Showing posts with label Facebook. Show all posts
Showing posts with label Facebook. Show all posts

Friday, 9 October 2009

Web Passwords

Passwords can be a pain. There are thousands of websites across the Internet that require passwords. Traditional advice has been to use different passwords for different applications. This is plainly impossible. A typical user of the Internet probably has passwords for their MSN, Gmail, YahooMail, Flickr, Picassa, Facebook, MySpace, Bebo accounts, as well as for their bank, mobile phone company, energy company, and innumerable other sites, some of which they've probably forgotten that they signed up for.

So, instead of saying each account should have a different password, I'd suggest that the best thing to do is to have a few passwords, but to have some rules around the ones that you use regularly.

  1. Always pick a good password. There's a guide here that offers some ideas.
  2. Don't use the same password for a mail account that you used to set up a social networking account with. For example, if you use the same password for Hotmail as you do Facebook, and one or the other gets "broken in to", it's likely the other will, too. And then it's incredibly difficult to regain control of either.
  3. Do change them occasionally.
  4. Consider what you're protecting. Don't use the same password for all your important accounts (e.g. bank, email) and use a separate password for account for sites you're not overly bothered about (e.g. that Fraggle Rock appreciation site you signed up to)
  5. Don't share them! I know this sounds obvious but don't let anyone else have your password – think about what you're giving the access to. This is especially true for passwords at university or in the workplace – the risk is much greater than simply to your data as it could impact the whole organisation.

These aren't simply theoretical risks. In the last few months, I have dealt with situations including the hijacking of a Facebook and related Hotmail account – believe me when I say that this is not easy to resolve – and several instances where people have sent their usernames and passwords to scammers.

The reason scammers want your username and password in a place like a university is because they want to send spam through the universities mail system. Unfortunately, this can lead to the whole university being blacklisted as a spammer and no-one will be able to send or receive email.

Please take care of your passwords.

Friday, 18 September 2009

Hacking Facebook

I just got pointed towards an article that shows that your Facebook account password is worth $100. It's impossible to tell whether this is genuine or not without sending $100 via Western Union to the Ukraine (and what is it about Western Union and scams??) but it does raise some interesting questions about how much people would be willing to pay to hack into someone else's account. I have had people come to me with this same issue and it's really difficult to regain control - it is a free service, after all.

More on this soon...

Monday, 10 November 2008

Social Networking Risks – Facebook and others

With the rise and rise of social networking sites, everyone is getting online and publishing more stuff about their own lives. But not everyone is fully aware of the risks that they run by putting so much information about themselves online.

The Internet never forgets

Many people don't realise that when something gets published, it is very hard to take it off the Internet. Consider this when publishing photos from the last time you had an all-night, booze-fuelled party. A number of sites offer historical archives of the web. Google offers up cached versions of web pages in its results. Historical data has caused all sorts of problems a number of companies, most recently United Airlines. Other stories keep resurfacing. The BBC and Microsoft have an ongoing issue with a story written in 2001 about Hotmail considering charging users for its e-mail service. The story (from 2006) is here.

Employers will search the web for you

Many employers will now search the web for any information they can find out about you before you get offered a job and, in some cases, will take issue with things that you post online while working for them. Here are some examples:

Policeman loses job opportunity because of his Facebook profile

Waterstones employee loses job because of blog comments

Australian man found lying about sickness through Facebook

Virgin and BA staff sacked for Facebook site criticising customers and their respective companies

And if you think you can simply delete your Facebook profile, think again. It is seemingly very difficult to actually erase yourself. While deactivating your account is simple enough, actually getting Facebook to delete your details is much harder. This has been the subject of concern by the Information Commissioner and he discusses it on this BBC page.

Watch out for the actions of others

If you do post something on your profile beware what others may do with that information. There has been a tragic case recently of a woman who was murdered by her husband, simply because she had changed her relationship status on her profile.

It's not all bad

There are ways that you can limit the risks you run by using social networking sites:

Always think about what you upload: consider what that picture of you on the drunken night out might look like to a future employer.

Don't post everything about yourself: a date of birth is essential for an identity thief – do you really need it on your profile?

Check the privacy settings: most sites, like Facebook, allow you to restrict who has access to what information.

Search online every so often to see what's published about you: it's always a good idea to see what information is available about you online.

Don't install every Facebook app: some have been found to be malicious

Only invite friends that you know: if you don't know them in person, think hard before accepting that friend request. They may be impersonating someone else.

There are sites that can help. Sophos do a really good guide to Facebook settings, there's an online video about MySpace privacy settings from SafetyClicks, and Bebo themselves have published an online safety guide.

But these settings will not protect you if you're either blogging directly, have your own website or use another service. Fundamentally, the question you have to ask yourself is: should this information be online at all.