Google Search

Showing posts with label there. Show all posts
Showing posts with label there. Show all posts

Thursday, August 9, 2012

Facebook: There are over 83 million fake accounts on our site [INFOGRAPHIC]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Facebook has released statistics showing that it believes there are more than 83 million fake accounts on its social network.

Some 8.7% of the site's 955 million users are believed to be bogus, according to documents that the company filed with the Securities and Exchange Commission (SEC) earlier this week.

Facebook fake infographic

According to Facebook, the biggest proportion of the bogus accounts (4.8% of all accounts on the network) belong to users who maintain duplicate accounts.

Why might you want to have more than one account? Well, I know a primary school teacher who doesn't want her pupils to see what she gets up to socially (and the drunken pictures her friends might post of her at wild parties) and so she maintains one "professional" account (under her real name) and another "personal" account under a nickname.

Of course, such behaviour (the ownership of more than one account, not the partying) is in violation of Facebook's terms & conditions.

Example of a Fake Facebook account

That clearly isn't bothering some 45 million users, however.

Then there are what Facebook calls "user-misclassified" accounts. Those users who have created personal profiles for their business, their boat, their pet, or some other non-human entity.

Facebook claims that approximately 2.4% of the accounts on its network are mis-classified in this way, and that really the owners of those almost 23 million accounts should create a page for their business/pet/etc instead.

Finally, and perhaps of most interest to Naked Security's readers, we come to the 1.5% of accounts that are categorised as "undesirable". Over 14 million Facebook accounts are used for the primary purpose of sending out spam or other malicious links and content.

Why does this matter? Well, clearly all Facebook users are interested in the site becoming a safer place, and the level of spam and malicious links being minimised. But more than that, companies who are considering advertising on the social network want to be sure that any "likes" they receive are from genuine users, not bogus accounts.

Fake accounts on Facebook

Interestingly, Facebook says that the percentage of fake accounts is higher in developing markets such as Indonesia and Turkey, than in countries where the social network is more established.

That was certainly experience of BBC News Technology reporter Rory Cellan-Jones, who recently explored the value of Facebook advertising by creating a page about "Virtual Bagels" and was flooded with fans from Egypt, Indonesia and the Philippines - with many of the accounts obviously false.

Of course, it's far from simple for Facebook to determine reliably if every account is fake or not, as anybody can create an account with a bare minimum of credentials. What remains to be seen is whether the proportion of dodgy accounts on Facebook continues to grow, and if the site's advertisers view it as a problem.

Follow @gcluley

View the original article here

Wednesday, August 24, 2011

Twitter is not charging in October, there is no petition, you're being phished

Facebook logoOver 30,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest internet and Facebook security threats. X

Twitter logoHi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats. X

Another scam to steal Twitter users credentials is making the rounds today. The tweets being sent out read "Twitter might start to charge in October, sign this petition to keep the service free! -URL-."

Twitter petition tweets

The official Twitter account, @safety, has warned people about the threat and it appears that the Twitter team is having partial success extinguishing this one. Here is an example block page I received when attempting to visit one of the URLs.

Twitter block image

Unfortunately it did not take me long to find the original destination dressed up with several different URL shorteners. This one seems to still be making the rounds to some extent.

Remember folks, rather than click those short URLs, you can always check them over at longurl.org. If you expanded this one you would see that it eventually takes you to ltittier -dot- com, which was registered on a Chinese DNS server at three past midnight this morning.

Twitter phishing page

The site is a near perfect duplicate of the real Twitter login site, and it masquerades as a message that your session has timed out. You will need to "reauthenticate" and hand over your identity to the criminals immediately.

At least one Twitter user seems to be having some fun with this and has produced her own copy of the scam... Earlier this morning @trojankitten posted "Twitter might start charging in October, a petition is picking up speed to keep it free.-URL-."

If you click the short link, you are redirected a bit and end up on a pastie.org page that reads:

"Hi,
This is Trojan Kitten. Twitter won't "start charging in October," but there's yet-another-twitter-malware, which will send tweets like these from your account, once you're affected:

"Twitter might start to charge in October, sign this petition to keep the service free! link.here/to-malware" "Twitter is going to charge now? read this article on twitter :( link.here/to-malware"

And since you see the text you're currently reading, you could've been affected: you clicked the link. I don't actually blame the users. So let's blame Twitter for its loose control on apps (in terms of security).

If you have been hit with this scam, be sure to change your Twitter password immediately and it would be prudent to log in and revoke all application API access as well.

You will need to reauthorize each Twitter enabled program as you use them, but your account will be safer for it.

Follow @chetwisniewski

View the original article here