Friday, November 5, 2010

Study: Facebook, Twitter get 'F' for security

From:
http://www.wtop.com/?nid=25&sid=2106979


November 5, 2010


WASHINGTON -- It is not as easy to prevent those with ill intent fromaccessing personal information in social networks like Facebook, Twitter and Flickr than those sites would have users believe, according to a new online study.



Following the recent creation of easily-accessible social network hacking tool "Firesheep," Digital Society, a "digital think tank," released a report card Thursday, giving scores to these sites among others.

Google got a "C," Yahoo and Amazon got a "C minus," Hotmail and Flickr both got a "D minus" and Facebook and Twitter received an "F."

"Even though the vulnerability and easy exploitation online services have been well known since 2007, the lack of mainstream tech media coverage has allowed the online industry to sweep the problem under the rug for the past 3 years," wrote George Ou, policy director at Digital Society and the author of the study.

WTOP reported Thursday that sites that implementing secure, "HTTPS" browsing can offer significantly more online protection.

With this browsing in place, Digital Society awarded Wordpress an "A." But when accessing the site without that measure, using only "HTTP" browsing, the site received an "F."

Seattle-based programmer David Butler, the author of Firesheep, claims he developed the program to encourage discussion of the overlooked flaw in these sites, hoping they will upgrade their security measures.

"The problem can no longer be ignored because anyone can use the attack to steal other people's account," Ou wrote.


Thursday, November 4, 2010

Facebook streamlines ‘stalking’

From: 
http://www.thetowerlight.com/2010/11/facebook-streamlines-stalking/



4 NOVEMBER 2010      BY JEREMY BAUER-WOLF
The term “Facebook stalking” has become relatively commonplace among social networking users, with Facebook releasing new features to aid these so called “creepers” on their mission.
Facebook Friendship Pages is the newest feature, an expansion of the now obsolete “wall-to-wall” page. With Friendship pages, users can access not only two individuals’ wall-to-wall, meaning basic posts, but also every photo they have tagged together, events both have attended, all comments on status updates and pictures, as well as all mutual “Likes,” encompassing music, movies and innumerable other forms of entertainment and subjects.
The project launched Oct. 28 when Facebook engineer Wayne Kao announced on his blog the implementation of the feature and the inspiration behind it.
“One of my favorite Facebook moments is browsing photos from friends in the News Feed after they’ve begun a new relationship, gotten engaged or gotten married,” Kao said on his blog. “It gives me a fun and meaningful glimpse of the friendship between two people I know. I realized that a similarly magical experience was possible if all of the photos and posts between two friends were brought together.”
While it may be important to note that Friendship Pages do not divulge any information not already available to those with access to both friends’ Facebooks, it does compile wall posts and events dating several years back.
Despite this, users still are uneasy.
“I understand that when you have Facebook, you obviously know what you’re putting on [it],” junior mass communication major Victor Hanas said. “You wouldn’t want to put anything you’re ashamed of, but I feel like Facebook is making this [information] a little bit too accessible.”
Friendship Pages are accessible under “Filters,” where the “Wall-to-Wall” tab used to be located, then under “Friendship Page.” From there, the user can navigate and match any two friends they wish, even if the two are unrelated. The friendship page will still show all mutual friends and “Likes.”
Beth Haller, a professor of mass communication specializing in online journalism, said that friendship pages further confuses the meaning of what an actual friendship is.
“It sounds like Facebook engineers, of all people, are thinking that ‘friends’ on Facebook means actual friends, when most of us on Facebook only have a few dozen true friends and the rest are just part of our social networks,” Haller said in an e-mail.  “So I think Facebook is working under the wrong definition of ‘friend’ if the engineers there think a program can select our ‘friends’ for pairing.”
Haller also explored the idea that keeping a historical record of the banter and memories between couples might result in upsetting results.
“It could be a fun app where they stroll down memory lane,” she said. “Otherwise, after a couple breaks up, will one member of the couple be tortured by this page being up forever? That could range from annoying to down right devastating.”
A fan page on Facebook, “Opt Out of the FB Friendship Feature,” has already formed and its members have begun spamming the link to it on Kao’s blog post.
The page takes the same stance as Haller, that Facebook has not provided the choice for users to opt out of the feature and that it has taken away ex-friends’ and couples rights to “forgive and forget.”
“That’s definitely dangerous,” freshman Dylan Lahman said. “It could really hurt for whoever is looking at it. I think it’s really weird that your entire relationship is open to the public.”
Freshman exercise major Corrie Dubyoski agreed the feature could be fine for the individuals in a relationship, but outside of that, she said the idea is gross.
“Everyone can see and comment on everything said to that person,” she said. “It’s plain creepy.”

Wednesday, November 3, 2010

In "Wild West" of Facebook sites, snakeoil salesmen abound

From:
http://www.mmm-online.com/in-wild-west-of-facebook-sites-snakeoil-salesmen-abound/article/190109/#



Matthew Arnold  November 03, 2010


Social networks are a “Wild West” of medical misinformation, a study has found. More than one in four comments on Facebook diabetes communities is promotional in nature, generally for unapproved products, Harvard and Brigham and Women's Hospital researchers said.

Though the researchers found “tentative support” for the health benefits of social media in the management of chronic disease—reporting patients sharing valuable insights into their conditions that they wouldn't get from their doctor and providing each other emotional support – the volume of dubious information raises red flags.

It could also offer a rationale for greater provision of legitimate medical information by companies through social media, proving the old PR maxim that if you're not telling your story, someone else will tell it for you—or in this case, sell your patients snake oil in place of proven therapies.

The study's authors looked at the 15 largest Facebook communities for diabetes patients and caregivers. In addition to the promotional comments, the researchers also identified “numerous instances of surveys, marketing pitches and efforts to recruit patients for clinical trials where the true identity of the poster could not be confirmed.”

The 15 sites had an average of 9,289 participants, and researchers evaluated 690 individual postings by 480 unique users. Two thirds were individuals describing their personal experiences with managing diabetes. Nearly a quarter consisted of personal info unlikely to be shared between patients and docs, such as patients discussing managing carbs from alcoholic beverages. Twenty-nine percent of posts were by patients providing emotional support to others, while 13% were providing specific feedback to info requests by fellow patients. Twenty-seven percent “featured promotional activity and first-person testimonials around non-FDA approved products and services.”

“Clinicians should be aware of these strengths and limitations when discussing sources of information about chronic disease with patients,” said senior author William Shrank, MD, MSHS. “Policy makers should consider how to assure transparency in promotional activities, and patients may seek social networking sites developed and patrolled by health professionals to promote accurate and unbiased information exchange.”

“There certainly are public health benefits that can be garnered from these sites,” added Shrank, “but patients and doctors need to know it is really the Wild West out there.”

The study was underwritten by CVS Caremark and published online in the 
Journal of General Internal Medicine.

Monday, November 1, 2010

Surprise! You are Being Bought and Sold by Facebook

From: http://www.pcworld.com/article/209444/surprise_your_facebook_data_is_for_sale.html






And not just to advertisers -- some app developers are selling Facebook's user info to data brokers. Where will it end?

Nov 1, 2010 2:00 pm
Facebook's privacy problems are like a centipede with footwear issues. "Other" shoes keep dropping, and there seems to be no end of them.


Lately Facebook's problems have been fueled by Wall Street Journal reporters peeking under the sheets to see what kind of shenanigans Facebook has been up to. That's how we learned Facebook apps have been inadvertently sharing user identities with advertisers, and the personal profiles culled from Facebook data by companies like Rapleaf can get very specific -- including names, locations, politics, and religious beliefs.


Imagine our surprise, then, when we turned to the InterWebs this morning and discovered that not only were Facebook apps sharing user identities (UIDs) inadvertently, but that some were also doing it advertently -- which is to say deliberately, on purpose, for money. Worse, app makers were selling user information to data brokers, which is a little like Charlie Sheen offering up his most intimate secrets to Perez Hilton. It won't stay in one place for long.


Once again, Facebook turned to blogger Mike Vernal to reveal the news. Vernal might be the most boring blogger on the planet; he's certainly one of the most obtuse, which is probably why they gave him the job. It takes him six paragraphs to get to the meat of the matter:


As we examined the circumstances of inadvertent UID transfers, we discovered some instances where a data broker was paying developers for UIDs. While we determined that no private user data was sold and confirmed that transfer of these UIDs did not give access to any private data, this violation of our policy is something we take seriously. As such, we are taking action against these developers by instituting a 6-month full moratorium on their access to Facebook communication channels, and we will require these developers to submit their data practices to an audit in the future to confirm that they are in compliance with our policies. This impacts fewer than a dozen, mostly small developers, none of which are in the top 10 applications on Facebook Platform.


We have also reached an agreement with Rapleaf, the data broker who came forward to work with us on this situation. Rapleaf has agreed to delete all UIDs in its possession, and they have agreed not to conduct any activities on the Facebook Platform (either directly or indirectly) going forward.


OK, a handful of app developers sold user identities to data brokers -- not good, but not the end of the world. If data brokers really wanted to, they could cull these same IDs manually by trolling through Facebook and collecting them. (Of course it's a lot faster and easier to simply buy them.)



Give Facebook points for bringing this to public attention before the media got to it first. Now subtract those points for giving us as little information about this matter as humanly possible.
Here's what I want to know:


  • Facebook has in the neighborhood of 550,000 apps. Has the company really checked the data-sharing habits of all of them? If not, how many apps have been vetted? The top 100? 200? 1,000? Which ones have been vetted, and how would anyone else know?
  • Which apps are guilty? Telling us that "fewer than a dozen" developers were involved, without telling us which ones, merely protects the guilty -- and does nothing for the people who've installed those apps and have a right to know. Even other app developers are calling for this information to be made public, because otherwise they're guilty by association.
  • What data brokers bought this information? To whom did they sell it? Are people getting targeted ads (or spam, junk mail, and telemarketing calls) as a result?
  • What does that "6-month full moratorium on their access to Facebook communication channels" mean exactly? That they will disappear from the Facebook apps pages? That they will go dark? And why six months? It's like Facebook is sending them to bed without dinner.
  • Will Rapleaf continue to scrape data from Facebook pages and include it in its profiles? Will it continue to share its data with Facebook advertisers? How cozy were Rapleaf and Facebook in the first place?
  • Where does this end? (See centipede, shoes above.)

Now contrast Vernal's statement with one of the comments attached to his blog post, which accuses an unnamed app developer of actively trying to sell Facebook users' private information to the Washington Times:


Please check in with the Washington Times about the developer who was approaching in them [sic] in early 2008 to resell Facebook user data. I ended up at a table at a conference, as this facebook app developer was trying to sell them a contract for data. I never got his name or the app---but the Washington Times' web/media team might remember him. He was specifically selling demographic information and IP addresses/locations of users to media companies so they could correlate age/sex/demographic/location for their advertisers.
This is the real issue. Is this a common practice? Does Facebook even know about this incident?


This is why I don't use Facebook apps and discourage others from doing so. I've seen too many that seem designed entirely for this purpose -- regardless of Facebook's written policies and pious statements to the contrary. I don't think the company has a clue of what's going on. For a service that claims 500 million+ members and wants to change the very nature of the Web, it's well past time Facebook got one.


Does Facebook have a clue? Weigh in below or email me:cringe@infoworld.com.


This article, "Surprise! Your Facebook data is for sale," was originally published atInfoWorld.com. Get the first word on what the important tech news really means with theInfoWorld Tech Watch blog.

Friday, October 29, 2010

Baby killed for interrupting mom's Facebook time

From: http://www.legitreviews.com/news/9319/




Posted by Joe Evans | Fri, Oct 29, 2010 - 03:31 PM




Yeah, you read it right. A 22-year-old mother essentially murdered her 3-month-old baby because its crying interrupted her Facebook FarmVille game. In what seems to be a disturbing trend, behavior as a result of addiction to entertainment on electronic devices is leading to serious encounters with the law. Just recently a woman fled with her boyfriend's PS3 because of his addiction, at which point he proceeded to run her off the road to get it back.

Tobias
A 22-year-old woman charged with shaking her baby to death pleaded guilty Wednesday to a charge of second-degree murder and faces 25 to 50 years in prison. Alexandra Tobias was arrested on charges of aggravated child abuse and murder after her 3-month-old son, Dylan Lee Edmondson, died in January. Prosecutors said Tobias admitted to becoming angry because the baby would not stop crying while she was playing Farmville on Facebook.

Tuesday, October 26, 2010

Firesheep Firefox Add-On Hijacks Twitter, Facebook Over Wi-Fi

From: http://www.pcmag.com/article2/0,2817,2371465,00.asp

By: Larry Seltzer
  • 10.26.2010

If you didn't already know that plain HTTP sessions are utterly insecure, here's proof: A new Firefox addin named Firesheepcaptures sessions on open Wi-Fi networks and goes one step more sinister. It finds users logged into Facebook, Twitter,Google, Amazon, Dropbox, Evernote, Wordpress, Flickr, bit.ly and more, and lets you take over their sessions and become them.
This isn't revolutionary in any way. Session hijacking in HTTP is oldnews, but it may never have been this easy before. For Windows users it's a bit harder, as they have to install WinPcap, a packet capture library, but it's still not much of a barrier. An OSX version is also available.
What can you do? Don't use open, unencrypted Wi-Fi networks or, if you do, use a VPN on them. At the very least, use HTTPS sessions on open networks. Hat tip to TechCrunch for suggesting Force-TLS, another Firefox extension that forces Firefox to use HTTPS (TLS) connections from certain sites.
Many of these sites offer TLS (HTTPS) connections, but don't default to them. Support can be flaky: Facebook on TLS has no chat available. What's up with that? Some services, like Gmail, have moved to all-TLS all the time.
I don't think there's any particular reason why Firesheep should be limited to Wi-Fi networks. Regular wired Ethernet connections aren't encrypted by default either. I'll research this and report back.

Saturday, October 23, 2010

Your Facebook post could come back to haunt you

From: http://www.9news.com/news/article.aspx?storyid=159329&catid=188

October 22, 2010


Ben McKee


DENVER - Remember that time you said you were mad at a co-worker and posted a nasty comment about them in your status update?



Hey, most of us have done silly stuff on Facebook, and many have said things that, perhaps, were not 100 percent truthful. But in the court of law, and in the public spectrum, those Facebook and Twitter posts could be taken as evidence of your character. They could even get you fired.


According to Gloria Allred, a high profile attorney, there are many social media nightmares and scares out there that are real, and not simply 'what if' scenarios. In some cases, something as seemingly harmless as a 'Tweet' has led to the breakdown of a relationship.


One such social networking scare was about a homemaker who had a fight with her husband and took it out on him online.


"She had a fight with her husband, her three young children, her dog was sick, and she posted online, 'I wish I were dead,'" Allred said. "She ended up being put in a psych[iatric] ward, and had to prove to her children she wasn't a danger to herself. And now, she's considering a divorce! That is a social networking horror story!"


No kidding, it is a horror story. But it is also a real one, just like that terrible day you had at work earlier this week. Employees should be cautious when posting their thoughts and feelings about work, particularly in the service industry. Employers looking for customer service can find out all they need to know about current employees' thoughts at work in a status update.


"Another [horror story] involves a waitress who posted on her Facebook page derogatory comments about the restaurant's customers. The employer confronted her with [that] Facebook page, and she ended up being fired for that," Allred said.


According to a survey conducted bywww.lawyers.com, 40 percent of those surveyed thought they could be fired for their comments made online. Meanwhile, 53-percent of those surveyed thought they should not be able to be fired for what they say online. Truth is, if you don't have a contract, the employer can, generally speaking, fire you for what you say online.


Another thing to keep in mind is how a 'Tweet' or a status update might affect your public image when you are in the spotlight, whether that's as a juror or before the podium as a defendant.


"If you're ever in a court of law, and you are a witness, let's say you testify that you've never done drugs or never had any alcohol whatsoever. Then the other attorney finds that on your Facebook page from when you were in college, maybe there is a photo of you drinking and doing drugs. They can use that in the court of law and challenge your credibility, and you may end up losing the case as a result!" said Allred.


Finally, it is important to know millions of sets of eyes can be viewing what you are saying online, even if you think what you say is private. Facebook allows users to 'Like' businesses, viewpoints and statements, which also opens up an opportunity for you to make an opinion public. Be careful about language or candor in those posts, because it could one day be seen again. Worse, it could go viral.


That's what happened to a former Duke University student recently, who posted her "sexcapades" online with sexually explicit images. While she thought she was just posting it to a few friends, it went viral and became a social networking horror story.


Truly, just like those old yearbook photos you were tagged in last week, those status updates, pictures and thoughts can come back to haunt you.

(KUSA-TV © 2010 Multimedia Holdings Corporation)

Wednesday, October 20, 2010

Does Apple Want to Buy Facebook?

From: http://www.cultofmac.com/does-apple-want-to-buy-facebook/64496

By John Brownlee, Oct. 19, 2010



Over the weekend, Steve Jobs and Mark Zuckerberg met for some dinner, and smart money would rest on the bet that they were trying to work out some sort of deal where  Facebook and Ping come together at last.
But could Apple’s interest be far more bold than merely ironing out some differences? Peter Kafka over at All Things D certainly thinks so: he speculates that Apple may want to buy Facebook outright with its $51 billion in cash reserves.
Here’s Kafka’s reasoning. Asked by Jobs what Apple intends to do with all of its cash, Jobs responded: “We firmly believe that one or more unique strategic opportunities will present itself to us, and we’ll be in a position to take advantage of it.” As Kafka sees it, Facebook’s a good bet for such an acquisition.
It’s potentially a strong investment: the grand vision of Facebook is a centralized Internet with the connections voluntarily self-mapped between users and advertisers. As such, Facebook’s competing directly against Google, which favors an algorithm-based approach to the same end. Buying Facebook would make Apple a credible threat to Google as the de facto author of the future Internet’s Manifest Destiny… and pay off big in advertising money down the line.
Interesting food for thought, at any rate, but my guess is that Zuckerberg is in this for the long haul. Either Facebook topples Google as the most important internet company out there, or it becomes the next MySpace. In his own way, Zuckerberg is just as much as a visionary as Jobs: I doubt simply cashing out for the money is really in Zuckerberg’s cards.

Crooks use Facebook to look for prey

From: http://newsinfo.inquirer.net/breakingnews/infotech/view/20101020-298815/Crooks-use-Facebook-to-look-for-preys-police-warn

By Abigail Kwok
10/20/2010



MANILA, Philippines—While police search Facebook to hunt down crooks, criminals too have found the socialnetworking site an easy venue to scour for preys.
Cyber-attacks range from identity theft to kidnapping, and even rape.
With the Philippines ranking 8th in world in Facebook use, the Philippine National Police issued safety reminders to Facebook users.

• Hide yourself from Facebook 
search result

Police said setting one’s account so that it is not publicly visible will help protect Facebook user from cyber harassment and security threats.

“If you do not want others to find you, change your username into your middle name if you are married. You may also go to privacy settings and click the view setting from ‘everyone’ to ‘friends’ or select ‘customize’ to make your settings even more private,” the PNP said.

The PNP added that users should only add people that they know and refrain from adding strangers.

• Limit your Personal Information

This will protect users from crimes such as stalking, kidnapping, and harassment. Police have advised users that personal information should only be made available to friends and those you know.
Facebook users should not provide the year and place they were born “because you have just given the identity thieves a key in stealing your financial life, police said. A study showed that the date and place of birth could be used to predict most and sometimes all of the numbers and passwords you are using.”

Users are also advised not to post their mobile phone numbers, landline numbers and home address.
Photo albums should be set to private and users are asked to avoid posting pornographic photos and videos.

• Avoid chatting to people you don’t know

This may cause sexual or cyber harassment. The PNP said, “Chat or talk only to those whom you really know. Change the topic if you sense something unusual or better yet, try not to chat with the person anymore.”

When joining groups, users are advised to be wary of “spam” accounts as this may expose one’s personal data to the public. .

When using 
applications like Farmville, users should also be wary and not divulge any personal information such as bank accounts.
• Never forget to “Sign Out”

“Otherwise, your account will be lost and you will not be able to open it because the password has been changed already. And it will be used for some purposes beyond your control,” the PNP said.

“Facebook is a tool used for good and bad reasons. Like a gun, it is used for good and bad purposes,” the PNP stressed.

Users who are being harassed via Facebook are advised to immediately report the incident to police.