News
Facebook users warned on cybercrime
ZDNet Australia
As Facebook evolves from a university social network into an enterprise tool, VeriSign iDefense security experts are warning that the platform is turning into a prime attack vector for cybercriminals.
Ryan Olson, a US-based analyst for VeriSign's iDefense operations against the proliferation of malicious code, said that while thousands of applications being developed by third parties for Facebook users are enriching the social network's functionality, the Facebook Platform provides a perfect channel for distributing malicious software.
"The potential is there, and the framework is there," Olson said.
"Rather than putting it in our terms of service that you promise not to breach our security and putting the onus on us, we are just going to open it up slowly over time," Facebook founder Mark Zuckerberg said in June.
"You use such developer applications at your own risk," Facebook states on its privacy statement.
While Facebook third-party developers do not necessarily have access to Facebook members' personal details, whether users agree to install an application is ultimately a caveat emptor scenario.
Adding pressure to the rush to develop new applications for Facebook, PayPal is running a competition that closes on 24 August, offering developers cash prizes of up to $10,000 for winning applications.
Developers require users to agree to their own terms of service and privacy policies as a condition of using their applications. Given the tendency by users to gloss over lengthy condition statements, this opens the possibility for developers to extend rights beyond the standard agreements.
However, Olson and Rick Howard, director of intelligence at VeriSign's iDefense Labs, said a longer-term problem is users' openness with personal information on public forums.
"They seem to have no sense of privacy," Howard said. "We think it could go two ways. In the future, they're either going to decide they're embarrassed by all the information they've put out there, or they may decide it's just the way it is and it's okay to put information out there."
In a "thought experiment" the two conducted in the US before visiting Australia, Howard said they managed to acquire enough information on one young user to steal her identity.
"We pulled down one person's name -- in this instance, a female -- and everything she put out there," Howard said. "In 15 minutes of doing Google searches, we were able to collect enough information to steal her identity."
So what can users do to protect themselves in this candid new world?
"Best practice, really: don't let information out like that," Howard said, adding that the "intoxicatingly interesting" nature of social networking is inherently at odds with best practices.
More about Software
- Obama in sex video shocker? Oh wait, it's just spam September 11, 2008
- No black holes from Large Hadron Collider, say scientists September 10, 2008
- Michael Moore to premiere film online September 05, 2008
- Images: Touring Google's Chrome browser September 05, 2008
- Extensions promised for Chrome September 04, 2008

- Samsung S5560 and B3410: Festive phones from Carphone Warehouse
- Microsoft security updates causing 'black screen of death'?
- 3 to let mobile-broadband punters cancel contracts over poor 3G coverage
- Twitter denies Japan plan to pay you 70 per cent for tweeting
- Google and Bing top searches of 2009: Swine flu, Facebook and the king of pop
- Gimmicks are the new megapixels: The new generation of unusual digital cameras

- Microsoft security updates causing 'black screen of death'?
- Twitter denies Japan plan to pay you 70 per cent for tweeting
- Google and Bing top searches of 2009: Swine flu, Facebook and the king of pop
- Pub fined £8,000 after punter pirates with their pint
- Virgin Media and CView to rifle through your packets
- How MySpace can beat Facebook in 2010
- Want to try the new Google homepage? We show you how
- Windows 7 Family Guy clips outed, with bonus Sugababes
- Last.fm interview: Behind the music
- Truphone talks turkey with free calls on Thanksgiving
- Man arrested for not tweeting to teeming tween tumult
- The best of Photosynth
- Seesmic Desktop for Windows: Better for Twitter than TweetDeck?
- Microsoft and Murdoch ganging up on Google?
- Spotify launches on Nokia, Samsung, Sony Ericsson phones


