Feeds

Facebook spams social networkers with phishy email

Click on this link...bitch

  • alert
  • submit to reddit

Next gen security for virtualised datacentres

Facebook has taken the unusual step of sending its users email asking them to click on a link so they can restore site configuration settings that were recently lost. Facebook isn't kidding, and neither are we.

"Unfortunately, the settings that control which email notifications get sent to you were lost," the email says. "We're sorry for the inconvenience. To reset your email notification settings, go to http://www.facebook.com/editaccount.php?notifications."

The wording sounds like so many phishing emails we've all received over the years. Even Aunt Mildred would feel proud of herself for spotting the ruse. Except it's not, and that's unfortunate because it threatens to desensitize newbies to the ever-present dangers of phishing attacks.

The move, because it flies in the face of everything security experts advise against, took some Facebook users by surprise.

"I'm amazed to see a large organisation like that sending something that looks so obviously evil," wrote Reg reader Kevin Lentin, who first brought our attention to the emails. "It would have been better to send an email saying 'please go to our website and login.'"

That's because Facebook is one bigger targets of phishers. With all the scammers eager to trick users into clicking on dodgy links, you'd think Facebook's security team would bend over backwards to educate their users to steer clear of them in emails, no matter where they appear to come from.

Not that Facebook is alone. Earlier this week, an eBay spokesman counseled users of the online auction house to never click on links embedded in emails, even though the eBay-owned PayPal continues to include links to its login page in emails it sends to users. As if this do-as-I-say-not-as-I-do advice wasn't bad enough, PayPal was found directing users to the wrong website. ®

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
Think crypto hides you from spooks on Facebook? THINK AGAIN
Traffic fingerprints reveal all, say boffins
prev story

Whitepapers

A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Maximize storage efficiency across the enterprise
The HP StoreOnce backup solution offers highly flexible, centrally managed, and highly efficient data protection for any enterprise.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.