Facebook security profiling doesn't like African log-ins

Social network nearly cost Kenyan employee his job

Secure remote control for conventional and virtual desktops

A tip-off from a source has turned up an interesting quirk in Facebook's security measures. He claims the social networking site appears to discriminate against log-ins from Africa.

Our tipster, Raj from Vancouver, Canada, has an interesting if unusual set of circumstances.

Raj runs a tech business and uses Facebook to connect with customers. But because he appreciates getting round-the-clock coverage and because he doesn't want to spend all his time updating Facebook, he has employed freelancers in Singapore, India and most recently Kenya to sign in and update his profile for him.

He could use a Page or a Group. But Raj is using a personal profile for this venture and in order to let his freelancers access his account, he shares his password with them.

And the problem? Raj's employees in Singapore and India were both able to log in and work for him, but Sam – Raj's Kenyan employee logging in from Nairobi – was blocked so many times by Facebook security checks he was unable to do his work. This became a problem to the extent where Raj was considering employing someone else in a different country who woulddn't have the same problems logging in.

Raj is in a funny situation here: not many Westerners hire Kenyans to update their personal pages for them... But it's exactly the unusual circumstances of Raj's case that has brought this particular Facebook quirk to light.

To go into a little more detail: the log-ins from India and Singapore were challenged – once – and accepted by Raj on a particular computer back in Vancouver that Facebook recognised. The challenge screens look like the one below. However, the Nairobi log-in was challenged and accepted four times in a row before Raj gave up on trying to get the Kenyan log-ins accepted permanently and engineered a workaround by setting up a VPN so that Sam's IP address matched his in Vancouver and lost the Kenyan connotations that seemed to be causing Facebook so many problems.

Screen grab of the Facebook security page Raj encountered 4 times

Raj wrote about the annoyance that the hyper security checks caused:

On four (4) separate occasions this week, Facebook temporarily locked us both out of my account. This has not only repeatedly disrupted my authorisations from other applications and social media work, klout, Facebook messenger (now a vital communication piece), and Microsoft Outlook  integration, but it's sucked a bunch of my time up, too! It seems only I can unlock my account from my office computer, so poor [Kenyan employee Sam] sits idle at night and then has to wait for me to come to the office in the morning to unlock the accounts. Can you say annoying? After jumping through Facebook’s little hoop four times, all I can say is can you get the hint, Facebook?

It's good that Facebook challenge log-ins from unfamiliar places. Goodness knows we give it enough stick for not protecting our security. But why did it accept Raj's confirmation of log-ins in Singapore and not the ones in Nairobi?

In a statement to The Register, Facebook admitted that it is more likely to block or question log-ins from geographical areas it considers suspicious.

A Facebook spokesperson told us:

We verify log-ins security based on the likelihood of a log-in from that geographic area being erroneous. If we spot a lot of suspicious activity from a particular IP address or area, we’ll take steps to make doubly sure that log-ins from that location are valid. If you log on from a new location, device, or we are wary of the browser you use, we’ll use additional security checks.

As Raj put it, before he figured out the VPN workaround: "I’d hate to turn him [Sam] to the door because of a social network that won’t let me inherently trust a whole country or ISP."

In an informal briefing with Facebook the company hammered home the point that you should never, ever, according to article 4.8 of the Facebook T&Cs share your password with another person.

But people share passwords: couples do it, friends do it, people who run events or businesses do it too.

Officially, a Facebook spokesperson told us:

If you log on from a new location, device, or we are wary of the browser you use, we’ll use additional security checks. Doing so is a responsible way of keeping our users' information safe and secure; it isn’t discrimination. Furthermore, this issue could be resolved by the user having multiple admins using their own profiles to manage a Facebook page rather than a profile. It is against our terms to allow more than one person access to an individual profile.

So this is profiling: the same as airport security guards choosing to search an Arab man rather than a white woman, or cops in Brixton searching a disproportionate number of black male teenagers – but in this case it was on the verge of costing a man his job.

Of course Raj could set up a Page. However there are several advantages to having a Profile on Facebook. It's possible to convert a Profile into a Page and to save your contacts – people who were "friends" with you will automatically switch to becoming "fans" of your page. But photos and contacts are the only two things transferred over, so other content such as past updates, wall-to-wall conversations and messages will be lost.

Raj mentions that he uses Facebook instant chat to talk to clients and chat is not available to Page-owners. Generally, as a personal profile you can access a lot more information about the people you are connected to, and as a Page you can only see their public information and can't for example write on their walls.

Facebook is very clear that there should be a distinction between businesses and people, but as Raj is aware there are some uses to being a person with friends rather than a Page with fans. The disadvantage is that Facebook might terminate you and your Facebook activity. That's in their terms and conditions too. ®

Gartner critical capabilities for enterprise endpoint backup

More from The Register

next story
UK fuzz want PINCODES on ALL mobile phones
Met Police calls for mandatory passwords on all new mobes
Canadian ISP Shaw falls over with 'routing' sickness
How sure are you of cloud computing now?
Don't call it throttling: Ericsson 'priority' tech gives users their own slice of spectrum
Actually it's a nifty trick - at least you'll pay for what you get
Three floats Jolla in Hong Kong: Says Sailfish is '3rd option'
Network throws hat into ring with Linux-powered handsets
Fifteen zero days found in hacker router comp romp
Four routers rooted in SOHOpelessly Broken challenge
New Sprint CEO says he will lower axe on staff – but prices come first
'Very disruptive' new rates to be revealed next week
US TV stations bowl sueball directly at FCC's spectrum mega-sale
Broadcasters upset about coverage and cost as they shift up and down the dials
O2 vs Vodafone: Mobe firms grab for GCHQ, gov.uk security badge
No, the spooks love US best, say rival firms
Ancient pager tech SMS: It works, it's fab, but wow, get a load of that incoming SPAM
Networks' main issue: they don't know how it works, says expert
Trans-Pacific: Google spaffs cash on FAST undersea packet-flinging
One of 6 backers for new 60 Tbps cable to hook US to Japan
prev story


5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.