Technology, Discovery & Innovation
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Computing Digital Life Discovery Space More Topics...
Enterprise I.T.
Average Rating:
Rate this article:  
Facebook Hijacking Points To Social-Networking Holes Facebook Hijacking Points To Social-Networking Holes
By Carl Weinschenk
November 10, 2009 2:19PM

Bookmark and Share
The nontechnical hijacking of nearly 300 unadministered Facebook groups illustrates the security issues facing social-networking sites. Dave Amsler of Foreground Security said social-networking sites like Facebook have major security issues. Facebook said the takeover of the groups was not a hijacking and no confidential information was exposed.
 



The takeover of administration rights to a large number of Facebook groups by an organization that calls itself Control Your Info is just one example of the many security issues facing social-networking Relevant Products/Services sites in general and Facebook in particular, according to experts.

Indeed, this nontechnical exploit can be called a benign example of what is at risk if better controls aren't put in place. Control Your Info hijacked almost 300 groups by simply taking over unadministered groups. Dave Amsler, the cofounder and CIO of Foreground Security, said the illegitimate administrators have access to profile information, e-mail addresses and other data Relevant Products/Services that members have provided. He pointed out that credit-card numbers aren't involved.

Hijacker Message

Control Your Info posted this message at those groups:

"Hello, we hereby announce that we have officially hijacked your Facebook group.

"This means we control a certain part of the information about you on Facebook. If we wanted we could make you appear in a bad way which could damage your image severly [sic]."

The group didn't respond to a request for an interview sent to the e-mail address at its web site.

Facebook's press-relations department e-mailed a statement which read in part that "there has been no hacking and there is no confidential information at risk. The groups in question have been abandoned by their previous owners, which means any group member has the option to make themselves an administrator in order to continue communication to the group. Group administrators have no access to private user information and group members can leave a group at any time."

Bigger Problems

The situation is evidence of significant vulnerabilities in Facebook, Amsler said. "The social-networking sites -- Facebook being the most important -- have major security issues," he added. "No one is bothering to secure anything."

He said the company seemed unconcerned when contacted. "We've reported major findings to them and their response is, 'Yeah, we know about it. There is not a whole lot we can do about it.'"

Amsler added that he agrees with the stated aims of Control Your Info -- to call attention to what critics say is an insecure Facebook environment -- but thinks the group acted unethically in hijacking groups. Still, he believes that Facebook probably will make the relatively easy, nontechnical changes necessary to prevent the hijackings.

Facebook defended its practices. "Security is a top priority for Facebook, and we devote significant resources to helping our users protect their accounts and information," according to a spokesperson. "Any assertion to the contrary is false. We think this focus on security is a major reason Facebook was recently named one of the top 10 most trusted companies in an independent survey conducted by TRUSTe and the Ponemon Institute." (continued...)

1  |  2  |  Next Page >

 

Tell Us What You Think
Your Comment:



Advertisement


 Enterprise I.T.
1.   Google May Make Gmail More Social
2.   IBM Power7 Server Takes on Big Load
3.   IBM Opens Cloud-Focused Data Center
4.   Google Apps Controls Mobile Devices
5.   Newly Independent AOL Posts Profit


advertisement
Google Attack Highlights Black MarketGoogle Attack Highlights Black Market
Paying for bug info is hotly debated.
Average Rating:
Zuckerberg's Comments BlastedZuckerberg's Comments Blasted
Called self-serving and irrelevant.
Average Rating:
Google May Make Gmail More SocialGoogle May Make Gmail More Social
Not a Facebook or Twitter killer.
Average Rating:


advertisement

Enterprise Hardware Spotlight
Nvidia Auto-Switches Notebook GPU To Save Battery Life
Nvidia has taken the wraps off a notebook technology that chooses the best graphics processor for any given application and automatically routes the workload to Nvidia or Intel processors.
 
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Mobile Enterprise Spotlight
To Love or Not To Love: Apple iPad Pros and Cons
Now that the iPad has officially been announced, opinions are rolling in on this device that combines the features of an iPod, e-reader, and tablet PC. Will the iPad turn fewer heads than the iPhone?
 
Analysts See iPad Price Drop, with Some Cannibalization
Just weeks before Apple officially rolls out the iPad, financial analysts are making pricing predictions. But could the analysis itself hinder the initial demand for the pricey tablet computer?
 
Bar Codes Go Mobile, Get Hip Again
For decades, retailers have used patterns of black dots and lines to encode data onto products. Now, bar codes are gaining favor as an easy way for cell-phone users to view ads and other data instantly.
 

Enterprise Technology Spotlight
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 
IBM Opens Eco-Friendly, Cloud-Focused Data Center
IBM has opened its latest data center in North Carolina. Big Blue said the $362 million facility in Research Triangle Park is designed to support cloud computing and other new computing models.
 

Navigation
Sci-Tech Today
Home/Top News | Computing | Digital Life | Discovery | Space | Innovation | Health | Science News
Environment
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.