Tag Archive for FB

10 Security Reasons to Quit Facebook

10 Security Reasons to Quit FacebookJoan Goodchild wrote an article for CSO Online that said Baby Boomers quit Facebook faster than they join based on information from Inside Facebook. The data indicate that after a huge growth in Facebook membership among the over-55 age group that same demographic began to defect in large numbers, just months after signing up. The CSO Online article quotes Scott Wright, a security consultant based in Canada and runs the site streetwise-security-zone.com says Boomers leave Facebook because they have discretion.

10 ways Facebook does not allow discretion

Here are 10 ways that Facebook does not allow for discretion, driving Boomer permanently off of Facebook.

Facebook1. Your Privacy is History Mr. Wright recalled an academic claim that the notion of privacy differs widely among generations. “The 20-something view of privacy is basically that their parents not see what they are doing. That’s about it,” he said. Apparently, Facebook founder Mark Zuckerberg agrees. He claims that openly sharing information with many people is today’s social norm. He went on to say “We view it as our role in the system to constantly be innovating and be updating what our system is to reflect what the current social norms are.” Many have translated this to mean Facebook doesn’t think its users want much privacy, and the policies of the site show that view. “If you can’t maintain privacy online and off, then you can’t speak freely,” said Bethan Tuttle, an Washington-based independent consultant and privacy advocate. Tuttle says in the article that the massive and quick growth Facebook has experienced, coupled with a lack of privacy-centric leadership has left end-user privacy as casualty.

2. They don’t have your best interests in mind Tom Eston, creator of the website socialmediasecurity.com points out, the business model of Facebook and Twitter, is to make user information as public as possible to generate new ways to make money. Mr. Eston said in the article;

They are really startups if you think about it. They don’t have a true business model … Their philosophy is the more you share, the more information they have to make money with. With that in mind, can you really count on them to protect you?

And do you know just how much information you are sharing that can be used not only by Facebook, but by the application developers that create those fun quizzes and games? Wright says most people don’t. (I wrote about this problem here).

3. Frequent redesigns affect privacy settings Mr. Wright in the CSO Online article said,

Just when people figure out the privacy settings on Facebook, they go and change them again … It always seems like it is being done in everyone’s best interest, but if you really examine it, they have never done anything other than to try to get people to share more information.

Facebook redesigns often make public, and searchable, certain user information that was previously private, and many of the features you can make private are left public unless you go in and adjust your privacy settings. This is no small task, according to Ms. Tuttle, “I am really good online but it took me several tries to get my Facebook privacy settings where I needed them to be.”

Phishing4. Social engineering attacks are getting more targeted Most Facebook users have received messages on their wall asking “Have you seen this video?” or “Is this you in this photo?” By clicking on the link, the user runs the risk of being infected by malware. These are known as social engineering attacks, and they are becoming more sophisticated said Mr. Wright. “They are becoming very targeted. Even seasoned security professionals are falling for them,” he said. The more information you share, coupled with a decrease in privacy, only means it is even easier for cyber criminals to get information about you that can be used to trick you into clicking on a bad link.

5. You can’t trust the ads Most web users think advertisements are harmless, unfortunately, some contain malicious links. One common scenario involves a pop-up from the ad that claims your computer is infected and prompts you to download software to fix it. Instead of helpful software, you end up downloading something nasty. This is now commonly known in the security community as “scareware,” and it’s still a very effective way to snare unsuspecting users.

6. Spam Spam claiming to be from Facebook has increased according to the article. “I think it’s a security concern,” said Mr. Eston. “Mostly because spammers can use that vulnerability to make you think the message is coming from Facebook when it is not. Many users simply wonder “Why is Facebook sending me this?” and instinctively open the message and log in to what turns out to be a fake screen that steals credentials.

7. You don’t really know your friends The author cites a report from security firm Cloudmark which concluded that close to 40 percent of new Facebook profiles are fakes.  Having lots of friends is dangerous because it opens you up to more security risks. Mr. Wright said those who get targeted for hacking are the users who have lots of friends (here is an example). The more friends you have, the more reach a criminal will have when he breaks into your profile and sends out a bad link to everyone.

8. You can’t help yourself from being dumb The attention around the site pleaserobme.com brought to light the safety concerns around social networking. Pleaserobme aggregates the Twitter feeds of people who play Foursquare, a location-sharing application. The problem is while playing the game, many users are also publicly broadcasting that their home is likely unattended and a good “opportunity” (as the site terms it) for thieves. As Ms. Tuttle put it, you need to think about what you are doing and many people are not. You’re putting yourself out there in potentially dangerous ways, particularly if you don’t know all of your “friends” that well.

9. The great unknown CSO Online says there is a lot of speculation about a Facebook IPO and future business strategy. What does this mean for users? Mr. Wright said some fear it means an increase loss of privacy as the social networking site inevitably looks for ways to make money by offering up valuable user information to advertisers and developers. Mr. Wright said,

One of the things I find most interesting is that there are still many people who are scared to death of social networking sites. These are usually the people who don’t see value in them. In the end, they may be the wisest of us all.

Bill Clinton i angry at you for using social media

10. Ex’s, creeps and parents Facebook is making it possible for people to be cyber stalked, even if they aren’t friends anymore, said Mr. Eston. Although the physical and virtual connections are broken, having mutual friends makes it easier for your ex to keep tabs on you. The same goes for any creepy guy or girl you are trying to avoid. Or you may get a friend request from a parent, which Mr. Wright claims many 20-something users consider the worst thing that could ever happen in the history of social networking. “That is a big driver for quitting,” he said. “Once the parent friends some of these people they immediately think ‘I’ve got to get out of this!

What do you think?

Are you concerned about your privacy on Facebook?

View Results

Loading ... Loading ...
Related articles

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

AccountKiller KO’s Online Accounts

AccountKiller KO's Online Accounts AccountKiller.com says it is a website dedicated to helping social network users reclaim their personal data. The website helps users reclaim their personal data by explaining and ranking social networking sites. The website explains how to delete online accounts and ranks them by how hard it is to reclaim your personal information.

AccountKiller provides instructions to remove your account or public profile on most popular websites, including Skype, Facebook, Microsoft (MSFT) Windows Live, Hotmail, MSNTwitterGoogle (GOOG), and many more.

The creators of AccountKiller have also created a blacklist of sites that do not allow their users to reclaim their online account information.  According to the website a black-listed site indicates it’s probably impossible or highly difficult to get rid of your account. Among the sites AccountKiller has blacklisted are:

The grey-listed sites may cost you some irritation or effort – but it should be possible to terminate your online accounts says AccountKiller. These sites will require you need to send a mail to the site, send a message using a webform or even call them to recover your personal information.

The creators of AccountKiller say that social media sites purposely make it difficult or even impossible to delete your account for two reasons. First, because they are profiting from their users’ data. These sites are in the business of data customer retention.  Alternatively, they suggest that these developers may simply be ignorant, lazy, or incompetent, i.e. not being able to create some account deletion function.

rb-

Kudos to the creators of AccountKiller, I now recommend this site to anyone who has questions about these social networking sites. It is time for social networking sites to provide transparency into their real business model, data collection, otherwise, there could be a social networking bubble.

What do you think?

Do you know how to get out of your social networking sites? Can you?

 

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Tech Regulatory Capture

Tech Regulatory CaptureRegulatory capture occurs when governmental bodies created to act in the public interest instead advances the commercial or special interests that dominate the industry or sector it is charged with regulating. Regulatory capture is a form of government failure, as it can encourage large firms to exploit the public.

Former Sen. Chris Dodd Named MPAA Chief

Former Sen. Chris Dodd Named MPAA ChiefChristopher Dodd, the former five-term Democratic senator from Connecticut is the head of the Motion Picture Association of America. He sat on the Foreign Relations Committee, headed the Banking Committee, and co-authored the Dodd-Frank Wall Street Reform and Consumer Protection Act. Among other things, he attempted to filibuster the legislation that immunized telecom companies from lawsuits over the Bush administration’s warrantless wiretapping program.

As head of the MPAA, he’s likely to be a little less friendly to the average netizen. The MPAA has lobbied hard for the controversial Anti-Counterfeiting Trade Agreement.

It has pushed for the government to shutter websites suspected of hosting infringing material and is responsible for using the American legal system to sue U.S.-based torrent search engines out of existence. A case against Canadian-based Isohunt is pending.

Facebook Adds Friends in Washington

Facebook Prepares to Add Friends in WashingtonDemocrat Sheryl Sandberg, the former Clinton administration official is a chief operating officer for Facebook. Ms. Sandberg, is the company’s No. 2 official behind co-founder and chief executive, Mark Zuckerberg.

Republican Ted Ullyot, a former clerk for Supreme Court Justice Antonin Scalia is the social networker’s general counsel. Mr. Ullyot, was a White House lawyer and chief of staff for Alberto Gonzales when he was attorney general in the George W. Bush administration. Facebook  told the Los Angeles Times that Mr. Ullyot “has extremely strong connections with the Republican Party, and we think that’s a good thing.”

Facebook Adds to Its Public Policy Staff

Facebook Adds to Its Public Policy StaffFacebook increased its Republican credentials by adding Catherine Martin, who is the site’s first director of public policy. Previously, Ms. Martin worked for President George W. Bush, serving as deputy assistant to the president and deputy communications director for policy and planning.

Facebook May Hire Former Obama Aide

Facebook May Hire Robert Gibbs, Former Obama AideFacebook is in talks to hire Robert Gibbs, President Obama’s former White House press secretary, for a senior role in helping to manage the company’s communications, people briefed on the negotiations told the New York Times.

Mr. Gibbs, who left the White House in February after two years on the job, had planned to help set up President Obama’s re-election campaign before taking a private-sector job, these people said. A job for Mr. Gibbs at Facebook could be worth millions of dollars. While details of his potential compensation package have yet to be discussed, people briefed on the talks said that he would receive a cash salary as well as shares ahead of the initial offering. Some investors have valued Facebook at more than $60 billion and could be the largest offering in history. Mr. Gibbs and a spokesman for Facebook declined to comment.

Facebook Woos Washington

Facebook Woos WashingtonThe Daily Beast points out that Facebook, Mark Zuckerberg’s company has 600 million members, making it about twice as big as the United States. The Daily Beast says that Facebook needs to get as cozy as it can with the U.S. Government and Barack Obama. This company is gathering more personal information about more people than any other company ever, even more than Google. Suddenly it is dawning on everyone, including members of Congress, just how much power Facebook is amassing.

Co to counter the trend Facebook has hired two more former government officials.

  • Elliot Schrage worked at the Council on Foreign Relations and Google before joining Facebook. Mr. Schrage, a lawyer by training, serves as Facebook’s head of global communications and public affairs.
  • Chris Hughes, a Facebook co-founder, ran Obama’s 2008 social networking operation via a website called My.BarackObama.com.

$35,000 For a Dinner With Obama

Yelp Just Paid $35,000 For A Steak Dinner With ObamaAfter President Obama’s love-in speech video on Facebook, another group of tech luminaries got a meeting with POTUS. The steak dinner at the home of Salesforce.com CEO Marc Benioff cost $35,000-a-plate. According to Business Insider other Silicon Valley big-shots in attendance included:

Related articles
  • Facebook Prepares to Add Friends in Washington (nytimes.com)
  • Chris Dodd shows how Washington works (salon.com)

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Google, Facebook and Yahoo Test IPv6

Google, Facebook and Yahoo Test IPv6A global trial of IPv6 is scheduled for June 8th 2011. Google (GOOG), Facebook, Yahoo (YHOO), and Akamai (AKAM) will reportedly take part in the IPv6 “test flight.” The Internet Society, a non-profit group that educates people and companies about net issues is coordinating World IPv6 Day. Those who sign up for the test will make their pages available via IPv6 for 24 hours to help iron out problems created by the switch to the new addressing scheme.

IPv6 good news

Internet Society logo“By providing an opportunity for the internet industry to collaborate to test IPv6 readiness we expect to lay the groundwork for large-scale IPv6 adoption and help make IPv6 ready for prime time,” said Leslie Daigle, chief Internet technology officer at the Internet Society in a statement.

“The good news is that internet users don’t need to do anything special to prepare for World IPv6 Day,” said Lorenzo Colitti, a network engineer at Google in a blog post. “Our current measurements suggest that the majority (99.95%) of users will be unaffected. However, in rare cases, users may experience connectivity problems, often due to misconfigured or misbehaving home network devices.”

According to Google, Vint Cerf, the program manager for the ARPA Internet research project chose a 32-bit address format for an experiment in packet network interconnection in 1977. For more than 30 years, 32-bit addresses have served us well, but now the Internet is running out of space. IPv6 is the only long-term solution, but it has not yet been widely deployed.  In November 2010 Mr. Cerf, one of the driving forces behind Google’s IPv6 efforts warned that the net faced “turbulent times” if it did not move quickly to adopt IPv6.

rb-

Vint Cerf wants you t use IPv6It will be interesting to see the number of participants. This all may just blow over the top because not enough of the right people in organizations see the need. I spoke to my Boss about this a while ago and I think one phone call has been made to our upstream ISP to see what they are doing. We probably won’t deal with it until there is a need for a point-to-point IP video conference with China or something and when it won’t work, then it is a crisis that gets addressed.

Does your organization have a plan for IPv6 migration?

View Results

Loading ... Loading ...
Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

LinkedIn Accounts can be Hijacked

Help Net Security has a report that users of the newly minted public LinkedIn (LNKD) are in danger of having their account hijacked. The Linkedin accounts can be hacked when accessing them over insecure Wi-Fi networks or public computers. Independent security researcher Rishi Narang told Help Net Security that the risk is due to two reasons. First, the LinkedIn session and authentication cookies have an unnaturally long lifespan. Secondly, LinkedIn does not remove the cookies once the user logs out.

LinkedInThe article says the cookies in question are JSESSIONID and LEO_AUTH_TOKEN, and are available even after the session initiated by the user has been terminated. The cookies are also set to expire only after one solid year, and this fact allowed the researcher to get access to a number of active accounts of various people from all over the world during a period of many months. “They would have login/logged out many times in these months but their cookie was still valid,” Mr.Narnag writes on his blog.

In addition to all of that, those two cookies and the others that the welcome page stores are transmitted in clear text over HTTP, because they don’t have a secure flag set. “If the secure flag is set on a cookie, then browsers will not submit the cookie in any requests that use an unencrypted HTTP connection, thereby preventing the cookie from being trivially intercepted by an attacker monitoring network traffic,” explains Mr. Narang.

According to the researcher, until LinkedIn makes some changes, the only way to “expire” the cookies is for the users to change their password and then authenticate themselves with the new credentials. This could be a stopgap measure if you know that someone has stolen those cookies and is accessing your account, but won’t new cookies be created after the password change and authentication?

Help Net Security says that the only solution to this problem is for LinkedIn to effect some changes, and according to Reuters, they are planning to offer “opt-in” SSL support for the entire site in the coming months (and that would encrypt the cookies in questions), but have not commented on the cookies have such a long lifespan.

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.