On mySimon: Logitech MX Revolution Laser Mouse
BNET Business Network:
BNET
TechRepublic
ZDNet

August 20th, 2008

Identity theft for the hip blogger on-the-go?

Posted by Jennifer Leggio @ 10:56 am

Categories: Reputation and Privacy, Security, Social Business Analysis, Social Media, Social Media Economy, Social Media and Security, Twitter

Tags: Financial, IM, SMS, Twitter, Blogger, Xpenser, Text Messaging/SMS/MMS, Telephony, E-mail, Financial Management

In Focus » See more posts on: polls

I was minding my own business on Twitter last night when I saw a tweet from Laura Fitton that said, “totally stoked i can now tweet expenses to myself at the point i incur them (and IM, email, SMS too).” I did an immediate double-take. I think my audible reaction was, “Eek!”

Turns out that Fitton was talking about a free service called Xpenser. Here’s a quick snippet in the company’s own words:

We were fed up with how painful expense reports and tracking were. After many experiments we found a workable solution: record expenses as soon as they happen and forget about them.

Xpenser lets you do just that - record expenses via whatever means are available to you quickly and painlessly. Send them in via Email, SMS, IM, or voice (call a number and say your expense). From your Blackberry, email “Lunch 78.50 with BigClient” and it’s recorded. From your phone, SMS “exp groceries 27.13″. From your computer, IM “Equipment 889.19 backup server”. From your phone, call and say “taxi 39 office to airport”. Use the Web interface to edit and finalize them or export them to your favorite financial management software. No more forgetting your cash expenses, no more half-day expense entry sessions.

Identity theft for the hip blogger on-the-goI’m not against online expense services as a whole (I know a lot of people who use and love FreshBooks). My concern with Xpenser is the data in transit from other Web-based services, some of which have been notoriously insecure at times. Users can send these expenses via instant message, Twitter, SMS, Jott, etc. From what I understand all of this feeds into a simple hosted spreadsheet that appears from the demo to only include dollar amounts and expense types, but that’s just the demo. Since true expense management includes relating your expenses to the type of account you used to pay them, isn’t there a risk that some users would list their account numbers or account types? Hard to tell from the demo — and nothing is written on the site to address this concern. Nor is there anything written that tells less-than-savvy Internet users how not to use this service in order to protect themselves.

It’s akin to writing private information on a piece of paper and throwing it in the trash can. There’s a very slim chance that anyone will find it — but there is still a chance.

Some people might say that Xpenser is an OK service if one knows better than to include account names and numbers but, quite frankly, I don’t want to put out there even the slightest bid of information that could allow a hacker to financially profile me, or even my small business, and give them added incentive to compromise any other part of my financial life.

This, to me, is one scary step away from the “Twitter as a PayPal killer” mumbo jumbo that was circulating around the Web a month or so back. As progressive as I feel about social networking tools I still feel we are a long way from trusting them with our financial records.

When I threw this over to a couple of security friends via email last night, one of the replies I got back was, “Good gravy, Xpenser sounds terrifying.”

When I commented on my continued shock this morning, Twitter pal Grant Beery, of the hockey blog Daily Deke, said, “Identity theft for the hip blogger on the go” (and thus the inspiration for my headline).

These folks get it. I don’t even know that Xpenser gets it. I dug through the site’s FAQ and blog and found nothing relative to security. Are people not asking these questions? The thing is, that Xpenser may be able to secure its site to the hilt (well, to some degree) but it cannot assure security of the services transmitting the data. So why trust it?

Would you send your financial data via Twitter, Jott, SMS or IM?

View Results

Loading ... Loading ...

Jennifer LeggioJennifer Leggio, aka "Mediaphyter," writes about the "social business" side of social media - including enterprise, security and reputation issues. See her full profile and disclosure of her industry affiliations.


Email Jennifer Leggio

For daily updates on Jennifer's activities, follow her on Twitter.

Subscribe to Social Business via Email alerts or RSS.

  • Talkback
  • Most Recent of 2 Talkback(s)
RE: Identity theft for the hip blogger on-the-go?
I think you missed the point of the service. It's not a comprehensive financial management solution. It's simply a way to track what you spend when you take money out of your pocket. If you sign up... (Read the rest)
Posted by: just.thefacts Posted on: 09/24/08 You are currently: a Guest | | Terms of Use
ewww  varapetra@... | 08/27/08
RE: Identity theft for the hip blogger on-the-go?  just.thefacts | 09/24/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More