On TechRepublic: Windows 7: Slower to boot than Vista?
BNET Business Network:
BNET
TechRepublic
ZDNet

August 8th, 2008

Facebook's (futile) malware exorcism - can social networks fight back?

Posted by Jennifer Leggio @ 12:06 pm

Categories: Blogging Best Practices, Facebook, Networking, Security, Social Business Analysis, Social Media, Social Media Best Practices, Social Media and Security

Tags: facebook, network, malware, site, kelly, social networking, security, online communications, marketing, advertising & promotion

In the wake of two recent worm attacks on Facebook, the popular social networking site responded last night with a statement about its security practices. Regarding the attacks, Max Kelly, head of security at Facebook, wrote this in a blog post:

…we spent most of last night working on a fix for a worm, which was targeting people on Facebook and placing messages on Walls urging users to view a video that pretends to be hosted on a Google or YouTube website. We’ve identified and blocked the ability to link to the malicious websites from anywhere on Facebook.

Have they now? Kelly writes that he and his team are soon headed to Defcon 16 this weekend in Las Vegas to learn how to make the site safer. Perhaps he and his team plan to attend “Satan Is On My Friends List” about securing social networks. But, really, is there a solution for Facebook waiting at Defcon? Probably not, and here’s why:

  • Making a social network secure is darn near impossible. As fast as Facebook (or any other social network) blocks those known malicious site hackers will come up with new ones. There’s no “patch” or “fix” for these issues.
  • Why? The major flaw with social networks comes down to user awareness and user responsibility. Kelly correctly states that many people use the Internet without any knowledge of security threats posed by hackers. Which makes these users…
  • …primary targets for online social engineering scams, similar to what was presented with the “Court Jester” malware attack. If users are unaware as to the threats presented by clicking on outside links, they are easily going to be spoofed. Facebook cannot keep its users from clicking off the site and downloading files.

“If a site allows any kind of links at all, then what a user does after they follow that link is really out of control of the social networking site,” said Wesley McGrew, who operates McGrew Security. “They can keep blocking the links to malicious sites as they pop up and they can try to educate their user base but that’s about it. Facebook is likely at the mercy of the security of each user’s home computer.”

If a user’s home PC gets owned, the malware can navigate the social network much in the same way that a legitimate user can. That could be tough for the Facebook security team to detect as the malware would have similar attributes to the user. While attacks on Facebook applications are not new the hackers’ ability to penetrate the Facebook wall is a big deal — and it’s these types of attacks that had a terribly negative effect on MySpace’s perceived viability when its pages began to get compromised on a regular basis.

Next: What should social networks do? –>

Pages: 1 2

Jennifer LeggioJennifer Leggio, aka "Mediaphyter," writes about the "social business" side of social media - including enterprise, security and reputation issues. See her full profile and disclosure of her industry affiliations.


Email Jennifer Leggio

For daily updates on Jennifer's activities, follow her on Twitter.

Subscribe to Social Business via Email alerts or RSS.

  • Talkback
  • Most Recent of 13 Talkback(s)
RE: Facebook's (futile) malware exorcism - can social networks fight back?
You could just deny any invitations to join a group or cause that involves the use of any third-party application.... (Read the rest)
Posted by: eric812@... Posted on: 08/29/08 You are currently: a Guest | | Terms of Use
Banks have this problem  dunsany | 08/08/08
Learning the hard way  fr0thy2 | 08/12/08
RE: Facebook's (futile) malware exorcism - can social networks fight back?  Bob C User | 08/11/08
RE: Facebook's (futile) malware exorcism - can social networks fight back?  Panda129 | 08/11/08
RE: Facebook's (futile) malware exorcism  w_c_mead | 08/11/08
ps-  w_c_mead | 08/11/08
or  seanferd | 08/11/08
RE: Facebook's (futile) malware exorcism - can social networks fight back?  TracyF | 08/11/08
RE: Facebook's (futile) malware exorcism - can social networks fight back?  justinseinlin | 08/11/08
RE: Facebook's (futile) malware exorcism - can social networks fight back?  Greenknight_z | 08/12/08
RE: Facebook's (futile) malware exorcism - can social networks fight back?  manudea | 08/12/08
Security is key  blarman_z | 08/13/08
RE: Facebook's (futile) malware exorcism - can social networks fight back?  eric812@... | 08/29/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
Learn more about tools to grow your business
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Save time with the UPS Business Essentials Guide
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
New Online Dashboard for IT Leaders
Read about top issues IT decision-makers face every day, plus get cost-effective solutions to real-life IT problems.
Learn more >>
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads