Feeds

One thumb up for Facebook security improvements

Outstandingly mediocre

Combat fraud and increase customer satisfaction

Security changes designed to curtail the spam and scams that have become endemic on Facebook over recent months have received a cautious welcome from security watchers.

Facebook has introduced a raft of features including: a known-bad-site blacklist (via a partnership with crowd-sourced blacklist outfit Web of Trust); protection against clickjacking; and limited support for two-factor authentication. As an opt-in service, Facebook will send users an SMS every time someone logs in from "a new or unrecognised device".

Net security firm Sophos welcomed the changes as a step in the right direction but criticised the dominant social network for not going far enough towards creating a genuinely safe online environment. Further measures Facebook ought to introduce include a popup confirmation dialog every time a user "likes" something, and an option to apply two-factor authentication for every login, not just for those from new devices.

"There's much more they could be doing, so we all need to maintain pressure on Facebook to keep on improving," said Paul Ducklin, Head of Technology, Asia Pacific at Sophos.

A blog post by Sophos, explaining its take on the changes, can be found here. ®

Combat fraud and increase customer satisfaction

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.