Showing posts with label Social Splinter. Show all posts
Showing posts with label Social Splinter. Show all posts

Friday, November 11, 2011

Report: FTC Nears Deal with Facebook For Opt-In Privacy Changes

Via Threstpost.com -

The deal will settle an FTC case alleging privacy violations on the social network by forcing users to opt in to any changes to default privacy settings, according to a report in the Wall Street Journal.

The FTC inquiry dates back more than two years, and followed changes to the default privacy settings that pushed some formerly private user information into the public domain, the Wall Street Journal reported. Despite efforts to quell controversy over its privacy policies since then, the company has repeatedly ired consumer advocates and some members of Congress since then. In September, Facebook pushed out changes to its 800 million members that made it easier to share information with their Facebook network and made it easier for applications that run on the platform to track and share users activities, as well.

Following the change, users noticed that the company was collecting data not only when users were logged on, but also when they were visiting other sites online, by way of a Facebook plug-in that continued to operate even when there was no active Facebook session. Congressmen Ed Markey (D-MA) and Joe Barton (R-TX), co-Chairs of the Congressional Bi-Partisan Privacy Caucus, sent a letter in September to the FTC to investigate the company's use of tracking cookies.

The exact terms of the rumored settlement aren't known, but reports suggest it would go a long way towards ending those kinds of practices. For one, Facebook would submit to independent privacy audits for 20 years settlement and to get user consent before making retroactive policy changes to its privacy. The agreement will not require users to expressly agree to all changes and feature additions on the site.


-------------------------------------------------------

Opt-in = good (for changes that might negatively impact your privacy level on FB).
Opt-in = bad (for changes that would improve user security, e.g. Default SSL Enabling).

Monday, October 3, 2011

Facebook and Websense Partner to Protect Users from Malicious Links

Via WebSense Security Labs -

Today, we have some exciting news. Some of you may have already heard about it, because it is big!

Starting today, we have implemented a partnership with Facebook, arguably the largest, most important platform on the globe, to better protect users against malicious links leading to malware-embedded websites and fraud.

A platform as popular as Facebook is naturally a target for attackers. We have been working with Facebook and their security teams for a number of years in order to keep their users safe, but now we have integrated directly into the platform for an unprecedented security combination.

Soon, when a user clicks on a URL that has been posted within Facebook, that link will be sent to Websense for security classification. The Websense® ThreatSeeker® Cloud, an advanced classification and malware identification platform, will then analyze the link in real time. If the destination site is considered unsafe, the user is presented with a warning page that offers the choice to continue at their own risk, return to the previous screen, or get more information on why it was flagged as suspicious.

In this way, we are helping Facebook continue their proactive fight to keep malicious links off of their platform and allow safe use for all of its members.

At Websense, we are all about innovation and changing the security game. We were the first company to promote and enable our customers to embrace safe, productive use of social with our web security gateway, the first to deliver security and anti-spam to protect companies presence within Facebook with Defensio, and now we are assisting in the protection of all users on the platform with our cloud integration.

[...]

For more information, you can view the news release here.


-----------------------------------------------------------

Kudos to Facebook for making a serious move to protect its users against malicious scams and links on the FB platform.

This should be pretty effective against the basic scams and malicious stuff that are so pervasive on the platform right now.

But it is also possible this will force the current FB platform attackers to move toward more complex scams and malware attacks on the FB platform - as they look for a way to counter the protection offered by Websense.

Thursday, April 14, 2011

New Malware Can Automatically Register Facebook Applications

Via Symantec Blog -

A few months ago, at least prior to February 7th, Sality operators pushed a new malware onto their P2P network of infected bots. The malware in question hooks into Internet Explorer using its standard COM interface, and gathers credentials submitted via web forms. February’s variant treated Facebook, Blogger, and Myspace logon information differently: on top of stealing and sending the username/password to a Command and Control (C&C) server, the information was also dumped to an encrypted file, onto the user’s compromised computer. At that time, the plausible guess was that these credentials would be used by upcoming malware – the Sality programmers are very imaginative.

This was confirmed last weekend. The newest Sality package contained a new malware, on top of their usual spam/web relays. The malware searches for encrypted files containing either Facebook or Blogger credentials (Myspace is left aside). If such files are found and contain credentials, the malware then connects to a C&C server (74.50.119.59, hosted in Florida) to request an “action script”. Such scripts look like C programs and are interpreted by the malware itself. The main goal is to automate Internet Explorer actions.

[...]

The function names are self-explanatory. The script, when executed, performs the following actions:
  • Create a visible instance of Internet Explorer.
  • Navigate to facebook.com.
  • Log in.
  • Go to the Facebook app #119084674184 page: this application, named VIP Slots, has been around for a few years.
  • Grant access to this application.
  • Close the browser instance.
The permission required by VIP Slots is only “Basic information”, meaning your name and gender, profile picture, networks, and list of friends. The application itself does not seem to exhibit malicious behavior, but the fact that a malicious program interacts with it is very troubling. The end-goal is not determined at this stage: registering the user could serve as aggressive spamming (application posts appearing on your news feed), or a way to get more users to use the app, for monetary purpose (by buying virtual credits). The application could simply be an innocent party.

Another script was also distributed. The actions taken by this generic script were the following:
  • Create an invisible instance of Internet Explorer.
  • Go to google.com.
  • Search for “auto insurance bids”.
  • Close the browser instance.
This script could serve experimentation purposes. It could also be a very convoluted way to measure the propagation of their creation: Google Trends report a recent peak for this search term.

As of today, it appears script distribution has stopped. However, new scripts could be distributed in the future as the C&C server is still up and running.

Tuesday, February 8, 2011

Syria Opens Facebook, YouTube for First Time in Five Years

Via theatlantic.com -

The Syrian Telecommunications Establishment (STE), Syria's state-owned Internet Service Provider (ISP), asked distributors to remove the firewall that blocks access to Facebook and YouTube. The changes should come into effect at some point today.
Read the full story at The Next Web.

---------------------------------------------------------------

While this is positive news, one must ask - "Now that they are open, how OPEN are they?"

Just because a user can get to a site, doesn't mean they can get to all content on said site - enter DPI and increased stealth censorship.

Wednesday, February 2, 2011

Facebook HTTPS Fail

According to Michael Brennan (@brennan_mike)...

http://twitter.com/#!/brennan_mike/status/32859085120471041
Facebook HTTPS fail. If you use an app that doesn't support it, FB asks you to switch to HTTP and then reverses your default HTTPS setting.
----------------------------------------------------------------------------

Since I use very few applications in Facebook, I am unable to verify his claim. However, there has to be a large number of FB apps which don't use SSL, so it makes sense they might work around that fact in this manner.

This could result in users unintentionally modifying their HTTPS setting to a less secure settings (aka disabling it).

With that being said, it is still recommended to enable HTTPS for Facebook, if you haven't already done so.

The checkbox can be found at: Account (at the upper right corner) --> Account Settings --> Account Security --> Secure Browsing (https)

Saturday, January 29, 2011

How Facebook Ships Code

Via FrameThink Blog -

I’m fascinated by the way Facebook operates. It’s a very unique environment, not easily replicated (nor would their system work for all companies, even if they tried). These are notes gathered from talking with many friends at Facebook about how the company develops and releases software.

Wednesday, January 26, 2011

Facebook Beefs Up Security With Full-Time HTTPS & Social Captchas

Via techcrunch.com -

Facebook is introducing two new measures to beef up security: expanding HTTPS connections as an all-the-time option and using social captchas to authenticate users who have lost passwords. Let’s take these one at a time.

HTTPS is a secure connection (more secure than plain-vanilla HTTP connections), and Facebook already uses HTTPS for when you log into an outside site through Facebook Connect and send your passwords back to Facebook. But now you will have the option to set HTTPs as the default connection for everything you do on Facebook itself.

[...]

Some app developers will need to use a new “Secure Canvas URL” so that their apps can also be accessed over HTTPS.

The social captcha feature is pretty clever. It will replace regular captchas (those slightly warped letters you are asked to re-enter to prove you are human) with a picture of one of your friends. You will need to identify the person to authenticate yourself when you are trying to retrieve a lost password or Facebook detects suspicious login activity on your account. You do know what all your “friends” look like, don’t you?


---------------------------------------------------------------------------------

Overall, I think this is a very positive step, but one of my friends said it best - "a security feature that has to be enabled will never be used by the masses. A for effort, but C for implementation."

Long story short, he is correct. When security is opt-in, people are less likely to do it, for various reasons.

Hopefully this is just the first step.

Google rolled out SSL to Gmail users in the same way. First it was an option, then it become default.

Let's hope Facebook will follow suit...and just in case that isn't in their roadmap, the security community should applause this change, but contiune to push for more.

Monday, November 29, 2010

How Facebook Applications Can Download All the Messages in Your Inbox

Via Fobes.com (The Not-So Private Parts) -

When Facebook rolled out its new Messages feature earlier this month — combining emails, chats, and SMS messages in one inbox and offering people @facebook.com email addresses — security engineer Joey Tyson tweeted, “Do you really want all your e-mail, IMs, and texts combined with all the data Facebook already has about you?”

SomeEcards expressed it different (at right): “One benefit to Facebook’s new email system is that your privacy can now be violated all in one place.”

One privacy protection model is to scatter your data about to make it more difficult to parse, akin to keeping valuables in different hiding spots in your house to thwart intruders getting everything in one go. For this reason, some people may be uncomfortable making Facebook their one-stop-shop for photo sharing, friend accumulation, and email storage. Another issue that may give the privacy-conscious pause is the fact that a Facebook permission exists that gives application developers the ability to download the content of your inbox…

[...]

If a user gives an application the “read_mailbox” permission, that application can have a field day with your private communications — downloading the content of a message, when it was sent, who it was sent to, etc.

[...]

The read_mailbox permission is not some kind of security oversight on Facebook’s part. “As with many products, we opened up an API for messages to make it possible for developers to create new opportunities on top of Facebook products,” says a Facebook spokesperson. “For example, with the messages API, a developer could create an application that people could use to read their Facebook messages directly from their desktop.”

She reiterated that an application can only rifle through a Facebooker’s messages if he or she “grant[s] expressed permission for the application to access his or her inbox on their behalf. And they can end that connection at anytime.” A recent post on the Facebook Developers blog reassures developers that they’ll still be able to access users’ inboxes with the permission with the new Facebook Messages.

Facebookers, here’s another reminder to pay attention to what an application asks permission to do when you add it to your Facebook page. And to think twice before deleting your non-Facebook email accounts.

Thursday, October 14, 2010

Facebook Users Can No Longer Delete Chat History

Via MSNBC.com -

It's starting to feel like anyone with anything to hide needs to find better hiding spots. For instance, people trying to keep their Facebook chats from prying eyes best find another IM program, because they can no longer erase chat history.

I discovered this while chatting the other day. Anyone who's ever IM'd knows those conversations can go all over the place, and frankly, I like to think of each conversation as a fresh start.

Nick O'Neill on AllFacebook also noticed, and linked to a forum where there are 132 posts complaining about the removal of the popular feature.

Sheesh, what's with this need to keep things? We just found out yesterday "deleted" photos stay on Facebook servers far longer than we ever would have imagined. Now, we find out conversations linger, too.

It used to be there, under your the thumbnail of your profile pic, in the chat box, a link that said, "Clear Chat History." It's been a feature since Facebook launched its chat program in April 2008. Now, our profile pics follow us on the chat as our avatars instead of our first names and that link is gone, to the great consternation of some Facebook users.

---------------------------------------------------------------------------------------------

Instead of using Facebook chat, I would suggest using Pidgin on Windows along with the Off-the-Record (OTR) plugin.

OTR uses a combination of the AES symmetric-key algorithm, the Diffie-Hellman (DH) key exchange, and the SHA-1 hash function to provide authentication, encryption, perfect forward secrecy and malleable encryption (aka deniability).

For users that prefer Apple OS, check out Adium. Like Pidgin, it supports multiple IM networks and supports OTR out of the box - no additional plugin required.

Wednesday, October 13, 2010

Facebook Offers One-Time Passwords via Text Message

Via CNET -

Facebook added several new security features today, including the ability for people to request a one-time password for use on public computers.

When using a computer on which you don't want to type in your regular password you can now request a one-time password by texting "otp" to 32665 from a mobile phone. You have to have already confirmed that the phone is yours on your Facebook account. The one-time password will expire after 20 minutes, the company said in a blog post.

Facebook is rolling the feature out gradually, and it should be available to everyone in the coming weeks.

People should avoid using their regular passwords or accessing sensitive information on public computers because the machines could be infected with keylogging programs or other data-stealing malware.

The company also announced that it will regularly ask people to update their basic account information such as phone number, extra e-mail address, and security question so that in the event an account can not be accessed there will be updated information that can be used to help prove that the person requesting access is the owner.

Sunday, October 3, 2010

UK MoD Advises Personnel to Disable Facebook Places

Via The Register UK -

Security chiefs have cautioned army, navy and RAF personnel to disable Facebook Places, over fears it could be used by terrorists to identify and track targets.

The new service could act as a "one stop shop targeting pack", particularly in Northern Ireland, they warn.

The Ministry of Defence is concerned about how it could be used by dissident Republican groups to gather intelligence on operations, as well as on the family and friends of personnel.

Facebook Places encourages members of the dominant social network to publish their location and was launched in the UK two weeks ago. Users do not necessarily have to actively use the service for their exact location to be widely shared.

An MoD advisory document about the potential threat is being circuled to military and civilian personnel in all three forces. It provides step-by-step instructions on how to disable Facebook Places using privacy settings, which it urges, although does not instruct, them to follow. To complete the lockdown, members of the forces must disable four separate data-sharing features.

[...]

The MoD calls on the forces to turn off a feature of Facebook Places called "People here now". Turned on by default, it means that all Facebook users checked in at a given location will be able to see who else is there, if they have checked in.

[...]

They also want personnel to ensure that if they do check in, intentionally or by accident, their location will not be visible to anyone. By default it is shared with their friends.

Facebook Places allows users to not only publish their own location, but also that of their friends, a feature of the service that most distressed privacy campaigners and has also caused the MoD concern. Although Facebook asks users for their permission the first time a friend tries it, the military are urged to block such requests preemptively.

Finally, the advisory document tells users how to stop third-party applications and websites getting access to location data, which by default they can.

[...]

The MoD's advisory is here (pdf).

Tuesday, September 7, 2010

Facebook Affects Students’ Grades

Via Times of India -

Students who are logged on to Facebook while studying get significantly lower grades than those who do not, according to psychologists.

A study has found that the exam results of those who used the social networking site while working, even if it was on in the background, were 20 per cent lower than non-users.

According to researchers, the findings put a dent in the theory that young people's brains are better at multitasking on digital gadgets.

"The problem is that most people have Facebook or other social networking sites, their emails and maybe instant messaging constantly running in the background while they are carrying out other tasks," the Daily Mail quoted study author Professor Paul Kirschner as saying.

"Our study, and other previous work, suggests that while people may think constant task-switching allows them to get more done in less time, the reality is it extends the amount of time needed to carry out tasks and leads to more mistakes," he added.

His team studied 219 students aged between 19 and 54 at an American university.

It was observed that the Facebook users had a typical grade point average - a score from zero up to four - of 3.06. Non-users had an average GPA of 3.82.

Those who did not use the site also said they devoted more time to studying, spending an average of 88 per cent longer working outside class.

Three fourth of the Facebook users said they didn't believe spending time on the site affected their academic performance.


--------------------------------------------------------------------------------

The sample size was small and a wide range (219 students between 21 and 54). But overall, the results aren't really shocking...people just aren't good multi-taskers.

The Myth of Multitasking
http://www.thenewatlantis.com/publications/the-myth-of-multitasking

How (and Why) to Stop Multitasking
http://blogs.hbr.org/bregman/2010/05/how-and-why-to-stop-multitaski.html

Monday, September 6, 2010

Mining Social Networks: Untangling the Social Web

Via economist.com -

Telecoms operators naturally prize mobile-phone subscribers who spend a lot, but some thriftier customers, it turns out, are actually more valuable. Known as “influencers”, these subscribers frequently persuade their friends, family and colleagues to follow them when they switch to a rival operator. The trick, then, is to identify such trendsetting subscribers and keep them on board with special discounts and promotions.

[...]

Companies can spot these influencers, and work out all sorts of other things about their customers, by crunching vast quantities of calling data with sophisticated “network analysis” software. Instead of looking at the call records of a single customer at a time, it looks at customers within the context of their social network. The ability to retain customers is particularly important in hyper-competitive markets, such as India. Bharti Airtel, India’s biggest mobile operator, which handles over 3 billion calls a day, has greatly reduced customer defections by deploying the software, says Amrita Gangotra, the firm’s director for information technology.

[...]

Of course, companies have long mined their data to improve sales and productivity. But broadening data mining to include analysis of social networks makes new things possible. Modelling social relationships is akin to creating an “index of power”, says Stephen Borgatti, a network-analysis expert at the University of Kentucky in Lexington. In some companies, e-mails are analysed automatically to help bosses manage their workers. Employees who are often asked for advice may be good candidates for promotion, for example.

Ellen Joyner of SAS, an analytics firm based in Cary, North Carolina, notes that more and more financial firms are using the software to uncover fraud.

[...]

Last year an American government body called the Recovery Accountability and Transparency Board (RATB) began using network-analysis software to look for fraud within the $780 billion financial-stimulus programme. In addition to the internet, RATB combs Treasury and law-enforcement databases to uncover “non-obvious relationships”, says Earl Devaney, its chairman. The software works very well, he says. It has triggered about 250 ongoing criminal investigations and 400 audits.

[...]

The Army Criminal Investigation Command already sniffs out procurement fraud by scanning text in e-mails. The software, developed by SRA, an American firm, can correlate numbers and phrases written in nine languages with financial databases. If a person discusses a particular Department of Defence payment with an individual not officially linked to the deal, SRA’s software may notice it.

The police department of Richmond, Virginia, has pioneered the use of network-analysis software to predict crimes.

[...]

Party plans turn out to be a particularly useful part of this picture. Richmond’s police have started monitoring Facebook, MySpace and Twitter messages to determine where the rowdiest festivities will be. On big party nights, the department now saves about $15,000 on overtime pay, because officers are deployed to areas that the software deems ripe for criminal activity. Crime has “dramatically” declined as a result, says Mr Hollifield.

[...]

Network analysis also has a useful role to play in counterterrorism. Terror groups are often decentralised, so mapping their social networks is akin to deciphering “a big spaghetti picture”, says Roy Lindelauf of the Royal Dutch Defence Academy, who develops software for intelligence agencies in the Netherlands. It turns out that the key terrorists in a group are often not the leaders, but rather seemingly low-level people, such as drivers and guides, who keep addresses and phone numbers memorised. Such people tend to stand out in network models because of their high level of connectedness. To find them, analysts map “structural signatures” such as short phone calls placed to the same number just before and after an attack, which may indicate that the beginning and end of an operation has been reported.


-------------------------------------------------------

The Telegraph UK has another related article on data mining and its affect on us all...

Makes me wonder, if we will see the development of companies that are designed to predict and tweak the predictive analysis results for an individual willing to pay the money. This would require a sort of personal data warehouse with constant feedback, leading to behavioral adjustments habits (e.g. spending habits, people in your social circle, etc) over time.

Tuesday, August 31, 2010

94% of Internet Users Befriend Unknown 'Good-Looking Woman'

Via Virus Bulletin News -

Research from BitDefender has shown that the vast majority of users of social network sites are willing to befriend an unknown, 21-year-old, fair-haired woman; many of them even shared sensitive data that could be used to steal passwords.

The researchers created the fake profile on a popular social networking site and sent a friendship request to 2,000 people (as many males as females). A small number of people accepted the request immediately, but after some persuasion, a staggering 94% of people ultimately befriended the unknown face. Among the reasons for doing so were that the woman had 'a lovely face' (53%), or that she worked in the same industry (24%). 17% of people even claimed that she had a known face, but 'couldn't remember the place they met'.

Perhaps even more surprising was that 86% of those who accepted the friendship request were working in IT; 31% even in IT security, an industry that has been stressing the risks of using social networking sites for many years.

The researchers continued their study posing as the fair-haired woman and had a two-hour written conversation with a small sample of their 'victims'. During this conversation, most victims revealed information such as their address, phone numbers or the names of their parents and pets; information that can be used to change passwords and steal identities. Many users also revealed sensitive business information.

The full report can be found here (PDF), with comments from Help Net Security here.

Friday, August 27, 2010

Facebook Alternative Diaspora Launches September 15

Via Mashable.com -

Diaspora, the much-hyped open source alternative to Facebook, will release its code to the world on September 15, but promises that its creators are just getting started.

Earlier this year, Facebook was embroiled in controversy after it made significant privacy changes. Users didn’t like having more of their information public, so they revolted.

During the height of the crisis, four NYU students decided to create an open source alternative to Facebook. Their goal was to raise $10,000 for their summer project, but dramatic interest helped them raise over $100,000 through donations. Even Facebook CEO Mark Zuckerberg donated to the project.

Since then, the Diaspora team has been mostly silent, coding away on their project. However, in a blog post earlier today, they revealed that the project is on track for release on September 15.

“We have Diaspora working, we like it, and it will be open sourced on September 15th,” the Diaspora team said in its announcement.

Thursday, August 19, 2010

Facebook Adds 'Places' Check-in Feature

Via WashingtonPost.com -

Facebook is following in the footsteps of younger social-networking sites by adding a "Places" feature that lets you share your real-world location with online friends. As company representatives explained at an event at Facebook's Palo Alto, Calif., offices and wrote in a blog post, you'll be able to tap a "Check In" button to announce your presence at a physical location to your Facebook friends. Your check-in will then appear on that location's "place page," on your profile and in your friend's News Feeds.

Your pals, in turn, can tag you as being with them, after which you can remove that tag--similar to the way Facebook's photo-tagging feature operates.

-----------------------------------------------

So basically, Facebook has copied FourSquare. But of course, Facebook has kept its past course and made some parts of Places opt-out....as opposed to opt-in. By default, your friends can check you in even if you don't check-in yourself!

Here are the three changes that I made to my FB settings...






Privacy Settings -> Customize Settings -> Things I share -> Set "Places I check in" to "Only Me"

Privacy Settings -> Customize Settings -> Things I share -> Uncheck the enable checkbox for "Include me in "People Here Now" after I check in"





Privacy Settings -> Customize Settings -> Things other share -> Select Disable for "Friends can check me in to Places"

Saturday, July 24, 2010

Hezbollah Spies via Facebook

Via Terror Wonk Blog -

In an excellent article in The Washington Times, UPI’s Shaun Waterman described a “red team” activity in which a security consultant created a false persona on Facebook that appeared to be attractive young woman who was working in cyber defense. She quickly garnered hundreds of friends in the national security community, as well as job offers and invites to conferences. In the process she gathered a great deal of sensitive materials such as inadvertently exposed passwords.

This is not a hypothetical concern – Hezbollah (long a terrorism pioneer) has already employed this strategy. According to the Israeli news site MySay:
The Hizbullah agent pretended she was an Israeli girl named “Reut Zukerman”, “Reut” succeeded during several weeks to engage more then 200 reserve and active personnel.

The Hizbullah agent gained the trust of soldiers and officers that didn’t hesitate to confirm him as a “friend” once they saw he/she is friends with several of their friends from the same unit. Most of them assumed that “Reut” was just another person who served in that elite intelligence unit.

In this way, Hizbullah collected information about the unit’s activity, names and personal details of its personnel, the unit’s slang, and visual information on its bases. This user / agent using Facebook is an example of a trend called fakebook.
The picture attached to “Reut Zukerman” was, of course, an appealing young woman (some tricks are timeless.)

Tuesday, July 6, 2010

Employees Challenged To Crack Facebook Security, Succeed

Via techcrunch.com -

Apparently Facebook noticed the slap down that the FTC gave Twitter in June because it “failed to prevent unauthorized administrative control of its system.” Shortly afterwards one of the senior engineers at Facebook responsible for SRE (site reliability engineering) challenged Facebook employees to try to compromise him and gain access to Facebook’s administrative system via information obtained from him.

They succeeded.

It took a couple of weeks though. Employees supposedly got in via his home WiFi network, says our source. The details aren’t entirely clear, and Facebook isn’t talking. What I’ve heard is that they were able to intercept data from his home network after capturing his WPA password by luring him into logging into a rogue WiFi SSID that appeared to be his own router. See here for some details on how easy this is to do.

Once his home network fell, the Facebook employees were able to monitor all his Internet activity and obtain clear text passwords, etc.

The Twitter hacks last year began with compromised personal email accounts and unfolded from there.

It’s absolutely a smart thing for Facebook to do this, and other companies should too. But if a security engineer at Facebook was compromised, even though he knew it was coming, imagine how trivial it would be for other people to get hit, too.

Now excuse me while I go camp out in Mark Zuckerberg’s back yard for a week or two and try to set up a rogue WiFi SSID. Wish me luck.

Wednesday, June 30, 2010

White Hat Uses Foursquare Privacy Hole to Capture 875K Check-Ins

Via Wired.com -

If you have checked in with Foursquare in San Francisco in the last three weeks, Jesper Andersen probably knows where and when — even if you’ve set your check-ins to be published to friends only.

Andersen, a coder who recently built a service called Avoidr that helps you avoid social network “friends” you don’t really like, figured out that Foursquare had a privacy leak because of how it published user check-ins on web pages for each location.

On pages like the one for
San Francisco’s Ferry Building, Foursquare shows a random grid of 50 pictures of users who most-recently checked in at that location — no matter what their privacy settings. When a new check-in occurs, the site includes that person’s photo somewhere in the grid. So Andersen built a custom scraper that loaded the Foursquare web page for each location in San Francisco, looked for the differences and logged the changes.

Even though he was using an old computer running through the slow but anonymous Tor network, Andersen estimates he logged about 70 percent of all check-ins in San Francisco over the last three weeks.

That amounts to 875,000 check-ins.

[...]

Andersen reported the privacy breach to Foursquare two Sundays ago — and the company admitted the bug existed. They asked for a week or so to fix the bug, and now, according to an e-mail sent to Alexander, the company is modifying its privacy settings to let users opt out of being listed on location’s web pages. The site previously allowed users to opt out of being listed in the “Who’s here now” function, but until Tuesday that button didn’t apply to listing “Who’s checked in there.”

“I’m trying to be white-hat,” Andersen said. “It definitely felt icky at times.”

Andersen confirmed the validity of his script’s findings by checking the results with people he knew. And even though his groups of friends “live in a data mining culture,” the findings didn’t sit well with all of them.

“Some were grossed out by it, and a couple of people stopped using Foursquare,” Andersen said. “One had a stalker and got creeped out by it.”

Foursquare declined to respond to two e-mail requests for comment, but in an e-mail to Andersen, Foursquare programmer Jon Hoffman thanked Alexander for bringing the issue to the company’s attention.


--------------------------------------------------

Privacy settings are great..and people really should set them to as private as possible (while keeping the service useable for your needs), but in the end...you really shoudn't trust those settings to keep your data completely private.

There is always a risk that the information will be exposed. It's best to be aware of this residual risk...and either accept it...or not.