Google Search

Showing posts with label handing. Show all posts
Showing posts with label handing. Show all posts

Thursday, November 28, 2013

Facebook, the early years: handing out a master password like candy

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Mark Zuckerberg. Image courtesy of Kobby Dagan / Shutterstock.You are not paranoid about surveillance - at least, not as far as Facebook is concerned.

It appears that Facebook founder Mark Zuckerberg and his minions, in the early days, had a master password with which they could sign in to any user account and poke at whatever data we entrusted to the site.

The Guardian gleaned this from Zuckerberg's former speechwriter, Katherine Losse.

Losse told the media outlet that users should be guarded with their private data on the site - a timely warning, given the launch of Facebook's social search tool graph search.

Losse - aka Facebook employee No. 51 - joined the company in 2005 as a customer support staffer and worked her way up to being Zuckerberg's ghostwriter. She left in 2010 and, according to the Guardian, is now regarded as a rogue former employee by Facebook itself.

In 2012, she released a book, The Boy Kings, about those early years.

Recent revelations about the US National Security Agency's (NSA's) voraciously hungry appetite for surveillance may have left many users of social networking sites fretting about the government sucking up our private data, but Facebook has been privy to that data - including our passwords - from its infancy, Losse told the Guardian.

As The Guardian's Siraj Datoo points out, that's a little scary, given that plenty of users likely have never changed their passwords since they first signed up.

To make matters worse, many people commit security blasphemy by using the same password on multiple sites.

To make matters spontaneously combust in worse-osity, Losse wrote in "The Boy Kings" that in its early years, Facebook passed out the master password like candy, without vetting any of the support staffers.

Here's an excerpt from the book, courtesy of coverage from CNet's Jennifer Van Grove:

"Jake introduced us to the hanky application through which users' e-mails to Facebook flowed. Once we learned how the software worked, Jake taught us, without batting an eyelid, the master password by which we could log in as any Facebook user and access all their messages and data... I experienced a brief moment of stunned disbelief: They just hand over the password with no background check to make sure I am not a crazed stalker?"

As Losse told The Guardian, social networking users tend to assume they're the only ones who can access the information they input, but at most companies, it's probably not true, given that "at least some of the staff need to have access to user accounts in order to do their jobs."

She said:

"There has to be a way for the staff to manage and repair user account issues, and for this reason user data within most startups, especially when they are young, is never completely locked up from company staff."

At any rate, Facebook doesn't hand out a master password anymore, it says.

Nowadays, the company told CNet, employees don't have password access:

"An audit by the Irish Data Protection Commission included a detailed review of the level of access to user data that employees have at Facebook and found that we have an appropriate framework in place. Facebook employees do not have access to users' passwords."

It is, of course, preferable that we have as clear a picture as possible of what companies do with our personal data, so this history of early data yahooism is welcome.

Facebook silhouette. Image courtesy of Shutterstock.If it helps Losse to sell more books by tying it in to concern about PRISM-like surveillance, that's OK, as far as I'm concerned.

The more light we shed on these formerly murky matters, the better.

Facebook from its start could watch us, listen to us, and, probably, make fun of us and our soppy, trivial and/or really embarrassing posts and data.

Now it can't, it assures us.

If that helps to ease your compulsive surveillance suspicions, paralyzing fear of electronic privacy violation, or even, to borrow the Joy of Tech's formal diagnosis, PRISM Anxiety Disorder, all the better.

Thank you, Ms. Losse, for letting us know.

Follow @LisaVaas

Follow @NakedSecurity

Images of Facebook silhouette and Mark Zuckerberg courtesy of Kobby Dagan / Shutterstock.com.


View the original article here

Monday, August 20, 2012

How social engineering tricked Wal-Mart into handing over sensitive information

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

WalmartWal-Mart pretty much sliced itself open and spilled its guts onto the scammer's lap.

In this year's Capture the Flag social engineering contest at Defcon, champion Shane MacDougall used good lying, a lucrative (albeit bogus) government contract, and his talent for self-effacing small talk to squeeze the following information out of Wal-Mart:

The small-town Canadian Wal-Mart store's janitorial contractor,Its cafeteria food-services provider,Its employee pay cycle,Its staff shift schedules,The time managers take their breaks, Where they usually go for lunch, Type of PC used by the manager, Make and version numbers of the computer's operating system, and Its Web browser and antivirus software.

DefconReporting from the Las Vegas show, which wrapped up a few weeks ago, Stacy Cowley at CNNMoney wrote up the details of how Wal-Mart got taken in to the extent of coughing up so much scam-worthy treasure.

Calling from his sound-proofed booth at Defcon MacDougall placed an "urgent" call - broadcast to the entire Defcon audience - to a Wal-Mart store manager in Canada, introducing himself as "Gary Darnell" from Wal-Mart's home office in Bentonville, Ark.

The role-playing visher (vishing being phone-based phishing) told the manager that Wal-Mart was looking at the possibility of winning a multimillion-dollar government contract.

"Darnell" said that his job was to visit a few Wal-Mart stores that had been chosen as potential pilot locations.

But first, he told the store manager, he needed a thorough picture of how the store operated.

Walmart. Image from Shutterstock

In the conversation, which lasted about 10 minutes, "Darnell" described himself as a newly hired manager of government logistics.

He also spoke offhand about the contract: "All I know is Wal-Mart can make a ton of cash off it," he said, then went on to talk about his upcoming visit, keeping up a "steady patter" about the project and life in Bentonville, Crowley writes.

As if this wasn't bad enough, MacDougall/Darnell directed the manager to an external site to fill out a survey in preparation for his upcoming visit.

The compliant manager obliged, plugging the address into his browser.

When his computer blocked the connection, MacDougall didn't miss a beat, telling the manager that he'd call the IT department and get the site unlocked.

After ending the call, stepping out of the booth and accepting his well-earned applause, MacDougall became the first Capture the Flag champion to capture every data point, or flag, on the competition checklist in the three years it's been held at Defcon.

Defcon gives contestants two weeks to research their targets. Touchy information such as social security numbers and credit card numbers are verboten, given that Defcon has no great desire to bring the law down on its head.

Defcon also keeps its nose clean by abstaining from recording the calls, which is against Nevada law.

However, there's no law against broadcasting calls live to an audience, which makes it legal for the Defcon audience to have listened as MacDougall pulled down Wal-Mart's pants.

Man vs Woman, courtesy of ShutterstockOne interesting thing to note: this year's contest took on a battle of the sexes theme, with 10 male and 10 female contestants vying to capture the flag.

Are men better at weaseling information out of people and at lying? Crowley quoted one female contestant who folded under the guilt of lying, saying she "just couldn't do it."

From her writeup:

Some contestants got nowhere with their calls, especially when they posed as outside marketers or researchers. Others froze up when they got a live human being on the line.

One first-time contestant landed a receptive HR representative, only to visibly collapse with guilt. She signaled the tech crew to cut the line.

"I just couldn't do it," she said afterward. "I'm an honest person. I didn't realize it would feel so wrong to sit there lying."

But while females might have more compunction than males about duping others, they're actually better at sniffing out a con.

Back in May, Chris Hadnagy of Social-Engineer.org, which sponsors the annual Capture the Flag contest, told Threatpost's Paul Roberts that female employees at targeted companies were less likely to fall for social engineering ruses than their male counterparts:

"Every time we get a woman on the phone as a target, she does better than the guys. She's more paranoid, and answers fewer questions. Her 'phish' meter goes up quicker and she hangs up."

Its anecdotal, but it's interesting.

In "Brain Sex: The real difference between men and women", a book about the physiological differences between the genders' brains, Anne Moir and David Jessel write that from the fetus's development in the womb, female brains are organised to respond more sensitively to all sensory stimuli, most particularly verbal/aural:

Girls and women hear better than men. When the sexes are compared, women show a greater sensitivity to sound. The dripping tap will get the woman out of bed before the man has even woken up. Six times as many girls as boys can sing in tune. They are also much more adept at noticing small changes in volume, which goes some way to explaining women's superior sensitivity to that 'tone of voice' which their male partners are so often accused of adopting.

What's an organisation to do to protect against getting vished so thoroughly like Wal-Mart?

Person dialling phone number, courtesy of ShutterstockWill it be technology like the kind Fujitsu's putting into field trials this month: phone scam detection technology that analyses voice intonation and recognises typical words used by scammers?

Or could we perhaps turn around Defcon's "battle of the sexes" and turn it into "cooperation of the sexes?"

In other words, perhaps organisations should rely more on women's inherent strengths at parsing spoken language to detect scams.

Wal-Mart spokesman Dan Fogleman told CNNMoney that the company was "disappointed [that] some basic information was shared" and that it would be mulling over what it should learn from the incident:

When you're in the customer service business, sometimes our people can be a bit too helpful, as was the case here. We emphasize techniques to avoid social engineering attacks in our training programs. We will be looking carefully at what took place and learn all we can from it in order to better protect our business.

Should one lesson for Wal-Mart and other organisations be that women should be conducting the anti-scam workshops?

Let us know your thoughts in the comments section below, and please don't hate on me for emphasising the gender aspects of this interesting lesson in phone scams.

It was Defcon who set it up as a battles of the sexes, not me.

Follow @LisaVaas

Man and woman arm-wrestling, dialling phone number and Wal-Mart images from Shutterstock.


View the original article here