Google Search

Showing posts with label about. Show all posts
Showing posts with label about. Show all posts

Tuesday, June 18, 2013

Rohypnol, rape and other disturbing content. Isn't it about time Facebook cleaned up its act?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Facebook Abuse"People use Facebook to stay connected with friends and family, to discover what’s going on in the world, and to share and express what matters to them."

Those are the words of Facebook itself. And there's nothing wrong with that.

But, unfortunately, it doesn't tell the whole story.

There are also people who use Facebook to bully others, to spread hate speech, to defraud, spam, and commit online crimes.

In October 2012, when Facebook reached one billion active monthly users, CEO Mark Zuckerberg said he was "committed to working every day to make Facebook better for you".

If compared to the populations of countries, Facebook's more than a billion users dwarfs the likes of the United States, Indonesia and Brazil and is only outranked by China and India. In short, Facebook is colossal.

But what marks out Facebook for special attention is how it polices those many many millions of people.

A quick search on Facebook, using the most obvious of search terms, finds plenty of ghastly content that many good-minded people would find disturbing.

I'm not talking about Facebook pages like "Embarrassing Nightclub Photos", whose whole raison d'être appears to be to humiliate "tired-and-emotional" party-goers - many of whom probably wouldn't have given permission for a photograph of them to be shared on Facebook, if anyone had bothered to ask.

Embarrassing Nightclub Photos on Facebook

"Embarrassing Nightclub Photos" isn't my cup of tea, but clearly there's an audience for this kind of material (the page has over 160,000 Likes) who have no qualms about checking out and sharing images of people unconscious through over-drinking, who are so drunk they've become incontinent, or have been snapped midway through a vomit.

What is more disturbing to me are pages which take things a sinister step further.

For instance, there are pages extolling the virtues of the date-rape drug Rohypnol which use images of young women in either a drunken or comatose state.

In the following, and other examples used in this article, we have pixellated out the faces of individuals - something which the original posters on Facebook seemingly didn't care enough to do.

Rohypnol image 2

ROHYPHNOL

When traditional dating methods just aren't cutting it!

Is that a funny joke to you? An ill-conceived bad taste joke about rape? Or something more sinister? No doubt, you have your own point of view, and whether Facebook should do more to prevent this kind of content from being shared.

In case you forgot, here's how Facebook describes what it is used for:

"People use Facebook to stay connected with friends and family, to discover what’s going on in the world, and to share and express what matters to them."

One wonders how that sentiment sits alongside the "Roofies" page on Facebook, which has over 650 Likes, and a motto which appears to condone use of the Rohypnol date rape drug.

"Roofies", for the uninitiated, is slang for Rohypnol and other sedative pills that can be used to facilitiate sexual abuse.

Roofies page extolling rohypnol

ROHYPNOL ROOFIES When "Nooosshh..zzzzz means "Yes"

Pretty unsavoury stuff, I'm sure many of you'll agree. And there are plenty of other posts on the page which can only be described as pro-rape and against a woman's right to decide if she wants to have sex or not.

Posts on Roofies Facebook page

And there's more. A simple search of Facebook using offensive phrases can bring up no end of unpleasantness.

Offensive content on Facebook

If you were a Facebook advertiser, how would you feel about your advertisement appearing on Facebook pages containing that kind of content? Is it something your brand would like to be associated with?

If it only took me a few seconds of searching to find content like this on Facebook, why can't Facebook search for similarly offensive phrases and take action against unsavoury content.

It's not as though only the only users of Facebook are broad-minded, unoffendable, adults.

Although young people under the age of 13 years old aren't allowed to log into Facebook, it's estimated that millions of pre-teens do go onto the social network every day. They, like the rest of us, can easily come into contact with this kind of offensive material on Facebook. They may even end up the victims of some of it.

Sadly, the onus is on Facebook users themselves to report abuse - which (might) then be followed-up by Facebook's four different abuse teams.

According to Facebook, abuse complaints are normally handled within 72 hours, and the teams are capable of providing support in up to 24 different languages.

If posts are determined by Facebook staff to be in conflict with the site's community standards then action can be taken to remove content and - in the most serious cases - inform law enforcement agencies.

Facebook has produced an infographic which shows how the process works, and gives some indication of the wide variety of abusive content that can appear on such a popular site.

The graphic is, unfortunately, too wide to show easily on Naked Security - but click on the image below to view or download a larger version.

Facebook reporting guide. Click to view large version of infographic

Of course, you shouldn't forget that just because there's content that you might feel is abusive or offensive that Facebook's team will agree with you.

As Facebook explains:

Because of the diversity of our community, it's possible that something could be disagreeable or disturbing to you without meeting the criteria for being removed or blocked. For this reason, we also offer personal controls over what you see, such as the ability to hide or quietly cut ties with people, Pages, or applications that offend you.

My own experience from a few years back (when my wife's life was threatened, I was labelled a paedophile, and Facebook users warned that they would burn my house), was that Facebook chose to take no action until the press got wind of the story.

facebook-threat.jpg

I would like to think things have got better since then - but the emails we receive at Naked Security from Facebook users suggest many still feel they aren't being properly protected from Facebook abuse.

The sheer amount of offensive material residing on Facebook says to me that leaving it up to the community to report offending content isn't working.

In my opinion, Facebook needs to invest resources and technology into pro-actively cleaning up its community, rather than relying on the community to police itself.

We would be interested in hearing about your experiences when you report abusive content to Facebook. Were you happy with Facebook's reponse? Join the discussion on our Facebook page

Follow @gcluley

View the original article here

Monday, April 1, 2013

Questions and answers about the Twitter hack

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Twitter birdI've been speaking to the media today about the Twitter hack that saw the credentials of around 250,000 users scooped up by cybercriminals.

During the day, the same questions have been cropping up - and I thought it would be useful to briefly cover them here.

What did the hackers steal?

According to a blog post by Twitter, the hackers stole usernames, email addresses, session tokens and salted-and-hashed passwords (which is certainly better news than if they had stolen plaintext passwords).

What could the hackers do with that information?

A few things:

The hackers could spam the email addresses, pretending to be Twitter and maybe trick you into clicking on a link or opening an attachment. In this way they might steal further information from you.They could target specific Twitter users (they now know the email address associated with each of the affected accounts) and craft an email designed to dupe the user in some way - potentially into clicking on a dangerous link or attachment - perhaps pretending to be someone else.Using the stolen session token they could, in theory, hijack your account, at least until the you or the hacker next logs off.They could attempt to crack the passwords, by setting computers and large dictionaries of commonly used passwords against the problem. If some of the passwords are cracked, the hackers could then attempt to see if the same passwords will also unlock victims' *other* accounts (such as their email).

Who is behind the hack attack on Twitter?

We don't know. Twitter has had its internal systems hacked in the past (infamously, for instance, celebrity accounts were hijacked after a Twitter employee was found by hackers to be using an extremely weak password - "happiness"). Normally attacks are against individual accounts with the intention of spreading diet spam or malicious links, rather than against Twitter's systems themselves.

I've heard media reports linking the Twitter hack with the attack on the New York Times and other newspapers that's been blamed on China. Was it the Chinese who hacked Twitter?

Although Twitter referenced the recent high-profile attacks on newspapers, they haven't explicitly said that they believe China hacked Twitter or presented any evidence to suggest that.

If Twitter has any information that does point a finger of suspicion towards China (such as if dissident or human rights Twitter accounts were targeted) they haven't shared that with the media.

How will I know if I am one of the Twitter users who has been affected?

Twitter has emailed affected users, resetting passwords and revoking session tokens. Your old password will no longer allow you into Twitter, and you'll have to choose another one.

What kind of password should I use?

Always use passwords that are not easy-to-guess or dictionary words. Make it as long as possible, and use a mixture of upper and lower case letters, numbers and special characters.

How am I supposed to remember a password like that?

Here's a video which explains how to choose a strong password, which is easy to remember but still hard to crack:

(Enjoy this video? You can check out more on the SophosLabs YouTube channel and subscribe if you like)

But you say I should have a different password for every website I use... how can I realistically remember all of them?

You can't. Use password management software like KeePass, 1Password or LastPass. They can hold your passwords securely, and all you have to remember is your master password (make it a good one). Password management software can even generate random, complex passwords for you when you create new accounts.

Couldn't I just let my browser remember my passwords?

Most modern browsers do offer to save your usernames and passwords for the websites you visit, but I do not recommend it.

Why does Twitter say that I should disable Java in my browser?

Whether your browser is Java-enabled or not has no bearing on whether Twitter (on completely different computers from your own) is capable of being hacked or not. However, we do see frequent web-based attacks exploiting security holes in Java - so, unless you really need it, it might be wise to learn how to turn off Java in your browser.

Think of it as Twitter just trying to be helpful and neighbourly, rather than giving advice specific to this latest attack.

(Of course, it's always possible that the computers of Twitter employees were infected via a Java vulnerability. But they haven't owned up to that. Other possible vectors by which Twitter staff might have been hit by malware included boobytrapped Word Documents or PDF files).

How else might take advantage of the Twitter hack?

It's possible we could see bogus emails spammed out pretending to come from Twitter. Users might be tricked into believing that they are really messages from Twitter telling them that their account was compromised in the hack, and click on links without thinking of the possible consequences. All users need to be on their guard against social engineering tricks like this.

What else should I do?

Read this article by my colleague Paul Ducklin.

Stay secure.

Follow @gcluley

View the original article here

Sunday, February 3, 2013

PowerPoint about the Mayan "end of the world" secretly boobytrapped with malware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Will the world end in 2012Earlier this week my colleagues Peter Szabo and Richard Wang respectively discovered and wrote about malware disguised as a Microsoft Excel spreadsheet used to generate Sudoku puzzles to help pass the time.

This morning I was contacted by another SophosLabs researcher, Scott Sitar, about a booby-trapped PowerPoint presentation titled "Will the world end in 2012?"

Like the Excel spreadsheet, this file contained Visual Basic macro code that drops an executable file called VBA[X].exe, where [X] is a random capital letter. In fact, the macro was functionally identical to that found in the Sudoku puzzle.

Also like the Sudoku generator, this sample required the user to enable macros, but didn't include the helpful tip on how to do it or really any good reason you might need a macro to learn about the end times.

What are these macros up to? They are designed to construct a valid Windows PE file (Portable Executable) from arrays of single bytes.

While this isn't particularly new, it would throw off the average user from understanding what these macros are designed to do even if they bothered to take a look.

Screenshot of malicious VB macros

Owl image retrieved by malwareThe EXE file that is extracted is what we call a dropper. It extracts another Windows PE file which downloads a picture of an owl, then contacts a command and control server.

It is designed to download another payload it will rename as Wmupdate.exe, but during our testing no instructions were sent from the command-and-control server to retrieve this payload.

Scott mentioned his suspicions that these were being automatically generated and not necessarily handcrafted by their creators. I think he's right.

I took a look around and discovered the original, uninfected files that these dangerous macros had been added to.

The presentation about the world ending was created by a preacher in the United States who appears to have nothing to do with this booby-trapped version. Don't go looking for this presentation though!

His legitimate WordPress blog has been compromised and is currently performing search engine manipulation duties for Viagra pushers, "off-shore" casinos, forex fraud and payday loans.

SEO keywords on compromised blog

If you do want to see what this presentation has to say, I was able to find it online in a safe to view format.

While macro viruses certainly aren't a new phenomenon, they aren't something many people think about.

Be careful with documents you acquire from random sources and never enable macros in documents you download or receive as email attachments.

You never know what might be lurking in there, but I suspect it won't be the end of the world.

A special thanks to Scott Sitar in SophosLabs Vancouver for spotting this and doing all of the analysis necessary to share this story.

Sophos Anti-Virus on all platforms blocks this malware as follows:

WM97/ExeDrop-G: The malicious Office macro
Troj/DwnLdr-KLB: The Windows malware dropped by the above

Follow @chetwisniewski


View the original article here

Friday, November 23, 2012

Is Google about to start scanning your Android for malware?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Android tabletDo you still think that there's no need for an anti-virus on your Android smartphone? Soon you might not have any choice.

Judging by a report on the Android Police website, a new edition of the Google Play app (Android's equivalent to the iOS App Store) has put in place the foundations for some kind of anti-virus functionality.

Looking at the code seen inside the app, it appears that Google could soon have the capability to perform anti-malware scans on your smartphone. Our own examination has confirmed the existence of strings in the app's code such as:

"Allow Google to check all apps installed to this device for harmful behavior? To learn more, go to Settings > Security."

"Installing this app may harm your device"

"Installation has been blocked"

"To protect you, Google has blocked the installation of this app."

There are also some interesting-looking graphics (well, not that interesting.. but you can probably imagine how they might be used):

Anti-malware graphics

Our examination of the new code in Google Play suggests that the company is building an API framework for virus-scanning in the future, and that the functionality will not be available until at least API level 17 (which will be supported in the version of the Android operating system after Android 4.1 (Jelly bean).

This functionality would also make use it seems of the Google Safe Browsing API.

Google attempts to keep malware out of its official Google Play Marketplace (with varying levels of success), but that doesn't stop users from installing Trojans from unofficial sources.

In the past we've seen fake versions of Instagram, Angry Birds and many more popular Android apps distributed via non-official channels with the intention of infecting Android phones and tablets.

My advice would be for Android users to protect their devices against malware. The problem is becoming too serious to ignore. Sophos has a free anti-virus for Android which you can download (naturally enough) from the Google Play store.

http://twitter.com/gcluley

Hat-tip: Android Police


View the original article here

Friday, November 9, 2012

Civil Rights CAPTCHA asks how you feel about gay people being beaten with sticks

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

If you want to put a spanner in the works of automated bots leaving spam comments on your blog, or creating fake accounts on your website, one of the things you may deploy is a CAPTCHA system.

We've all seen them. They are the questions (often using distorted graphics) that you get asked by a website which is trying to determine if you are a human being or an automated computer program.

Sometimes they're not much of a hurdle for humans to jump over:

Conventional CAPTCHA

On other occasions, they may present some of us with a tricky challenge:

Facebook CAPTCHA fail

And although some have tried to make the task of completing a CAPTCHA fun,

CAPTCHA challenge

others have probably made the barrier of entry too high:

Complicated calculus spam CAPTCHA

A Naked Security reader has pointed me to a new CAPTCHA system, being actively promoted by the Civil Rights Defenders group.

According to the Swedish-based group, its CAPTCHA system "takes a stand for civil rights issues across the globe" and it hopes that it will "help promote and empower our partners - brave human rights defenders, who often put themselves at great risk through their engagement for other people's rights."

Here's an example, where you are asked if you feel glamorous, pleasant or agonized at the thought of gay people being beaten with a stick:

CAPTCHA question

And another, where website visitors are asked how they feel about a ban on "homosexual propaganda":

CAPTCHA question

If you fail to answer correctly (or at least, fail to answer in accordance with the opinion of the Civil Rights Defenders group and any sane member of society), you will be told to wait five seconds and another question will be popped up for you to try again.

If I have any issue with the Civil Rights Defenders' CAPTCHA system it would be that at the moment there seems to be a very limited selection of questions - and all the ones I saw required a negative response.

A wider gallimaufry of questions for web users to ponder - both negative and positive - would probably be a more effective challenge for automated bots.

All this, of course, is ignoring the fact that CAPTCHAs are frequently beaten today by spammers outsourcing the cracking of CAPTCHAs to impoverished workers in the third-world, paid a pittance for completing thousands of the puzzles each day.

Nevertheless, this is an imaginative step by the Civil Rights Defenders group.

Follow @gcluley

View the original article here

Tuesday, September 18, 2012

Sophos Techknow - All about Java

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Welcome to another episode of Techknow, the podcast in which Sophos experts debate, explore and explain the often baffling world of computer security.

In this episode, entitled All about Java, Paul Ducklin and Chester Wisniewski dig into the what, the how, and most importantly the why, of the popular programming language that dominated security headlines in August 2012 for all the wrong reasons.

Java brings with it some significant risks, yet for many people, it's "just there on my computer." And the reason it's there is, "It's always been there. And you need it for lots of websites, don't you?"

Even in the business world, many organisations never quite seem to have got around to asking where, or even if, Java is needed on corporate assets such as laptops and servers.

In this quarter-hour podcast, Duck and Chet tell you All about Java (did you know it was originally named after a tree?), and help you to make an informed decision in balancing its risks and rewards.

Listen now:

(31 August 2012, duration 16'19", size 11MBytes)

Listen later:

Download Techknow podcast

Follow @duckblog
-

Tags: drive-by, drive-by download, Exploit, Java, JavaScript, Linux, Malware, oak, Oracle, osx, solaris, Sun, techknow, vulnerability


View the original article here

Thursday, May 17, 2012

What the FBI didn't tell us about the hotel malware threat

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Internet access in hotel room. Image from ShutterstockIf you follow the field of computer security chances are that you saw the warning issued by the FBI's Internet Crime Complaint Center (IC3) this week about using hotel internet connections.

Here's the full text of the advisory, with some responses sprinkled throughout from yours truly:

Malware Installed on Travelers' Laptops Through Software Updates on Hotel Internet Connections

Recent analysis from the FBI and other government agencies demonstrates that malicious actors are targeting travelers abroad through pop-up windows while establishing an Internet connection in their hotel rooms.

"Malicious actors"? Are we talking cybercriminal gangs and fraudsters or state-sponsored bad guys from an enemy nation?

"Travelers abroad"? So, you mean that this can't possibly happen within the United States?

Why the coyness about naming countries? Is it because the FBI doesn't know which countries this pertains to (other than it's definitely not happening in the USA)? Is it because they have a list of countries, but they're not sure if it's a complete, exhaustive list? Or is it because the authorities don't want to say which countries?

Recently, there have been instances of travelers' laptops being infected with malicious software while using hotel Internet connections.

"Malicious software"? Can you tell us what malicious software? Is it a particular malware family? Can you at least tell us what the malware is attempting to do?

In these instances, the traveler was attempting to setup the hotel room Internet connection and was presented with a pop-up window notifying the user to update a widely-used software product.

"A widely-used software product"? Why not name it? The FBI isn't saying a variety of popular products, it's saying "a widely-used software product". Should it really be up to us to place bets as to whether it's likely to be Adobe Flash or not?

If the user clicked to accept and install the update, malicious software was installed on the laptop. The pop-up window appeared to be offering a routine update to a legitimate software product for which updates are frequently available.

Which operating system are we talking about here? Windows? Mac OS X? Linux? iOS? Might have been handy to mention..

The FBI recommends that all government, private industry, and academic personnel who travel abroad take extra caution before updating software products on their hotel Internet connection.

"Government, private industry, and academic personnel..take extra caution"? Hang on. What about the rest of us? Shouldn't we also be careful if we're taking our computers overseas, perhaps on vacation? Or is the un-named country where this is happening not the kind of place people go on holiday to?

Checking the author or digital certificate of any prompted update to see if it corresponds to the software vendor may reveal an attempted attack.

But is likely to be beyond the ken of the vast majority of users..

The FBI also recommends that travelers perform software updates on laptops immediately before traveling, and that they download software updates directly from the software vendor’s Web site if updates are necessary while abroad.

Sensible. No complaints with that. But the idea of business people travelling for weeks on end without installing security updates while they're on the road sounds like it could backfire.

Anyone who believes they have been a target of this type of attack should immediately contact their local FBI office, and promptly report it to the IC3's website at www.IC3.gov. The IC3's complaint database links complaints together to refer them to the appropriate law enforcement agency for case consideration. The complaint information is also used to identify emerging trends and patterns.

What's fascinating about the advisory is what it doesn't say. And without more information it's hard to know how computer users are supposed to take meaningful action to protect themselves other than follow the normal advice of running security software, being careful what you install, running a VPN to hide your browsing from snoopers, etc.

It's certainly very peculiar that the FBI didn't share more information in its warning, or mention where in the world it believes it has seen these attacks taking place.

By coincidence, earlier this week, for the first time in almost ten years, a Chinese defense minister visited the United States.

The day before the FBI's warning was issued, US Defence Secretary Leon Panetta met his Chinese counterpart Liang Guanglie in Washington DC, and told the world's press that the two countries must work together to avoid cyber war, and emphasised the importance of the relationship between China and the USA.

US and Chinese military chiefs met in Washington this week, to discuss cyber attacks

Maybe there was more that the authorities could have said about this hotel malware threat, but thought it undiplomatic to publicise.

Follow @gcluley

Laptop in hotel room image, courtesy of Shutterstock.


View the original article here

Thursday, April 5, 2012

Technical paper: Learn about the Blackhole exploit kit

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Blackhole, courtesy of ShutterstockThe Blackhole exploit kit first reared its head in late 2010. Since then it's grown to be one of the most notorious exploit kits ever seen.

In this technical paper, "Exploring the Blackhole Exploit Kit", SophosLabs' Fraser Howard lifts the lid on Blackhole.

He describes in detail how it works and the various files used to exploit machines and infect them with malware.

Fraser discusses how the kit has become so successful by uncovering and explaining the tricks used by Blackhole.

From how a user's web traffic is controlled to how the attackers attempt to evade detection, the paper offers a great insight into how Blackhole works.

Blackhole image, courtesy of Shutterstock


View the original article here

Sunday, November 20, 2011

Facebook will no longer tell you everything it knows about you

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Facebook CDIn the face of an ocean of users demanding their personal data as required by European Union law, Facebook has sharply constricted the amount of data it's handing over.

Instead of sending CDs, Facebook is now directing users to a page where they can download a personal archive, but that archive is now covering only 22 categories — less than half of the 57 categories received by early requesters in the Europe vs. Facebook campaign, according to a report from ITworld.

The new stinginess comes in the midst of an audit by Ireland's Data Protection Commissioner. The audit is the result of 22 privacy-based complaints (to view the list of complaints, go to Kim Cameron's Identity Weblog) lodged by Europe vs. Facebook.

That campaign is led by Max Schrems, a 24-year-old law student from Vienna who secured 1,200 pages of personal data on a CD months ago by using a European requirement that entities with data about individuals make it available to those individuals if they request it.

The Irish agency is auditing Facebook for compliance with the country's Data Protection Acts of 1988 and 2003, which transpose the E.U.'s Data Protection Directive, known as 95/46/EC.

Europe vs. Facebook contends that Facebook is withholding personal data in violation of these laws, which require companies to disclose data to users on request.

Lisa McGann, a senior investigations officer, on Tuesday told IDG News Service that the agency has received an additional 150 complaints about Facebook’s inadequate response to data requests and 10 complaints over data protection, according to ITworld.

Stack of emailMr. Schrems told ITworld that he’s exchanged e-mails with Richard Allan, Facebook's director of European public policy, who’s indicated that Facebook is contemplating a system modification that would allow a more in-depth batch of information if the agency finds fault in the company's current strategy.

In the meantime, Facebook is throttling back the data volume it releases. While Facebook is defending its actions, claiming that it is "fully compliant with E.U. data protection laws," the categories of data it’s releasing has nosedived.

Mr. Schrems told ITworld that the CDs Facebook initially sent out when he and others first requested their personal Facebook dossiers contained 57 categories of data. Now, Mr. Schrems said, Facebook is excerpting between 19 and 24 categories of data.

In addition to cutting back on the data it releases, Facebook has turned to a do-it-yourself model. Facebook recently created an email address, datarequests@fb.com, for people to request data. An autoreply from that account directs users to an archive download tool.

Facebook Download Archive site

The autoreply also curtly snips off further conversation, stating that “We will not enter into further correspondence about your specific data through this email address.”

The latest move by Facebook is just "a way of getting rid of people," Mr. Schrems told ITworld, since more transparency would "freak people out," he said.

Facebook, if what Mr. Schrems believes is correct, I’d like to propose that you’re wrong. More transparency would have the opposite effect to freaking us out.

As it is, we’re already freaked out. Hundreds of legal complaints are a visible symptom of freak-out.
What’s going to continue to freak us out is if you keep tightening your sphincter.

The more tight-fisted you are with our personal data, the more you will cause your users to suspect that you plan to do things with it that we would rather you didn't.

If you're on Facebook and want to keep informed about privacy issues, scams and internet attacks, join the Sophos page on Facebook, where over 150,000 people regularly share information on threats and discuss the latest security news.

Follow @lisavaas

View the original article here

Wednesday, October 26, 2011

SSCC 76 - Michael Kaiser, NCSA and Rob Strayer chat about cyber security

function utmx_section(){}function utmx(){}(function(){var k='2740995052',d=document,l=d.location,c=d.cookie;function f(n){if(c){var i=c.indexOf(n+'=');if(i>-1){var j=c.indexOf(';',i);return escape(c.substring(i+n.length+1,j')})();SSCC 76 – Michael Kaiser, NCSA and Rob Strayer chat about cyber security | Naked Security /* */×The press love Sophos's free anti-virus for Mac - fancy giving it a spin?Antivirus and Security Software from SophosGlobal websites    Press    About us    Contact usProductsSolutionsSupportSecurityPartnersNaked SecuritySkip to contentSearch for:

Archive by date |author |category

Send us a tip | Subscribe by RSS

Follow us on TwitterJoin us on FacebookCheck out the SophosLabs YouTube channelConnect with us on LinkedInMalwareSpamSocial networksData lossLaw & OrderApplePodcastVideoMoreAbout iOS 5 introduces security challenges and flawsHacker's phone call to Boston Police saying he defaced their website.. because he was bored SSCC 76 - Michael Kaiser, NCSA and Rob Strayer chat about cyber security

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Don't forget you can subscribe to the SophosLabs YouTube channel to find all our latest videos.

Hi there! If you're new here, you might want to subscribe to our RSS feed for updates.

Already using Google+? Follow Naked Security's Graham Cluley for the latest security news.

On LinkedIn? Join the Naked Security discussion group and connect with your peers in the security industry.

We're very sorry, something happened and we couldn't sign you up. We'll try to fix it so please come back later and try again.

Congratulations, you've successfully signed up for our daily news! Check your inbox soon, we've sent you an email.

Sorry, that email doesn't look right to us so we haven't added it to our list.

We're adding your address to our list...

utmx_section("Newsletter intro text")

Want to see more? Get Naked Security headlines by email every day!

utmx_section("Newsletter button text")by Chester Wisniewski on October 23, 2011|91096Leave a commenthttp%3A%2F%2Fnakedsecurity.sophos.com%2F2011%2F10%2F23%2Fsscc-76-michael-kaiser-ncsa-and-rob-strayer-chat-about-cyber-security%2FSSCC+76+-+Michael+Kaiser%2C+NCSA+and+Rob+Strayer+chat+about+cyber+security2011-10-23+03%3A31%3A04Chester+Wisniewskihttp%3A%2F%2Fnakedsecurity.sophos.com%2F%3Fp%3D91096

Filed Under: Featured, Law & order, Malware, Podcast, Privacy

Sophos Security Chet Chat logoLeading up to the State of Cyber Security event we will be speaking at October 27th in Washington DC I interview the other panellists on their thoughts around cyber security.

First I interviewed Michael Kaiser the founder and chief executive of the National Cyber Security Alliance. The NCSA focuses on providing educational outreach to home users, schools and small businesses about staying safe online.

We talked about the challenges facing the public when going online and the goals for National Cyber Security Awareness Month. Michael also gave us a glimpse into what he will be discussing at our State of Cyber Security event.

Rob Strayer, Director of the National Security Preparedness Group at the Bipartisan Policy Center, also found some time to chat with me by phone this week. Staryer's group focuses on encouraging public/private cooperation on matters of cyber security.

Rob discussed the goals of the National Security Preparedness Group and why they think there is so much work to be done for better information sharing between the public and private sectors. Rob also shared a teaser about his presentation at our event on October 27th.


(21 October 2011, duration 11:58 minutes, size 8.6 MBytes)

You can also download this podcast directly in MP3 format: Sophos Security Chet Chat 76, subscribe on Stitcher, iTunes or our RSS feed.

Follow @chetwisniewskiDigg

Tags: #NCSAM11, Bipartisan Policy Center, chet chat, Michael Kaiser, NCSA, NCSAM, Podcast, Rob Strayer

iOS 5 introduces security challenges and flawsHacker's phone call to Boston Police saying he defaced their website.. because he was bored About the authorChester Wisniewski is a Senior Security Advisor at Sophos Canada. He provides advice and insight into the latest threats for security and IT professionals with the goal of providing clear guidance on complex topics.You can follow Chester on Twitter as @chetwisniewski or send him an email at chesterw@sophos.com.View all posts by Chester WisniewskiRelated PostsIT administrators await mammoth Microsoft security patch bundleThe state of cyber security - Join Sophos and the NCSA in Washington DCSophos Security Chet Chat 41SSCC 57 - Infosec Europe 2011, Facebook privacy4th grade root beer memory foils Facebook chat scammer4th grade root beer memory foils Facebook chat scammerImage (1) twitter-hacked.jpg for post 15581Twitter website struck by 'Iranian Cyber Army' hackersPopularRecentRelatedanonymous-phone-thumbHacker's phone call to Boston Police saying he defaced their website.. because he was boredLaw student triggers 22 legal complaints and likely audit of FacebookHow to find out everything that Facebook *really* knows about youios5250iOS 5 introduces security challenges and flawsgaddafi-malware-thumbMalware attack poses as bloody photos of Gaddafi's deathosborne-170Letter from HM Treasury? Just another scamosborne-170Letter from HM Treasury? Just another scamanonymous-phone-thumbHacker's phone call to Boston Police saying he defaced their website.. because he was boredChetChatLogo250SSCC 76 - Michael Kaiser, NCSA and Rob Strayer chat about cyber securityios5250iOS 5 introduces security challenges and flawsIT administrators await mammoth Microsoft security patch bundleThe state of cyber security - Join Sophos and the NCSA in Washington DCIT administrators await mammoth Microsoft security patch bundleThe state of cyber security - Join Sophos and the NCSA in Washington DCSophos Security Chet Chat 41SSCC 57 - Infosec Europe 2011, Facebook privacy4th grade root beer memory foils Facebook chat scammer4th grade root beer memory foils Facebook chat scammerImage (1) twitter-hacked.jpg for post 15581Twitter website struck by 'Iranian Cyber Army' hackersVideo posts

More videos this way

Nimda, Lion hole, scam bust, .CZ.CC and RIP Steve - 60 Sec SecurityNimda, Lion hole, scam bust, dot CZ dot CC and RIP Steve - 60 Sec Security 60ss-20110913-250Apple fakery, DNS hack, DigiNotar, Linux, Wikileaks - 60 Sec Securityterrytoad-250Facebook page hijacking locks out original admins [VIDEO]Bomb hoax, busts, ATM skimming, Twitter security, Google fined - 60 Sec SecurityBomb hoax, busts, skimming, Twitter security, Google fined - 60 Sec Security facebook-aflame-squareMacbooks, Korea, Spamford busted, phones lost, Anonymous threat - 60 Sec SecurityTwitter FeedSophosLabs: RT @gcluley: Listen to hacker telling police he hacked their website because he was bored http://t.co/fp1B4jSu #occupyabout 2 hours agogcluley: RT @nakedsecurity: Letter from HM Treasury? Just another scam http://t.co/3vn3tjoLabout 4 hours agogcluley: Listen to hacker telling police he hacked their website because he was bored http://t.co/9eGHHL9Iabout 6 hours agogcluley: Sophos podcast: Michael Kaiser, NCSA and Rob Strayer chat about cyber security http://t.co/GgI2afz3about 8 hours agoChetWisniewski: Sophos Security Chet Chat 76 #podcast - interview Michael Kaiser NCSA and Rob Strayer from Bipartisan Policy Center http://t.co/RsSqcKXvabout 12 hours ago
Follow us on TwitterJoin us on FacebookCheck out the SophosLabs YouTube channelConnect with us on LinkedInEnglishDeutschEspañolFrançaisItalianohttp://www.sophos.co.jphttp://www.sophos.cnhttp://tw.sophos.comhttp://kr.sophos.com© 1997-2010 Sophos Ltd. All rights reservedLegalPrivacyJobsRSSjQuery(document).ready(function($){ Gravatar.profile_cb = function( h, d ) { WPGroHo.syncProfileData( h, d );}; Gravatar.my_hash = WPGroHo.my_hash; Gravatar.init( 'body', '#wpadminbar' ); });

View the original article here