Showing posts with label social-network. Show all posts
Showing posts with label social-network. Show all posts

Wednesday, December 9, 2009

Facebook security issues? It's the ducky's fault

Gee everybody's so friendly on Facebook ... probably too much so.

Two Facebook users, Daisy Felettin and Dinette Stonily, sent out friend requests to 100 Facebookers each, chosen at randon though concentrating on their own age groups. Between the two of them, 95 people decided to become their friends.

Except Daisy and Dinette don't exist. They were created by the IT firm Sophos to show how easy it is to convince Facebook users to reveal personal information to total strangers.

Daisy (using a photo of a rubber duck as her avatar), is known to Facebook users as a 21-year-old woman, while Dinette Stonily presented "herself" a, a 56-year-old with a photo of two cats as her avatar.

Daisy concentrated on younger Facebook users, and came away with 46 new friends. Of these 46, she got full birthdates from 89 percent of them, family/friend data from 46 percent, a town or suburb from 50 percent, a full address from four percent, and a phone number from seven percent.

Older Facebook users, when dealing with Dinette, were also quick to become friends. Of the 100 approached, 41 became friends -- but another eight approached Dinette of their own accord and befriended the cat-loving phantom. And of the 49 new friends, Dinette got full birthdates from 57 percent of them, family/friend data from 31 percent, a town or suburb from 43 percent, a full address from six percent, and a phone number from 23 percent.

Check out their names again. They're based on anagrams for "false identity" and "stolen identity."

Ugh. There are a lot of people who shouldn't be running computers.

At Sophos, they call this experiment the “rubber duck attack.” There's a purpose behind the goofy moniker, as it shows how you can gather someone’s personal info without any technical expertise, simply by working within the social network’s rules.

I can't stand Facebook. I'd rather not waste my time with it. I was ready to shut down my account when some friends -- real friends, as in people I know and like -- started contacting me there. For many of these friends, that's the online way to keep up with one another.

OK. It goes like this. Not everyone who says he wants to be your friend is really your friend. Got it? You wouldn't invite some random person into your living room just because he says he wants to "friend" you, as they say in Facebook. But then y'all already knew that.

Here's something revealing: The 46 people befriended by Daisy have an average of 220 Facebook friends, while Dinette's 49 new pals have an average of 932 Facebook friends.

I'm tired of belaboring this point: Nobody has that many friends. 

Sophos (the duck people) offer their own social-networking security tips:

  • Don't blindly accept friends. Treat a friend as the dictionary does, namely "someone whom you know, like and trust." A friend is not merely a button you click on. You don't need, and can't realistically claim to have, 932 true friends.
  • Learn the privacy system of any social networking site you join. Use restrictive settings by default. You can open up to true friends later. Don't give away too much too soon. 
  • Assume that everything you reveal on a social networking site will be visible on the internet for ever. Once it has been searched, and indexed, and cached, it may later turn up on-line no matter what steps you take to delete it.

And watch out for potential friends bearing rubber ducks.

###

Monday, November 2, 2009

Many social-media games turning into scams

I can't get into Facebook. I do have an account, though I use it more to communicate with some of my friends. And I can't see spending a lot of time on it to play the games.

I have some friends who are seriously into the Facebook games and applications. Farmville, Bejeweled, YoVille, and Mafia Wars are real popular among the people I know. I can't be bothered with that stuff myself. I go on Facebook maybe long enough to check my messages, say hello to a few friends, and log off to check my Twitter account.

At first glance the Facebook games seem to be harmless fun. I understand you play many of them in levels; you clear the first level and move up to the bigger and better stuff -- much like the old-school Mario Brothers game or Dungeons & Dragons. So far, so good.

But TechCrunch has been working on a series of articles on the social-media games, and writer Michael Arrington smells a lot more scam than score.

With a lot of these games, there are two ways to hit another level: Earn it by playing well enough to clear the level you're on, or pull a George Steinbrenner and buy a new level. With real money. Your real money.

Already you can see this coming, if you're half perceptive. The game gets you hooked. It's like any other "progressive" type of game, and I can vouch for that. I've spent many hours trying to crack the combination on FreeCiv, an open-source version of Sid Meier's Civilization. Next I know the sun's coming up, my legs are frozen in one position, my left hand is all cramped up from pushing the mouse around, and my butt lost all feeling hours ago. So I can understand that.

But crank in the buy-ins and the special offers, especially if you're frustrated at the %$&#! game and your brain is fuzzed over from a marathon session, then things get real interesting.

On Oct. 31, Arrington wrote this:

... these games try to get people to pay cash for in game currency so they can level up faster and have a better overall experience. Which is fine. But for users who won’t pay cash, a wide variety of "offers" are available where they can get in-game currency in exchange for lead gen-type offers. Most of these offers are bad for consumers because it confusingly gets them to pay far more for in-game currency than if they just paid cash (there are notable exceptions, but the scammy stuff tends to crowd out the legitimate offers). And it’s also bad for legitimate advertisers. The reason why I call this an ecosystem is that it’s a self-reinforcing downward cycle. Users are tricked into these lead gen scams ...

Here's one scam, according to Arrington:

... users are offered in game currency in exchange for filling out an IQ survey. Four simple questions are asked. The answers are irrelevant. When the user gets to the last question they are told their results will be text messaged to them. They are asked to enter in their mobile phone number, and are texted a pin code to enter on the quiz. Once they’ve done that, they’ve just subscribed to a $9.99/month subscription. Tatto Media is the company at the very end of the line on most mobile scams, and they flow it up through Offerpal, SuperRewards and others to the game developers ... nothing in the offer says that the user will be billed $10/month forever for a useless service.

Had enough yet? Here's another:

Video Professor ... users are offered in game currency if they sign up to receive a free learning CD from Video Professor. The user is told they pay nothing except a $10 shipping charge. But the fine print, on a different page from checkout, tells them they are really getting a whole set of CDs and will be billed $189.95 unless they return them. Most users never return them because they don’t know about the extra charge. Woot. Again, sites like Offerpal and SuperRewards flow these offers through to game developers ...

Slashdot, one of my favorite sites for geeky news, says this about the TechCrunch articles:

... the system is rife with scams, and many game developers turn a blind-eye to them, much to the detriment of the players and the legitimate advertisers — not to mention the games that rightly disallow these offers and fall behind in profits. The article asserts that Facebook and MySpace themselves are complicit in this, failing to crack down on the abuses they see because they make so much money from advertising for the most popular games ...

If you play these online games -- or if you're thinking about it -- I highly recommend these three TechCrunch articles, all by Arrington:

Part One - Social Games: How The Big Three Make Millions

Part Two - Scamville: The Social Gaming Ecosystem Of Hell

Part Three - Two Companies That Said No To Social Media Scams

I'm getting awfully tired of doing these pieces on Internet scams. I'd rather do how-tos and reviews any old day. You think these scammers can give me enough of a break to pursue this? C'mon guys ... at least do it for my convenience?

###

Friday, October 30, 2009

Internet reaches middle age



Although few had even heard of this Internet thing (then known as the "information superhighway" until the early or mid-1990s, it got its real start 40 years ago this week.

It was Oct. 29, 1969 when the first two nodes of ARPANET were interconnected between UCLA’s School of Engineering and Applied Science and SRI International (SRI) in Menlo Park, California. And unless you were one of the guys on the inside, you really didn't know or care.

I was a bit of a late adopter. It was 1996 when I used a noisy modem to link into an Internet provider in a nearby city. My computer was an old Leading Edge XP, with an 8088 processor, Hercules graphics card, DOS 5, and 2400-bytes-per-second modem. I used Procomm to link up, and the text-only Lynx browser to surf.

This wasn't the first time I'd used a modem. By then I was an old hand at sending text files point to point over the phone lines. I worked for a newspaper in Kingman, Arizona at the time, and generated a lot of stories from my home office in Bullhead City, 40 miles away. I'd call the publisher, Matt, and tell him to set up the computer for incoming copy, give him five minutes, then send the stuff. Soon Matt would see my text streaming across his screen, a character at a time. One of my other reporters would send me his copy from his home office, I'd edit it from home, then send it to the home office the same way. I was even able to execute commands on my home computer (the Dos-driven PC) from the MacIntosh at work, using an old-school program called Telnet.

Once I got the knack of surfing the Internet, it became a bigger part of my life. And I remember telling my parents about my experiments. Dad was already good with computers -- we'd traded software for several years -- but he wasn't sure about this online thing. A curious toy, he concluded.

At the time, Netscape was the go-to browser before Internet Explorer nuked it in market share. There were rumors that you might be able to surf on the same infrastructure that your cable TV used, and much faster than dialup. Companies began building their own primitive Web sites, and ordinary people were cobbling together their own Web sites on GeoCities (which shut down a few days ago). It was a whole new world out there, the Wild Blue Yonder.

It's been 13 years since I fired up my first Web browser (Lynx, by the way, is still available and still text-only). But a lot has changed since then. Rather than write for print, my work shows up in the ether of the Internet and many of my readers are on the other side of the world.

I've developed friendships with people I'd never met, and who live in places I've never visited. I've discovered musicians I've never heard before and downloaded their music. I've downloaded entire a lot of software and quite a few operating systems -- and asked questions about the software online. I've communicated with a Linux developer in Australia and let him know how I was able to get his system to run on computers that even he wasn't sure could be done. I've debated many a subject online. I've set up the computer to download news from several hundred sources at a time.

I'm an experimenter, and can't leave stuff alone. Besides Netscape, I've used Internet Explorer, Mozilla, Seamonkey (which is what Mozilla has become), Opera, and Google Chrome. Firefox is my most-used browser now, but I notice Seamonkey is now in 2.0 and it deserves a look.

Instead of listening to a whining modem, I go straight wireless. I have about a half-dozen places where I go to do my work -- some indoors, some outside, and I'll unpack my netbook, hit a few buttons, and talk to the world. In fact, once I left dialup I had no earthly reason to even keep a landline -- a cell phone on my hip, wireless Internet close by, a second, Internet-based phone line through Google Voice, all my communications needs are met.

Even then, I'm a bit of a primitive. My cell phone merely makes calls and sends off text messages. It doesn't browse the Web. I can send short text messages to Twitter or this blog, even an email, but my single-function LG doesn't stack up to those iPhones or Crackberries that do everything.

When you consider the all-purpose cell phones, netbooks, laptops -- and I recently read about a pen that's really a computer -- you just may see desktop computers as another dying breed. Even hard drives may become a thing of the past, what with USB thumb drives and online file storage. Some of your netbooks work with just internal flash storage and USB drives, without a hard disk in sight.

The folks at UCLA and Menlo Park had no idea at the time what they'd started.

(Screenshot: The old text-based Lynx web browser, where I made my first forays on the Internet, is still around. It's shown here with Firefox 3.5.3.)

###

You tell me: Remember your first time on line? Care to share? Use the comments section for your input.

Wednesday, October 28, 2009

Facebook password-reset email carries a virus

Sheesh!

These writers of viruses and other nefarious code will stop at nothing to spread the love. But while you can see many viruses coming a mile away, I understand this one looks official.

This one, a Trojan horse dubbed Bredolab, comes dressed up as a "Password Reset Confirmation Email" from Facebook. In the email you click on the link to -- you think -- get your new password. That's when the fun -- if you can call it that -- starts. That link downloads system-destroying files, such as rogue "anti-spyware" programs that inject their own spyware, into your computer.

Considering some of the problems Facebook has been encountering -- partly from increased traffic and partly from its own recent redesign, this email almost sounds plausible.

I haven't seen this one myself; I got the details from Mashable! and MXLab.

According to MXLab, here's the body of the message:

Hey vguysville ,

Because of the measures taken to provide safety to our clients, your password has been changed.
You can find your new password in attached document.

Thanks,
The Facebook Team


Here's the drill. If you see something like this from Facebook, watch out. It's probably not from Facebook. Bear this in mind:

- If you didn't request a password change from Facebook, you have no reason to receive a reset confirmation. Don't bother opening it; dispose of it immediately.

Enjoy your computer, don't be skeered of the virus bogeyman, but be wary when you go online. Cool?

###

Tuesday, October 6, 2009

Phish tales: My Twitter, 1000s of Hotmail accounts hijacked

I'm fairly new at this Twitter thing, and I'm still prone to rookie mistakes. And for a few days, I was paying for one.

I occasionally get worthless tweets from folks about quick-and-dirty ways to build my traffic. Most of them are pure crap, by the way, but while some are harmless crap, others are more nefarious. I came across one -- GET 1000's OF FOLLOWERS, with a link. OK. I could smell the crap all the way from here, but I thought I'd take a look at it to, well, see what was going on. Research purposes, you understand.

I clicked on the link and immediately got the warning that the site was possibly one for phishing. For those who don't know what that is, phishing is when someone is trying to harvest information from you. Valuable information that you wouldn't give out otherwise. Like a password.

As soon as I saw that warning, I clicked on it to basically abort the mission. Supposedly, that was the end of that.

Not so. Soon after that, I noticed I had been making some real strange tweets, or more correctly, some jerkface was sending them out under my name. Every day. There would be some message credited to me, advertising some "service" that gives you thousands of followers. Or something. In social media, followers and friends are the coin of the realm. The more followers you have, the bigger your network and the more valuable your site. I use Twitterfeed to link my writing directly into Twitter, and all of my followers (right now about 40 of them) gain access to my work.

Soon I noticed these posts linking to the phishing site started going out every day, with the link and my name on them. Some idiot hijacked my Twitter account, and I became a spammer.

I tried a few quick damage-control measures. Blocking the original source of the link. Adding a disclaimer to warn followers away from that link. Part of that was saving face -- letting my followers know it wasn't me sending those things. And the spam messages still showed up, every day.

Final analysis: There seems to be a simple fix, a real no-brainer. Change your Twitter password. I did that, and the messages stopped. D'oh!

Meanwhile, those who use Hotmail for email (I'm not sure why you'd want to) are getting phished big time. According to gHacks Technology News:

Microsoft has recently confirmed that thousands of Windows Live Hotmail customer’s credentials were exposed on a third party website. According to Neowin the account information were posted by an anonymous user at the pastebin website. The list that was posted contained over 10.000 account details of accounts starting with the letters A and B which suggests that additional lists might be in the hands of the attackers. Initial investigations suggest that only accounts used to access Windows Live Hotmail were affected (which includes email accounts ending with hotmail.com, msn.com or live.com ... Microsoft determined that the attack was not a breach of internal Microsoft data and believes that the account data was gained by a phishing attack. Phishing attacks are common ways these days to lure users into entering their account data on websites that look like the real deal but are not ...

Again, the gHacks-prescribed fix is a simple one: Change your password. Now.

There are a few before-the-fact and after-the-fact ways to protect yourself here:

Changing your password is the best back-end fix, though it is a pain in the butt. Even more painful now, when you access your accounts through a third-party application or site. For me, this meant changing the passwords on TweetDeck and Twitterfeed. As I write this, I'm pretty sure I haven't checked if my feed on this blog has been fixed yet; probably not. Note to self: Fix.

I haven't really checked it out yet, but there's a program called lastpass that's supposed to make it easy. It was mentioned in the gHacks piece, so I downloaded it and will give it a go. Might have something to write about there; stay tuned.

Also, the other standard self-protection rules apply. Don't click on Twitter links unless you know the source. Pretty much the same rule as opening email attachments. I know I'm screwing myself here, as I get a fair bit of blog traffic through Twitter. But y'all pay attention to what the link is. If the link is attached to a blog post (in my case it's prefaced with a COLUMN or WORKBENCH) it'll be OK. Those attachments will only mess with your mind, not your computer or Twitter account. If the preface is something like GAIN ZILLIONS OF FOLLOWERS, MAKE MILLIONS WHILE SITTING ON YOUR BUTT, or LOSE 20 POUNDS OF DANGEROUS UGLY FAT WITHOUT CUTTING OFF YOUR HEAD, the link is probably real sketchy and you'd do well to ignore it. But you don't need me to tell you that.

This last is going to require some extra vigilance, as so much Twitter traffic involves passing links back and forth. Especially mine. Looking at the last 40 tweets from my network (representing about two hours), 31 have clickable links. Most will refer me to a blog post or a news story. This is probably disproportionately high, as many Twitter users merely use the account to keep track of some friends. Mine actually doubles as a news feed, so I'm going to have a higher percentage of links.

Sometimes it's tempting to cut all cords and wireless, eschew all technology, and go back to quill pen and foolscap. But that's not an option, not if I wish to function in today's hooked-up dialed-in world.

###

You tell me: What protective measures are you employing here? What works? What doesn't? Do you have any horror stories you wish to share? Use the comments section below.


Wednesday, September 23, 2009

Twitter's appeal: People love the mundane

I'll have to admit, this Twitter grows on you.

A couple of years ago, I hadn't even heard of Twitter, and even a year ago I wondered what the point of it was.

Twitter is called a "microblogging service," which allows one to post whatever he wants online, as long as it's no more than 140 characters. Twitter basically asks the question, what are you doing now?

And most of the posts (called "tweets" in Twitter parlance) indicate that a lot of people have no real life, and should stay away from computers. I mean, how many posts about the mundane can you endure?

It's this mundane stuff that seems to be much of Twitter's appeal. And, it's become huge. According to ComputerWorld, people are tweeting from the car, the theater, from restaurants, even from the can. But, the Helsinki Institute for Information Technology studied these short messages -- actually from Jaiku, a microblogging platform that Twitter is practically edging out of existence -- and suggests most of the posts are beyond inane. And the Oxford University Press studied 1.5 million "tweets" and came to the same conclusion.

Newsweek columnist Daniel Lyons calls Twitter "a playground for imbeciles, skeevy marketers, D-list celebrity half-wits, and pathetic attention seekers," citing folks like Shaquille O'Neal, Kim Kardashian, znd Ryan Seacrest as regulars in TwitLand.

"It's morbidly fascinating, kind of like the forbidden thrill you get watching Maury Povich's show or professional wrestling," Lyons wrote. "You know it's awful. You know you shouldn't enjoy it, yet you can't look away. That, I'm afraid to say, is why I've come to believe that, of all the hellish things that have been spawned in the fever swamp that is the Internet, Twitter may turn out to be the most successful of them all—not in spite of its stupidity, but because of it."

Lyons said that one recent study -- though he didn't cite it in his article, so the findings are immediately suspect -- said that 40 percent of tweets were "pointless babble." Only 40 percent? My own study, using a time-honored methodology called "pulling numbers out of my butt," suggests close to 70 percent of tweets are mindless, worthless wastes of server space.

Shoot, I don't want to know what you're having for dinner, unless I'm invited. I personally don't give a rip that you're going to the bathroom now, and I REALLY don't want to know how it came out. Are we on the same page here?

Twitter is one of those things where the machine is invented first and you find out what you can use it for later. And, so far, a few put it to good use. It was someone on Twitter who brought us up to speed, real-time, on the election protests in Iran a few months ago. Someone else used the microblogging service to send us the first pictures of that plane crash in the Hudson River in January, the one where the pilot did such an incredible job of keeping all his passengers alive.

I've picked up a few blog ideas from tweets, and some interesting reading has come my way through Twitter. A few job leads. And, I notice businesses use Twitter to introduce product lines, throw out ideas, you name it. Used properly (and I'm sure there's a trick to it), one with good leadership chops can build his own ready-made parade to get in front of.

When you do the Twitter thing, you find out who else is using that service, and you may elect to "follow" a person. Or someone else may opt to follow you. For a minute that seemed too strange for words, like I'm being stalked or something. But that's how word about something can get out quickly. I have a mixed bag of followers on Twitter. Most are legit, the kind of folks I wouldn't mind chatting with over some coffee. But other followers are nothing but smarmy hucksters with an agenda. But since I'm the one making the tweets, I'm calling the shots. I'm pretty selective about who I follow, but am less discriminate about who chooses to follow me. Hey, if the sketchier followers click on the link and make it to this article (and if they're not easily offended), we're all cool with it.

Admittedly, I wasn't really sure what to do with my Twitter account once I opened it. I used it for a while for short, newsy items via text message directly into a sidebar on one of my blogs -- like dispatches from last November's election -- until I found out how to post directly to the blog from my cell phone. But after that I figured out how I can use Twitter.

I'm finding it another vehicle for getting word out on my blogs. Both -- The Column, Reloaded and The Workbench, Reloaded -- automatically drop links into Twitter through a service called Twitterfeed, so you can open my prose directly from there. As soon as I started using that, my readership jumped considerably.

Occasionally I'll send out a tweet on something else I'm working on, sort of a teaser for this blog. I've done this from the computer, and often via text message from my phone. (If you see a ~E at the end of a tweet -- or a short blog entry -- it means I turned my cell phone into remote control. I love showing off.)

Ooooh, I'm doing something really stupidly mundane now, and I've got to let my followers know all about it. A 140-character review to follow.

(Lest I forget: Follow me on Twitter!)



Saturday, September 19, 2009

People may pay $100 bounty to crack your Facebook account

It's a jungle out there.


... security vendor PandaLabs has discovered an online service offering to help those so inclined to hack into any Facebook account they choose for a price: $100 ...

Be careful out there!

A totally peripheral note: Must these idiots be referred to as "hackers?" Ask anyone in the programming community, especially those folks who create some really good free software. They call themselves hackers, and it's not the same thing. Hackers build things, they say, while "crackers" tear things down.

About YOU