Feeds

Social net sites do wonders for crooks, spooks and bosses

'Computers are making people easier to use everyday'

High performance access to file storage

RSA Europe Social networks make obtaining sensitive background information on people as a prelude to stealing their identities – and running attacks on corporations – easier than ever before.

Ira Winkler, president of ISAG (Internet Security Advisors Group), an ex-NSA officer and cybercrime guru, has called for increased security awareness training. "People don't realise what they are putting out there," he said. "Computers are making people easier to use everyday."

Speaking at the RSA Europe conference in London on Wednesday, Winkler outlined a range of attacks that social networking might enable. Information on LinkedIn, for example, has been used as a prelude to targeted attacks against corporates or government agencies as part of the expanding list of so-called Advanced Persistent Threat-style (APT) attacks commonly blamed on China. Lower-level criminals can use information on social networks such as Facebook to guess the answers to password reset questions, for example. Worse still, 4Square users are giving away their location every time they log in to a venue, revealing to potential burglars that they are away from home in the process.

Much of this type of activity is wrongly described as social engineering, according to Winkler. The security guru said the term social engineering has been bastardised. Its original meaning referred to an interaction with people where they would be directly manipulated into performing actions or giving away confidential information. The bastardised term is now misapplied to "check this out" lures in mass-mailed computer viruses or even to the lifting of sensitive information consumers have unwittingly left on social networking sites, he says.

He also pointed out that few stop to think that current or potential employers might scan their Facebook profiles, which reveal details of drunken parties or time taken off work when they are supposedly sick.

Content-filtering tools for social networks don't exist as yet. In the absence of such tools, Winkler favours security awareness training for users, which he argues is sorely needed.

"You can have no expectation of privacy for anything you put on the internet," Winkler. "The test has to be: do you want your worst possible enemy to see the information you are putting online?" ®

High performance access to file storage

More from The Register

next story
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
Bad PUPPY: Undead Windows XP deposits fresh scamware on lawn
Installing random interwebs shiz will bork your zombie box
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.