Aug 22, 2007, News Report
Social networking users are being warned of the dangers of allowing strangers to gain access to their online profiles, following new research into the risks of identity and information theft occurring through global phenomenon Facebook.
Compiled from a random snapshot of Facebook users, research by the IT security company Sophos shows that 41 percent of users, more than two in five, will divulge personal information -- such as e-mail address, date of birth and phone number -- to a complete stranger, greatly increasing their susceptibility to ID theft.
The Facebook ID Probe involved creating a fabricated Facebook profile before sending out friend requests to individuals chosen at random from across the globe. To conduct the experiment, they set up a profile page for 'Freddi Staur' (an anagram of 'ID Fraudster') -- a small green plastic frog who divulged minimal personal information about himself. Two-hundred friend requests were sent out to observe how many people would respond, and how much personal information could be gleaned from the respondents.
"Freddi may look like a happy green frog that just wants to be friends, but actually he's happy because he's just encouraged 82 users to hand over their personal details on a plate," said Graham Cluley, senior technology consultant at Sophos. "While accepting friend requests is unlikely to result directly in theft, it is an enabler, giving cybercriminals many of the building blocks they need to spoof identities, to gain access to online user accounts, or potentially, to infiltrate their employers' computer networks."
Sophos Facebook ID Probe findings:
In the majority of cases, Freddi was able to gain access to respondents' photos of family and friends, information about likes/dislikes, hobbies, employer details and other personal facts. In addition, many users also disclosed the names of their spouses or partners, several included their complete résumé, while one user even divulged his mother's maiden name -- information often requested by Web sites in order to retrieve account details.
"What's worrying is how easy it was for Freddi to go about his business. He now has enough information to create phishing e-mails or malware specifically targeted at individual users or businesses, to guess users' passwords, impersonate them or even stalk them," explained Cluley. "Most people wouldn't give out their details to a stranger in the street, or even respond to a spam e-mail, yet several of the users Freddi contacted went so far as to make him one of their 'top friends'. People need to realize that this is still unsolicited communication, despite it occurring within Facebook, and users must employ the same basic precautions -- such as not responding in any way -- to prevent exposure to wrongdoers."
As well as the successful friend requests, a number of users unwittingly enabled Freddi to gain access to their profile information simply by sending response messages such as "Who are you?" and "Do I know you?" back to his Facebook inbox. Sophos experts note that users' profiles can be protected from such exposure by adjusting the privacy controls within their Facebook account settings.
"It's important to remember that Facebook's privacy features go far beyond those of many competing social networking sites. This is about the human factor -- people undoing all that good work through carelessness and being preoccupied with the kudos of having more Facebook friends than their peers, which could have a serious impact on business security, if accessed in the workplace," continued Cluley. "Of course, some businesses may already be considering blocking Facebook for productivity reasons -- but equally, other companies will see business benefits in this type of interaction, hence it's important that the site is used sensibly and securely."
Read real world deployments of technology in government from our sponsors.
View All Industry Solutions
Yes! I would like more information about CA's solutions for Government.
The Evolution of Identity and Access Management IAM has become a key tool in the organization’s security and risk management efforts. Many Govt. organizations however, are not realizing the potential of a fully evolved IAM solution. This paper helps them achieve that goal.
How can a comprehensive IAM solution help me reduce security risk and achieve easier compliance? Identity and Access Management (IAM) solutions help you manage users and their access to your IT resources while acheving more effective compliance.
IT Governance: Making the Difference in Cities, Counties and States Project and portfolio management helps government respond to old and new challenges. Featuring case studies from California Department of Agriculture, New York City, and Oakland County, Michigan.
CA Information Governance Solution Brief The CA Information Governance solution helps you solve an array of challenges with unique offerings including federated records management, email management, retention management and business process automation.
IT Network Management: State and Local Governments Face New Challenges Network and voice management tools help agancies get optimum performance from today's increasingly complex networks.
Success Stories: San Francisco Health Plan San Francisco Health Plan helps more people access affordable healthcare by simplifying IT management
Success Stories: Social Services Agency, County of Santa Clara County of Santa Clara improves the quality of social services with simplified IT management
CA Network & Voice Management Solution Brief Integrated, fault and performance management for end-to-end service assurance of multi-vendor, multi-technology converged networks.
Key Trends in the IAM Market and how CA's R12 Suite Addresses these Trends Identity and Access Management (IAM) has been a major force in the enterprise IT marketplace for years now.This paper will address the question: What's driving interest in IAM solutions?
Network and VoiceManagement for Evolving Business IT management specialist CA provides a foundation for delivering the value of unified network and voice management
A Vision for Dynamic Business Service Management By applying new levels of consolidation, automation and insight, dynamic Business Svc Mgt delivers improved service levels and cost controls
Deploying the CMDB for Change & Configuration Management The Configuration Management Database (CMDB) plays a critical role within the ITIL framework.
The Changing Face of Network Management Automated NCCM tools reduce the downtime and degradation caused by configuration changes.