Monday September 6, 2010 2:20 PM AEST
 
Blogs
Latest Comments

Facebook faces the music

  • Email a Friend
  • Print Page
By Dan Kaplan
Apr 24, 2009 | 8 Comments
I just got finished reading a lengthy article about Facebook in New York Magazine - easily my favorite magazine in the whole world, well, aside from SC Magazine - and, like I figured, it failed to touch on any of the information security risks of the popular social-networking site.

That’s not to say the story overlooked the privacy ramifications of the site. In fact, much of the article revolved around the inarguable fact that Mark Zuckerberg and his cronies are amassing huge amounts of data on you - you gotta be on Facebook, right? - and tens of millions of your friends all over the world (even if they promise to protect it while you’re here and get rid of it if you decide to leave).

But I’m not here to debate this point, although it seems as if Facebook is making a good faith effort to satiate privacy advocates. The problem with Facebook, and other burgeoning social networking sites like Twitter, is that we get all caught up in this data privacy issue and never talk much about the insecurity of web applications - and how that can be a really bad thing.

We saw it over the weekend, up close and personal, when an attention-seeking teenager from Brooklyn (aren’t they all, really?) devised a cross-site scripting worm that was able to cut across Twitter and infect -albeit benignly - a vast number of profiles.

But what if this attack were more profit-driven? What if the worm spread links to a more malicious website than it did? What if the code asked the user to divulge personal information?

Sites such as Facebook and Twitter have a lot on their minds, mainly figuring out how to monetise their insane popularity. (It’s harder than it seems; nobody wants to pay for anything on the internet.)

But amid their revenue-generating boardroom meetings, they must stop for at least a few minutes to show users their committment to code security and recognise their place as a pioneer in the web’s revolution. Pretty soon, everyone is going to be doing something at least somewhat similar to Facebook and Twitter.

As a blog post on the Gnucitizen think tank said soon after the Twitter attack:

There is no merit in discussing how this has been done and for what purposes but this incident is yet another proof that the attack landscape is rapidly changing and moving towards web enabled infrastructures and the client-side. Soon or later almost every website will be equipped with social capabilities (google’s own opensocial and friendconnect platforms) and than simple persistent XSS attacks will turn into quite nasty problems.

John Pescatore of Gartner was a tad more terse in his “Twelve Word Tuesday” blog post:

Malware just taught Twitter the lesson Microsoft learned in 2001: security matters.

We’re looking up to you Facebook, Twitter, MySpace, etc. Please don’t let us down.
 
Ads by Google
Thoughts on this article? Add a comment below.
Comments: 8
I like facebook for social networking and keeping track of my friends but its no bueno when it comes to discovering bands. I find the layout of myspace to be nauseating so I've been using www.putiton.com to find and follow new music acts.
SC Magazine - comments icon Posted by Sam HamiltonJun 5, 2009 4:14 AM
>>/
SC Magazine - comments icon Posted by arminJun 13, 2009 10:38 PM
I agree with sam. putiton.com will be pretty cool when more artists sign up. good article Dan...
SC Magazine - comments icon Posted by JamesJun 17, 2009 4:39 AM
Hi, Well translator in this time we are founding they perform its task because translator means performs its works easy among different projects and now every one like to use translator in every language translator is available.
SC Magazine - comments icon Posted by Perth TranslatorAug 24, 2009 8:46 PM
I
SC Magazine - comments icon Posted by laneSep 11, 2009 3:56 AM
I read articles in facebook Its nice to hear facebook.It show popular people and their stories about popular and adding friends. I also like the http://tinyurl.com/y8wqgap/ at the end, like you have it
SC Magazine - comments icon Posted by JordanFeb 20, 2010 5:07 PM
I read articles in facebook Its nice to hear facebook.It show popular people and their stories about popular and adding friends. I also like the http://tinyurl.com/y8wqgap/ at the end, like you have it
SC Magazine - comments icon Posted by JordanFeb 20, 2010 5:15 PM
There is no meritoriousness in discussing how this has been done and for what purposes but this incident is yet other see that the round landscape is rapidly dynamical and mobile towards web enabled infrastructures and the client-side. Soon or after near every website faculty be transistorised with party capabilities and than ultimate relentless XSS attacks leave activity into quite grotty problems. ------------------------------ @Jackson [URL=http://www.smart-card.com]smart card[/URL]
SC Magazine - comments icon Posted by JacksonMay 27, 2010 5:43 PM
Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Comments have been disabled on this article.
 
 
 
Featured Whitepapers