Google Search

Showing posts with label friends. Show all posts
Showing posts with label friends. Show all posts

Thursday, August 29, 2013

Facebook introduces Trusted Contacts, makes you ask, “How much do I trust my friends?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Losing access to your Facebook account is a big deal, especially if you use it to generate business as well as to keep up with your friends.

Getting control back over "lost" online accounts can be an even bigger deal.

It's not as though you went into a branch of Facebook, or Google, or Microsoft, and established your identity in a reliable and repeatable way when you opened your account.

And there's no-one at the branch you've never been to who would recognise you with certainty by your appearance, voice and mannerisms.

So you're stuck with unreliable methods, such as knowing the answer to various "security" questions, or sending in a scanned copy of a driving licence.

Neither of those approaches to account recovery are appealing from a security point of view, or terribly convincing as identification.

But what if there were someone who could speak up for you to the Facebooks of the world, and that you would trust to speak up for you because you selected them for that job in the first place?

That's the idea behind Facebook's just-announced Trusted Contacts feature.

You choose three to five trusted contacts that can request account recovery codes on your behalf, but you need to have three codes at the same time to complete the recovery process.

? To configure this feature, assuming it's available in your region and language, login to Facebook and go to the "gear wheel" dropdown menu. Choose Account Settings, go to the Security tab and click on Trusted Contacts, then Choose Trusted Contacts.

This is bit like setting up a corporate bank account so that it requires multiple signatures, to prevent a rogue director operating alone.

As Facebook points out in its evangelism of this new service:

With trusted contacts, there's no need to worry about remembering the answer to your security question or filling out long web forms to prove who you are. You can recover your account with help from your friends.

Will it work?

I'll give this approach a qualified "Yes."

I like the fact that this effectively decentralises your identity (or, more correctly, your right to assume a specific identity) on Facebook, and lets you take control of it yourself.

There are risks, however.

As Facebook points out, you need to "choose people you trust, like friends you'd give a spare key to your house."

But the company may be making a bit of a culutural leap there, because I'm not convinced that we yet treat access to other people's online accounts with the same gravity as we do access to their property.

Nick Statt, a Readwriteweb journalist who was still at college when Facebook came onto the social scene, wrote about this very issue under the headline, "Can You Really Trust Your Friends?"

His concern over Trusted Contacts lies mainly in the fact that he, and his friends, seem to have spent their formative adult years in a milieu in which "If anyone left their account open on any computer that wasn't their own that person's Facebook account was fair game."

And even if your friends don't share what Nick Statt calls the "joy of Facebook hacking," you have to be sure that your Trusted Contacts will heed Facebook's own warning:

Your trusted contacts should make sure it's you before giving you security codes.

In theory, three out of the three-to-five chums you choose to be your Trusted Contacts would need to collude to rip your account off.

But in practice, one turncoat "friend" might very well be able to collect three codes for himself by applying social engineering to two of your other friends.

For example, he could ask the others to generate recovery codes and send them to what he says is your new email account, and tell them that you weren't able to call everyone individually because you had to use a borrrowed phone.

Apple took a different approach when it introduced two-factor authentication recently, preferring instead to rely on a single recovery code so that only you can reset your password.

Apple reminds you to write down and keep somewhere safe - what you might do, in fact, with a spare key to your house.

That's an approach I think I prefer, but I can see why Facebook didn't want to rely on a single, long-lasting recovery code.

After all, the temptation to store the master password somewhere insecure (such as in an unencrypted file on your everyday computer) will just be too great for some users.

Worse still, if you lose that one-off master password, then you'll lose access to your account forever.

And that, if you remember, is the very problem we were trying to avoid at the top of the article.

Follow @duckblog


View the original article here

Thursday, July 25, 2013

Snapchat sexting spam - how to stop messages from Honey Crush 9 and her friends

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

SnapchatSnapchat, which claims to deliver more than 150 million saucy photos per day between users' mobile phones, has suffered this week from a spam attack.

It's possible - if you are over the age of 17 - that you still don't know what Snapchat is.

It's a smartphone app, available for both iPhone and Android devices, that allows users to control how long a sent message or picture can be seen for, before it expires after a maximum of 10 seconds.

Still not getting the idea? Well, maybe this will help explain the attraction. The service has become notorious because some have touted it as a way of safely "sexting" and sharing naked pictures. Meanwhile, others have argued that it's not safe at all.

What isn't in doubt, however, is that Snapchat has become immensely popular - particularly among young people.

And so it wasn't really a surprise to see users complain that they had been sent photos from scantily-clad women with names such as "Honey.Crush9" inviting them to join them in a Skype conversation.

Snapchat spam, and Twitter comments from victims

Receiving such a sleazy photograph can certainly get you into trouble (see the Twitter conversation above, where one user explains her boyfriend would have had some serious questions to answer if "Honey Crush" had turned out to be a secret saucy admirer of his rather than a spammer), but there are other potential security risks.

The messages sent via Snapchat encouraged recipients to connect with the apparent sexy senders on Skype. Once you've made sexy Honey your Skype friend, she could exploit you in a number of ways.

For instance, "she" could send you malicious links with the promise of a webcam chat, or send you spammy links to a dating website, or make automated Skype calls to spread fake anti-virus warnings.

In some of the more eyebrow-raising situations she might enter into a steamy webcam conversations with you, where she strips and encourages you to do the same... only to take photos and video footage for the purposes of blackmail.

Snapchat's CEO and co-founder Evan Spiegel posted a message on the site's official blog apologising for the spam attack, and offering advice to users.

Statement from Snapchat

The reason why so many people received unsolicited photos from Honey Crush and her spamming counterparts is that Snapchat allows anyone to send you photo messages. By default, anyone who knows your username or phone number (or who can guess it) can send you a message.

To protect yourself from Snapchat spam like the examples seen above, you can configure the app to only accept messages from users on your list of friends.

According to Snapchat's FAQ, you can change this setting. It tells users to tap the camera icon as if you are going to take a picture, then, tap the square button on the bottom right corner of the screen.

Select "Settings", go to "Who can send me snaps...", and select "My Friends" instead of "Everyone."

What a shame Snapchat didn't make this the default in the first place...

Follow @gcluley

View the original article here

Monday, October 22, 2012

Twitter DMs from your friends can lead to Facebook video malware attack

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Tweetie birds. Image from ShutterstockHave you received a Twitter message from an online friend, suggesting you have been captured in a Facebook video?

A number of Naked Security readers have been in touch in recent days regarding a variety of direct messages that have been spammed out from compromised Twitter accounts.

The aim of the messages? To trick the unwary into clicking on a link.. and ultimately infect computers.

Here is one example:

Twitter direct message

your in this LoL

And here's another. Note that there are many different combinations of wording that can be used.

Twitter direct message

you even see him taping u thats awful

Users who click on the link are greeted with what appears to be a video player and a warning message that "An update to Youtube player is needed". The webpage continues to claim that it will install an update to Flash Player 10.1 onto your computer.

Malicious webpage

In this example, the program you are being invited to download is called FlashPlayerV10.1.57.108.exe, and is detected by Sophos anti-virus products as Troj/Mdrop-EML, a backdoor Trojan that can also copy itself to accessible drives and network shares.

Quite how users' Twitter accounts became compromised to send the malicious DMs in the first place isn't currently clear, but the attack underlines the importance of not automatically clicking on a link just because it appeared to be sent to you by a trusted friend.

If you do find that it was your Twitter account sending out the messages, the sensible course of action is to assume the worst, change your password (make sure it is something unique, hard-to-guess and hard-to-crack) and revoke permissions of any suspicious applications that have access to your account.

http://twitter.com/gcluley

Birds image from Shutterstock.


View the original article here

Sunday, September 16, 2012

Facebook glitch lets spear phishers impersonate users' friends and family

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Spear fishing. Image from ShutterstockFacebook, blaming a "temporary misconfiguration," accidentally let spear phishers vacuum up users' personal details so they could pose as friends and family and thus make their come-ons convincing, the company told Forbes on Wednesday.

Forbes staffer David M. Ewalt was alerted to the threat when he himself received two targeted spam messages in the preceding week, both sent to a personal email address registered with his Facebook account.

Both emails appeared to come from someone he interacts with on Facebook. The sender personalized the subject line with the text "for David."

When Ewalt checked the messages' header fields (here are instructions on how to do that), he saw his friend's name in the "From" field, but the originating address wasn't their typical account; instead, it was "a bogus-looking Yahoo! Philippines email," he wrote.

He quickly found that others had reported similar spear phishing Facebook emails, all received in the past few weeks.

Facebook told Forbes that it has discovered what it called a "single, isolated campaign that was using compromised email accounts to gain information scraped from Friend Lists due to a temporary misconfiguration on our site."

The social network said it's since enhanced its scraping protections to protect against such attacks and will continue to investigate, but that there's been neither a mass compromise of Facebook accounts nor any leak of private information.

According to Ewalt, the spear-phishing emails pose as messages from close friends or family members, address the intended victim by name in the subject line or body of the message, and include a link to a website controlled by the spammers, all meant to exploit people's tendencies to click on strange links if they come from those whom they trust.

So, has Facebook now fixed the problem? Perhaps not judging by this tweet from Reuters reporter Joseph Menn:

While Facebook tries to get to the bottom of the problem, here are its recommendations on the steps users should take to protect their accounts:

Review your security settings and consider enabling login notifications.Don’t click on strange links, even if they’re from friends, and notify the person if you see something suspicious. How do you determine if a link is "strange"? Hover over a link without clicking on it. You'll see the full URL of the link's true destination in a lower corner of your browser. Don't use the links in an email, instant message, or chat to get to any web page if you suspect the message might not be authentic or you don't trust the sender. Instead, navigate to the website directly.Be suspicious of any email with urgent requests for login or financial information, and remember, unless the email is digitally signed, you can't be sure it wasn't forged or spoofed.Don’t accept friend requests from unknown parties.If you come across a scam, report it so that it can be taken down. Facebook earlier in the month introduced a dedicated email address for reporting phishing scams: phish@fb.com. Don’t download any applications you aren’t certain about.When accessing Facebook from places like hotels and airports, text "otp" to 32665 to receive a one-time password to your account.Visit Facebook’s security page and read the items "Take Action" and "Threats".

And on a related note, how do we verify whether email addresses are fake? Well, you could alway ping it.

Tech blogger Amit Agarwal wrote up instructions on how to ping an email address to determine if it was real of fake.

Or you could plug the questionable email address into this nifty little email verifier I came across.

It seems to work. Therefore, I'm sorry to report, NehemiahHesters@lisavaas.com, that you don't exist, so I guess I can't "Buy Ciails and Viarga online," which is a shame, since they sound like new drugs, tropical resorts, or a combination of both - the last of which strikes me as genius.

Follow @LisaVaas

Spear fishing image from Shutterstock.


View the original article here