ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Facebook evolves into an attack tool for criminals

Liam Tung ZDNet Australia

Published: 30 Jul 2007 08:18 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

As Facebook evolves from a University alumini network into an enterprise tool, VeriSign iDefense security experts are warning that the platform is turning into a prime attack vector for cybercriminals.

Ryan Olson, US-based analyst for VeriSign's iDefense malicious code operations, said that the thousands of new applications being developed for Facebook users, whilst enriching functionality, present a perfect channel for distributing malware.

"The potential is there and all the framework is there," said Olson.

Facebook founder Mark Zuckerberg said in June: "Rather than putting it in our terms of service that you promise not to breach our security and putting the onus on us, we are just going to open it up slowly over time."

"You use such developer applications at your own risk," Facebook states on its privacy statement.

While Facebook third-party developers are not party to the Facebook members' personal details, agreeing to install an application is ultimately a caveat emptor scenario.

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

Adding pressure to the rush to develop new applications for Facebook, PayPal is running a competition which closes on 24 August, offering developers cash prizes of up to AU$10,000 (£4,197) for winning applications.

Developers require users to agree to their own terms of service and privacy policies as a condition of using their applications. Given the tendency by users to gloss over lengthy condition statements, this opens the possibility for developers to extend rights beyond the standard agreements.

However, Olson and Rick Howard, director of intelligence at VeriSign, said a longer-term problem is users' openness with personal information on public forums.

"They seem to have no sense of privacy," said Howard. "We think it could go two ways: in the future they're either going to decide they're embarrassed by all the information they've put out there or they may decide it's just the way it is and it's ok to put information out there."

In a "thought experiment" the two conducted in the US before visiting Australia, Howard said they managed to acquire enough information on one young user to steal her identity.

"We pulled down one person's name — in this instance a female — and everything she put out there," said Howard.

"In 15 minutes of doing Google searches, we were able to collect enough information to steal her identity."

So what can users do to protect themselves in this candid new world?

"Best practice, really. Don't let information out like that," said Howard.

He said that the "intoxicatingly interesting" nature of social networking is inherently at odds with best practice.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
22 out of 23 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Trading and Derivatives Specialist, Global Financial Markets Business Development

All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, ...

Supply Chain Management Consultant - Product Lifecyle Management

All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, ...

UK Territory Manager, Enterprise Sales, Identity Management, Reading

It would be advantageous if you have experience selling security software, identity management, and/or directory technologies (or Provisioning ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation