't forget you should join the Naked Security from Sophos Facebook page, where we keep you up-to-date on the latest hoaxes, scams, security and privacy issues affecting Facebook users.

Follow @gcluley

View the original article here

Tuesday, June 18, 2013

Rohypnol, rape and other disturbing content. Isn't it about time Facebook cleaned up its act?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Facebook Abuse"People use Facebook to stay connected with friends and family, to discover what’s going on in the world, and to share and express what matters to them."

Those are the words of Facebook itself. And there's nothing wrong with that.

But, unfortunately, it doesn't tell the whole story.

There are also people who use Facebook to bully others, to spread hate speech, to defraud, spam, and commit online crimes.

In October 2012, when Facebook reached one billion active monthly users, CEO Mark Zuckerberg said he was "committed to working every day to make Facebook better for you".

If compared to the populations of countries, Facebook's more than a billion users dwarfs the likes of the United States, Indonesia and Brazil and is only outranked by China and India. In short, Facebook is colossal.

But what marks out Facebook for special attention is how it polices those many many millions of people.

A quick search on Facebook, using the most obvious of search terms, finds plenty of ghastly content that many good-minded people would find disturbing.

I'm not talking about Facebook pages like "Embarrassing Nightclub Photos", whose whole raison d'être appears to be to humiliate "tired-and-emotional" party-goers - many of whom probably wouldn't have given permission for a photograph of them to be shared on Facebook, if anyone had bothered to ask.

Embarrassing Nightclub Photos on Facebook

"Embarrassing Nightclub Photos" isn't my cup of tea, but clearly there's an audience for this kind of material (the page has over 160,000 Likes) who have no qualms about checking out and sharing images of people unconscious through over-drinking, who are so drunk they've become incontinent, or have been snapped midway through a vomit.

What is more disturbing to me are pages which take things a sinister step further.

For instance, there are pages extolling the virtues of the date-rape drug Rohypnol which use images of young women in either a drunken or comatose state.

In the following, and other examples used in this article, we have pixellated out the faces of individuals - something which the original posters on Facebook seemingly didn't care enough to do.

Rohypnol image 2

ROHYPHNOL

When traditional dating methods just aren't cutting it!

Is that a funny joke to you? An ill-conceived bad taste joke about rape? Or something more sinister? No doubt, you have your own point of view, and whether Facebook should do more to prevent this kind of content from being shared.

In case you forgot, here's how Facebook describes what it is used for:

"People use Facebook to stay connected with friends and family, to discover what’s going on in the world, and to share and express what matters to them."

One wonders how that sentiment sits alongside the "Roofies" page on Facebook, which has over 650 Likes, and a motto which appears to condone use of the Rohypnol date rape drug.

"Roofies", for the uninitiated, is slang for Rohypnol and other sedative pills that can be used to facilitiate sexual abuse.

Roofies page extolling rohypnol

ROHYPNOL ROOFIES When "Nooosshh..zzzzz means "Yes"

Pretty unsavoury stuff, I'm sure many of you'll agree. And there are plenty of other posts on the page which can only be described as pro-rape and against a woman's right to decide if she wants to have sex or not.

Posts on Roofies Facebook page

And there's more. A simple search of Facebook using offensive phrases can bring up no end of unpleasantness.

Offensive content on Facebook

If you were a Facebook advertiser, how would you feel about your advertisement appearing on Facebook pages containing that kind of content? Is it something your brand would like to be associated with?

If it only took me a few seconds of searching to find content like this on Facebook, why can't Facebook search for similarly offensive phrases and take action against unsavoury content.

It's not as though only the only users of Facebook are broad-minded, unoffendable, adults.

Although young people under the age of 13 years old aren't allowed to log into Facebook, it's estimated that millions of pre-teens do go onto the social network every day. They, like the rest of us, can easily come into contact with this kind of offensive material on Facebook. They may even end up the victims of some of it.

Sadly, the onus is on Facebook users themselves to report abuse - which (might) then be followed-up by Facebook's four different abuse teams.

According to Facebook, abuse complaints are normally handled within 72 hours, and the teams are capable of providing support in up to 24 different languages.

If posts are determined by Facebook staff to be in conflict with the site's community standards then action can be taken to remove content and - in the most serious cases - inform law enforcement agencies.

Facebook has produced an infographic which shows how the process works, and gives some indication of the wide variety of abusive content that can appear on such a popular site.

The graphic is, unfortunately, too wide to show easily on Naked Security - but click on the image below to view or download a larger version.

Facebook reporting guide. Click to view large version of infographic

Of course, you shouldn't forget that just because there's content that you might feel is abusive or offensive that Facebook's team will agree with you.

As Facebook explains:

Because of the diversity of our community, it's possible that something could be disagreeable or disturbing to you without meeting the criteria for being removed or blocked. For this reason, we also offer personal controls over what you see, such as the ability to hide or quietly cut ties with people, Pages, or applications that offend you.

My own experience from a few years back (when my wife's life was threatened, I was labelled a paedophile, and Facebook users warned that they would burn my house), was that Facebook chose to take no action until the press got wind of the story.

facebook-threat.jpg

I would like to think things have got better since then - but the emails we receive at Naked Security from Facebook users suggest many still feel they aren't being properly protected from Facebook abuse.

The sheer amount of offensive material residing on Facebook says to me that leaving it up to the community to report offending content isn't working.

In my opinion, Facebook needs to invest resources and technology into pro-actively cleaning up its community, rather than relying on the community to police itself.

We would be interested in hearing about your experiences when you report abusive content to Facebook. Were you happy with Facebook's reponse? Join the discussion on our Facebook page

Follow @gcluley

View the original article here

Wednesday, June 5, 2013

Facebook plugs Timeline privacy hole

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Europe vs FacebookEurope v. Facebook, an Austrian student organization that keeps tabs on Facebook's privacy transgressions, recently discovered that Facebook's latest timeline redesign allowed friends of friends to see the total number of Events a user has attended, even if that person's privacy settings were set to only allow friends to see such events.

This screw-up allowed for unintended sharing of sensitive information, such as political beliefs and sexual orientation, the group said in a release.

europe-v-facebook.org - Facebook March

From the release:

"Users were able to look through often times thousands of past events users were invited to, including demonstrations or gay parties."

Facebook's timeline changes allowed unintended displays of information to friends of friends. Facebook’s View as function displayed such information as public, displaying it in batches of event activity under a heading called Events.

Facebook thankfully plugged the hole within hours of the group informing the company about the problem.

The problematic section, Events, disappeared from affected users' profiles, after which the group could no longer access the data in question, Europe v. Facebook said.

Europe-v-facebook.org - Facebook fixed leak in new timeline

When Facebook announced the redesign on March 13, the company said it be would rolled out over a few weeks.

Many users, not having been upgraded yet, were oblivious to the privacy hole, Europe v. Facebook said.

This is the latest of a string of challenges the group has put to Facebook over what it deems privacy violations in Europe.

The group has filed a total of 22 complaints with the Irish Data Protection Authority against Facebook’s European subsidiary in Ireland.

Max SchremsThose complaints were built on the work of meticulous document requester and researcher Max Schrems, who in 2011 extracted a pile of 1,200 pages that comprised his then-current personal-data Facebook dossier.

In fact, Schrems, the organizer of Europe v. Facebook, has been awarded the 2013 International Privacy Champion Award by the Electronic Privacy Information Center (EPIC) for his work, which has "inspired more than 40,000 users around the world to make similar access requests, helping to ensure greater transparency of internet companies".

As reported by IDG News Service's Jeremy Kirk, Facebook committed to changing how it retains data and altered some privacy controls following a critical audit by the regulator released in December 2011.

Unsatisfied, Europe v. Facebook has continued to keep the Irish Data Protection Commissioner's feet to the fire.

This recent privacy hole is just the latest result of the group's praise-worthy efforts.

The group is to be applauded for its vigilance. That vigilance is pricey, so if you care about privacy and want to support their efforts, you might want to consider contributing to their work at https://www.crowd4privacy.org/.

If you're on Facebook and want to keep informed about privacy issues, scams and internet attacks, join the Naked Security page, where over 211,000 people regularly share information on threats and discuss the latest security news.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Saturday, May 11, 2013

Has Justin Bieber died in a car crash? No. But that doesn't stop Facebook users spreading the "news"

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Justin BieberBefore you start sobbing, let me tell you the good news.

Justin Bieber hasn't died in a car crash.

Phew! I'm sure we're all relieved about that. Not least Mister Bieber himself.

But what if you had heard on the grapevine that the pint-sized heart-throb had come to a grisly end? How would you have confirmed the news?

Chances are, these days, that you might have Googled for an appropriate phrase like "bieber dies in car crash". And look what the very first search result is:

Google search result

If you were to click on that link you would be taken to what appears, at first glance, to be a legitimate news website:

Fake news story

However, if you are a long term reader of Naked Security there should be enough here to ring some alarm bells. Doesn't it remind you of the Global Associated "news" story from earlier this year about the death in a car crash of Pet Shop Boys star Neil Tennant?

Funnily enough that appears to have happened on entirely the same stretch of road - "Route 80 between Morristown and Roswell".

Past bogus death reports have involved the likes of deaths of Adam Ant, Jim Carrey, Christian Slater, Vanilla Ice, Tom Cruise amongst many others...

The truth is that somewhat tasteless websites exist which allow anyone to automagically generate a fake news story about a death in a car crash. Simply changing the link changes the name of the victim.

Before you know it, internet users are unwittingly forwarding the message without checking their facts, and the tasteless website is earning itself some cash from all of the new traffic seeing its adverts.

Sadly, careless Facebook users are re-sharing this bogus story of Justin Bieber's death to all and sundry, keeping the hoax alive and helping drive traffic to a website that thinks it is clever to play such sick pranks.

Fake news spread on Facebook

Get your real news from real news websites. Don't trust Google or your Facebook friends, as they may be sharing links and stories that simply aren't true.

Follow @gcluley

View the original article here

Wednesday, May 8, 2013

Facebook fixes bug that leaked users' phone numbers

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Like image courtesy of ShutterstockFacebook has fixed a bug that was leaking users' phone numbers to application developers.

Reported in June 2012, the API (application programming interface) bug was affecting the email field in some mobile apps that accessed Facebook's API.

The original report about the glitch was reproduced in a Facebook notice in which Facebook's Alvin Sng said it should now be resolved.

Facebook said that when retrieving a user's email address via graph API, app developers were receiving a 10-digit number once for every 1,000 users, more or less, instead of the properly formatted email address the documentation states that the field should return.

But as pointed out by IDG's Zach Miners, some app developers reported significantly higher incidences.

One such developer - Nathan Cobb, research investigator with the American Legacy Foundation, an antismoking nonprofit - said the group's smoking cessation app, Ubiquitous, was returning phone numbers for about one in every 200 users, Miners reports.

Facebook hasn't reported whether or not it knows of developers who've used the numbers to call users to promote their services.

Facebook graph searchAs it is, those concerned about privacy are already disturbed by the possibility of Facebook's new Graph Search being able to squeeze out data that users might have posted and then forgotten about, or how it could be used to cross-relate disparate pieces of data about people, with less than desirable results.

Or, as Sophos's Graham Cluley put it in this headline: How to find single women who like men *and* like getting drunk, with Facebook Graph Search.

Graph Search doesn't reveal anything Facebook users haven't already shared, but it does make it a heck of a lot easier to piece together.

Facebook took nine months to fix the API glitch so that it's no longer handing over users' phone numbers on a silver platter.

Stories like this make it easier to understand why some assume the company's priorities lie in digging personal data out, rather than ensuring it doesn't get handed over inadvertently.

Follow @LisaVaas
Follow @NakedSecurity

Like image courtesy of Shutterstock


View the original article here

Saturday, April 27, 2013

Facebook turns a deaf ear to users aged over 99

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Life goes into a sort of reverse time-warp after we attain the age of 99, if Facebook is to be believed.

The social media behemoth apparently never assumed that a person with three digits worth of living to their credit would sign up to use its service.

Hence, Facebook finds itself apologizing to Marguerite Joseph, a 104-year-old Michigan woman in the United States.

Marguerite Joseph on Facebook

According to Ms. Joseph's granddaughter, Gail Marlow, Facebook keeps shaving 20 years off of Joseph's age.

According to WDIV-TV, when Ms. Marlow tries to input her grandmother's birth year as 1908, Facebook rolls it back to 1928.

The real-life centenarian is legally blind and doesn't hear well, but her granddaughter reads posts from relatives and types in responses to all of the messages Ms. Joseph receives.

Ms. Marlow has been trying to bring the problem to Facebook's attention for years - including directly emailing Facebook founder Mark Zuckerberg - but hasn't yet heard back.

Her grandmother turns an auspicious age - 105 - in April, Ms. Marlow says, meaning it's high time to get her age right:

"Every time I tried to change the settings to the right year, Facebook always came back with an unknown error message and would send us right back to a year she wasn’t born in... I would love to see her real age on Facebook, I mean in April she’s going to be 105. It’s special."

Facebook logoFollowing press interest, Facebook finally apologized on Wednesday, saying that it's working to fix a problem limiting used of pre-1910 birthdates.

From WDIV-TV:

We've recently discovered an issue whereby some Facebook users may be unable to enter a birthday before 1910. We are working on a fix for this and we apologize for the inconvenience.

I'm glad to hear Facebook is finally paying attention.

True, Facebook has had much bigger fish to fry. Nothing like 83 million fake accounts, privacy glitches, arguments over facial recognition, and a Java-assisted network breach to distract a company.

But ignoring a reported glitch for years seems a bit excessive.

Talk about hard of hearing. Years of non-responsiveness does little to reassure us that Facebook is listening.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here