Facebook evolves into an attack tool for criminals

As Facebook evolves from a University Alumina network into an enterprise tool, VeriSign iDefense security experts are warning that the platform is turning into a prime attack vector for cyber-criminals.

Ryan Olson, US-based analyst for VeriSign's iDefense malicious code operations, told ZDNet Australia that the thousands of new applications being developed for Facebook users, whilst enriching functionality, present a perfect channel for distributing malware.

"The potential is there and all the framework is there," said Olson.

Facebook founder Mark Zuckerberg said in June: "Rather than putting it in our terms of service that you promise not to breach our security and putting the onus on us. We are just going to open it up slowly over time."

"You use such developer applications at your own risk," Facebook states on its privacy statement.

While Facebook third-party developers are not party to the FaceBook member's personal details, agreeing to install an application is ultimately a caveat emptor scenario.

Adding pressure to the rush to develop new applications for Facebook PayPal is running a competition which closes on August 24, offering developers cash prizes up to AU$10,000 for winning applications.

Developers require users to agree to their own terms of service and privacy policies as a condition of using their applications. Given the tendency by users to gloss over lengthy condition statements, this opens the possibility for developers to extend rights beyond the standard agreements.

However, Olson and Rick Howard, director of intelligence at VeriSign, said a longer term problem is users openness with personal information on public forums.

"They seem to have no sense of privacy," said Howard. "We think it could go two ways: In the future they're either going to decide they're embarrassed by all the information they've put out there or they may decide it's just the way it is and it's ok to put information out there".

In a "thought experiment" the two conducted in the US before visiting Australia, Howard said they managed to acquire enough information on one young user to steal her identity.

"We pulled down one person's name -- in this instance a female -- and everything she put out there," said Howard.

"In 15 minutes of doing Google searches, we were able to collect enough information to steal her identity."

So what can users do to protect themselves in this candid new world?

"Best practice, really. Don't let information out like that," said Howard.

He said that the "intoxicatingly interesting" nature of social networking is inherently at odds with best practice.

Advertisement

Talkback 1 comments

  1. US not AU Mountain/\Ash -- 01/08/07

    You said the prize money was "to AU$10,000 for winning applications".

    Following the link, this is USD$10,000 and it's not even open to Australians.


Latest Videos

ZDNet's CIO Vision Series

Department of Defence | Greg Farr, CIO (part two)

In the second part of his interview, Defence CIO Greg Farr talks about outsourcing, the skills crisis and reveals his most urgent IT priority.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Angus Kidman I'm a celebrity, don't back me up
    Celebrity comes with its perks — free alcohol, better-looking partners, lots of holiday time — and disadvantages — constant media intrusions, being forced to appear in films with Eddie Murphy for the long-term good of your career, and having to do mindless radio interviews with angry men who've been awake since 4am.
  • Array Lies, damned lies and telco stupidity
    Earlier this month, Telstra put out a press release trumpeting that it's come up with a new phone coaching service to help people who are "bamboozled" by their mobiles. Another excellent example of wrongheaded thinking from the mobile industry.
  • Array Dear carriers: More walking, less talking
    Sometimes, a well-placed and well-timed letter can make all the difference. Other times, it can make no difference at all — and even hurt your case. This week's missive by the Competitive Carriers' Coalition, I would suggest, falls into the latter category.
  • More blogs »

Tags

Back to top

Featured