Share

Related Stories

  • AVG/Ponemon study concludes users unaware of the security risks of smartphones
    Building on preliminary research announced at the Mobile World Congress in Barcelona recently, AVG Technologies – in partnership with the Ponemon Institute – has released a report that claims to show high levels of data security complacency amongst users of smartphones.
  • ISSE 2009: Geographically targeted attacks could be future of social network threats
    Just as social networks such as Facebook are seeing advertisement targeted depending on users’ settings and geographical location, so could malware and other threats be targeted specifically, said Stefan Tanase, senior security researcher at Kaspersky Lab, Romania, at the ISSE 2009 conference on 7 October.
  • Social networking - a risk to information security?
    As the popularity of social networking sites continues to mount, it becomes increasingly important to consider the information security risks posed in the context of a wider data loss prevention and reputation management strategy. Cath Everett reports
  • Comment: It’s Time for Smartphone Security
    As the mobile market grows, so does mobile malware. Don DeBolt, director of threat research at internet security company Total Defense, discusses how IT practitioners and company employees can best stay safe by protecting themselves from mobile hacks, privacy concerns and more in a day and age when mobile malware is on the rise
  • Risky business: 70% of young employees ignore IT security policies
    A disturbing 70% of young employees said they often ignore the company’s IT security policies, according to a survey sponsored by Cisco.

Top 5 Stories

News

Facebook applications exposed as security risk

01 May 2008

Speculation on the security of social networking has increased amid reports that applications on Facebook are capable of collecting personal information.

The disclosure follows an investigation carried out by BBC Click who created a malicious programme that masqueraded as an application, and tested it on a fictional profile. The results showed that despite high privacy settings, sufficient personal data could be harvested in order to carry out ID fraud.

Applications on the social networking site run from third-party servers and consequently cannot always be strictly monitored by Facebook themselves. When an application is downloaded, the user is given the option to prevent it from accessing their personal details, however many applications require permission in order to function.

Facebook is legally covered through a disclaimer in its ‘Terms and Conditions’, but the question still hangs of how liable the company should be.

“People are predisposed to sharing information” remarks David Emm, senior technology consultant at Kaspersky Lab, who cites password proliferation as a major problem in personal security. “It is difficult to see how Facebook are liable, but it seems that social networking sites should hold some degree of responsibility.”

Mark Murtagh, technical director of Websense, believes that the developments are ‘inevitable’. He observes that “Web 2.0 technologies such as Facebook are not only being used by employees for keeping in touch with their friends, but are rapidly being adopted by business as people use these technologies to build business contacts” adding that “companies understand that allowing access to these tools in a safe environment is what is needed.”

A spokesperson for Facebook responded to the investigation, maintaining that “We regularly evaluate and adjust the security settings for third party applications to ensure that Facebook's terms of service are not violated” and advising that users “employ the same precautions while downloading software from Facebook applications that they use when downloading software onto their desktop”.

This article is featured in:
Application Security • Internet and Network Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.