Archive for Social Networking

10 Security Reasons to Quit Facebook

Social Media Joan Goodchild, wrote an article for CSO Online that said Baby Boomers quit Facebook faster than they join based on information from Inside Facebook. The data indicates that after a huge growth in Facebook membership among the over-55 age group that same demographic began to defect in large numbers, just months after signing up. The CSO Online article quotes Scott Wright, a security consultant based in Canada and runs the site streetwise-security-zone.com says Boomers leave Facebook because they have discretion.

Here are 10 ways that Facebook does not allow for discretion, driving Boomer permanently off of Facebook.

Facebook1. Your Privacy is History Mr. Wright recalled an academic claim that the notion of privacy differs widely among generations. “The 20-something view of privacy is basically that their parents not see what they are doing. That’s about it,” he said. Apparently Facebook founder Mark Zuckerberg agrees. He claims that openly sharing information with many people is today’s social norm. He went on to say “We view it as our role in the system to constantly be innovating and be updating what our system is to reflect what the current social norms are.” Many have translated this to mean Facebook doesn’t think its users want much privacy, and the policies of the site reflect that view. “If you can’t maintain privacy online and off, then you can’t speak freely,” said Bethan Tuttle, an Washington-based independent consultant and privacy advocate. Tuttle says in the article that the massive and quick growth Facebook has experienced, coupled with a lack of privacy-centric leadership has left end-user privacy as casualty.

2. They don’t have your best interests in mind Tom Eston, creator of the web site socialmediasecurity.com points out, the business models of Facebook and  Twitter, is to make user information as public as possible to generate new ways to make money. Mr. Eston said in the article

They are really startups if you think about it. They don’t have a true business model … Their philosophy is the more you share, the more information they have to make money with. With that in mind, can you really count on them to protect you?

And do you know just how much information you are sharing that can be used not only by Facebook, but by the application developers that create those fun quizzes and games? Wright says most people don’t. (I wrote about this problem here).

3. Frequent redesigns affect privacy settings Mr. Wright in the CSO Online article said,

Just when people figure out the privacy settings on Facebook, they go and change them again … It always seems like it is being done in everyone’s best interest, but if you really examine it, they have never done anything other than to try to get people to share more information.

Facebook redesigns often makes public, and searchable, certain user information that was previously private and many of the features you can make private are left public unless you go in and adjust your privacy settings. This is no small task, according to Ms. Tuttle, “I am really good online but it took me several tries to get my Facebook privacy settings where I needed them to be.”

4. Social engineering attacks are getting more targeted Most Facebook users have received messages on their wall asking “Have you seen this video?” or “Is this you in this photo?” By clicking on the link, the user runs the risk of being infected by malware. These are known as social engineering attacks, and they are becoming more sophisticated said Mr. Wright. “They are becoming very targeted. Even seasoned security professionals are falling for them,” he said. The more information you share, coupled with a decrease in privacy, only means it is even easier for cyber criminals to get information about you that can be used to trick you into clicking on a bad link.

5. You can’t trust the ads Most web users think advertisements are  harmless, unfortunately some contain malicious links. One common scenario involves a pop-up from the ad that claims your computer is infected and prompts you to download software to fix it. Instead of helpful software, you end up downloading something nasty. This is now commonly known in the security community as “scareware,” and it’s still a very effective way to snare unsuspecting users.

6. Spam Spam claiming to be from Facebook has increased according to the article. “I think it’s a security concern,” said Mr. Eston. “Mostly because spammers can use that vulnerability to make you think the message is coming from Facebook when it is not. Many users simply wonder “Why is Facebook sending me this?” and instinctively open the message and log in to what turns out to be a fake screen that steals credentials.

7. You don’t really know your friends The author cites a report from security firm Cloudmark which concluded that close to 40 percent of new Facebook profiles are fakes.  Having lots of friends is dangerous because it opens you up to additional security risks. Mr. Wright said those who get targeted for hacking are the users who have lots of friends (here is an example). The more friends you have, the more reach a criminal will have when he breaks into your profile and sends out a bad link to everyone.

8. You can’t help yourself from being dumb The attention around the site pleaserobme.com brought to light the safety concerns around social networking. Pleaserobme aggregates the Twitter feeds of people who play Foursquare, a location-sharing application. The problem is while playing the game, many users are also publicly broadcasting that their home is likely unattended and a good “opportunity” (as the site terms it) for thieves. As Ms. Tuttle put it, you need to think about what you are doing and many people are not. You’re putting yourself out there in potentially dangerous ways, particularly if you don’t know all of your “friends” that well.

9. The great unknown CSO Online says there is a lot of speculation about a Facebook IPO and future business strategy. What does this mean for users? Mr. Wright said some fear it means an increase loss of privacy as the social networking site inevitably looks for ways to make money by offering up valuable user information to advertisers and developers. Mr. Wright said,

One of the things I find most interesting is that there are still many people who are scared to death of social networking sites. These are usually the people who don’t see value in them. In the end, they may be the wisest of us all.

Bill Clinton

Listen Zuckerberg - Stop changing the settings or I'll tell Hillary

10. Ex’s, creeps and parents Facebook is making it possible for people to be cyber stalked, even if they aren’t friends anymore, said Mr. Eston. Although the physical and virtual connections are broken , having mutual friends makes it easier for your ex to keep tabs on you. The same goes for any creepy guy or girl you are trying to avoid. Or you may get a friend request from a parent, which Mr. Wright claims many 20-something users consider the worst thing that could ever happen in the history of social networking. “That is big driver for quitting,” he said. “Once the parent friends some of these people they immediately think ‘I’ve got to get out of this!’”

What do you think?

Are you concerned about your privacy on Facebook?

View Results

Loading ... Loading ...

AccountKiller KO’s Online Accounts

Data theft AccountKiller.com says it is a website dedicated to helping social network users reclaim their  personal data. The web site helps users reclaim their personal data by explaining and ranking social networking sites. The web site explains how to delete accounts and ranks them by how hard it is reclaim your personal information.

AccountKiller provides instructions to remove your account or public profile on most popular websites, including Skype, Facebook, Microsoft (MSFT) Windows Live, Hotmail, MSNTwitterGoogle (GOOG) and many more.

Data MiningThe creators of AccountKiller have also created a blacklist of  sites that do not allow their users to reclaim their personal information.  According to the web site a black-listed site indicates it’s probably impossible or highly difficult to get rid of your account. Among the sites AccountKiller as blacklisted are:

The grey-listed sites may cost your some irritation or effort – but it should be possible to terminate your account says AccountKiller. These sites will require you need to send a mail to the site, send a message using a webform or even call them to recover your personal information.

The creators of AccountKiller say that sites purposely make it difficult or even impossible to delete your account for two reasons. First, because they are profiting from their users data. These sites are in the business of data customer retention.  Alternatively, they suggest that these developers may simply be ignorant, lazy or incompetent, i.e. not being able to create some account deletion function.

Michigan iron ore miner

Lets see what can be dug up on you

Kudos the creators of AccountKiller, I now recommend this site to anyone who has questions about these social networking sites. It is time for social networking sites to provide transparency into their real business model, data collection, otherwise there could be a social networking bubble.

What do yo think?

Do you know how to get out of your social networking sites? Can you?

Are we in a social networking bubble?

LinkedIn Accounts can be Hijacked

Data Theft Help Net Security has a report that users of the newly minted public LinkedIn (LNKD) are in danger of having their account hijacked when accessing it over insecure Wi-Fi networks or public computers. Independent security researcher Rishi Narang told Help Net Security that the risk is due to session and authentication cookies with an unnaturally long lifespan and LinkedIn’s failure to remove them once the user logs out.

LinkedInThe article says the cookies in question are JSESSIONID and LEO_AUTH_TOKEN, and are available even after the session initiated by the user has been terminated. The cookies are also set to expire only after one solid year, and this fact allowed the researcher to get access to a number of active accounts of various people from all over the world during a period of many months. “They would have login/logged out many a times in these months but their cookie was still valid,” Mr.Narnag writes on his blog.

In addition to all of that, those two cookies and the others that the welcome page stores are transmitted in clear text over HTTP, because they don’t have a secure flag set. “If the secure flag is set on a cookie, then browsers will not submit the cookie in any requests that use an unencrypted HTTP connection, thereby preventing the cookie from being trivially intercepted by an attacker monitoring network traffic,” explains Mr. Narang.

According to the researcher, until LinkedIn makes some changes, the only way to “expire” the cookies is for the users to change their password and then authenticate themselves with the new credentials. This could be a stopgap measure if you know that someone has stolen those cookies and is accessing your account, but won’t new cookies be created after the password change and authentication?

Help Net Security says that the only solution to this problem is for LinkedIn to effect some changes, and according to Reuters, they are planning to offer “opt-in” SSL support for the entire site in the coming months (and that would encrypt the cookies in questions), but have not commented on the cookies have such a long lifespan.

 

YouTube Founders Acquire Delicious from Yahoo!

Social NetworkingIn one of the most search engine friendly articles, ITnewsLink reports that on April 27th, YouTube founders Chad Hurley and Steve Chen announced they have acquired the Delicious technology from Yahoo! (YHOO). They plan to continue the service that users have come to know and love and make the site even easier and more fun to save, share and discover the web’s “tastiest” content.

deDeliciousProviding a seamless transition for users is incredibly important. Yahoo! will continue to manage Delicious over the next couple months as users are able to sign up for new accounts. After the transition period is complete, users’ information will be moved over to the new service.

“As we have said, part of our product strategy involves shifting our investment with off-strategy products to put better focus on our core strengths and fund new innovation, says staff on Yahoo! blog. We believe this is the right move for the service, our users and our shareholders. Chad Hurley and Steve Chen are building an exciting new company and we look forward to watching the Delicious service continue to develop!”

Updated to WordPress 3.1

Thanks to a snow day, I was able to update the Bach Seat blog to WordPress 3.1.

Step 1: Backup

Step 2: Disable plugins

Step 3: Update from Dashboard

Step 4: Reactivate plugins

Step 5: Test

All seem OK for now, please let me know if you find anything broken.

I don’t see any real changes.
rb-

Switch to our mobile site