Friday, October 25, 2024

Facebook Offers Security Guide

August 21, 2011 by  
Filed under Lingerie Events

Top 15 Facebook Apps For Business
(click image for larger view)
Facebook on Thursday began promoting a guide designed to help users participate in its social network with less risk, a need that has grown as the service has.

Co-authored by Linda McCarthy, former senior director of Internet safety at Symantec, Keith Watson, a security research engineer at Purdue University, and Denise Weldon-Siviy, a teacher and editor, the Guide to Facebook Security offers both well-worn security advice and surprising recommendations.

More Security Insights




White Papers


Analytics


Webcasts

Videos

TechWebTV catches up with Whisper Systems' CTO and co-founder Moxie Marllinspike to discuss and demo WhisperCore -- a mobile security solution that brings BlackBerry-like centralized enterprise-grade security to Android devices.Richard Bejtlich, CSO and VP of managed services, sits down with Dark Reading's Kelly Jackson Higgins at Black Hat USA to talk about the two hats he wears at the incident response company, and trends in attacks against enterprises and security firms.We spoke with Chris Sather, Product Management for Network Defense at McAfee about McAfee's next generation firewalls that analyze relationships and not protocols.

Though some Facebook users question the wisdom of presenting the guide as a downloadable PDF–a common vector for malware–those averse to PDFs are probably sufficiently sensitized to Internet security issues that they wouldn’t benefit from the advice. Those unaware of the potential pitfalls of file downloads, however, will almost certainly find something of value in the 14-page document.

The guide opens with the most common online security recommendation in recent years: choose a good password, one that’s at least eight characters long, contains one or more numbers, and at least one special character. It goes on to reiterate other conventional wisdom, like not reusing your Facebook password on other sites, not sharing it with friends, and changing it regularly.




You’ve probably heard this before. But many Facebook users probably haven’t or have ignored this advice previously, which is why it bears repeating.

What might not be expected is advice like making sure you log out of Facebook. “Logging out of Facebook when you’re not using it is a simple and effective way to protect your account,” the guide states. “Many people think that if they close the webpage or exit the browser that also logs them out of Facebook. It doesn’t. The next person who goes to Facebook.com on that computer will find themselves [sic] already logged in–to your account.”

Facebook has a vested interest in keeping users logged in: It could log users out after a period of inactivity, the way online banking sites do. But the company wants users to remain logged in when they visit other websites, particularly sites that have integrated Facebook APIs, like Social Plugins. That’s because social features provided by Facebook won’t load on third-party sites when a Facebook user visits but isn’t logged in to Facebook.

The authors of the guide appear to be aware of this tension, because they qualify their advice. The guide specifies that you should log out of Facebook when using the service away from home. Even so, the guide also advises logging out of Facebook when a home computer is shared. Those serious about security might consider logging out at the conclusion of a Facebook session, even if that de-socializes third-party websites.

The guide also advises Facebook users to only friend people they know. Anyone with more than several hundred Facebook “friends” has probably violated this suggestion many times over.

This is particularly important because Facebook operates under the assumption that you know your friends. When attempting to access Facebook from abroad, Facebook will attempt to verify your identity by asking you to identify your friends in tagged pictures.

The security guide also provides valuable recommendations about things like how to obtain a one-time password–text “otp” to 32665 (FBOOK) from a phone that you’ve registered with Facebook–and how “Like” buttons can be trapped for clickjacking attacks.

If you’re the least bit unsure about how to navigate the world of social networking securely, take a look at the Guide to Facebook Security.

Attend Enterprise 2.0 Santa Clara, Nov. 14-17, 2011, and learn how to drive business value with collaboration, with an emphasis on how real customers are using social software to enable more productive workforces and to be more responsive and engaged with customers and business partners. Register today and save 30% off conference passes, or get a free expo pass with priority code CPHCES02. Find out more and register.

Share and Enjoy

  • Facebook
  • Twitter
  • Delicious
  • LinkedIn
  • StumbleUpon
  • Add to favorites
  • Email
  • RSS

Featured Products

Speak Your Mind

Tell us what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!