July 30, 2007 8:24 AM PDT

Facebook users open to cyberattacks, ID theft?

As Facebook evolves from a university social network into an enterprise tool, VeriSign iDefense security experts are warning that the platform is turning into a prime attack vector for cybercriminals.

Ryan Olson, a United States-based analyst for VeriSign's iDefense operations against the proliferation of malicious code, said that while thousands of applications being developed by third parties for Facebook users are enriching the social network's functionality, the Facebook Platform provides a perfect channel for distributing malicious software.

"The potential is there, and the framework is there," Olson said.

"Rather than putting it in our terms of service that you promise not to breach our security and putting the onus on us, we are just going to open it up slowly over time," Facebook founder Mark Zuckerberg said in June.

"You use such developer applications at your own risk," Facebook states on its privacy statement.

While Facebook third-party developers do not necessarily have access to Facebook members' personal details, whether users agree to install an application is ultimately a caveat emptor scenario.

Adding pressure to the rush to develop new applications for Facebook, PayPal is running a competition that closes on August 24, offering developers cash prizes of up to $10,000 for winning applications.

Developers require users to agree to their own terms of service and privacy policies as a condition of using their applications. Given the tendency by users to gloss over lengthy condition statements, this opens the possibility for developers to extend rights beyond the standard agreements.

However, Olson and Rick Howard, director of intelligence at VeriSign's iDefense Labs, said a longer-term problem is users' openness with personal information on public forums.

"They seem to have no sense of privacy," Howard said. "We think it could go two ways. In the future, they're either going to decide they're embarrassed by all the information they've put out there, or they may decide it's just the way it is and (that) it's OK to put information out there."

In a "thought experiment" the two conducted in the United States before visiting Australia, Howard said they managed to acquire enough information on one young user to steal her identity.

"We pulled down one person's name--in this instance, a female--and everything she put out there," Howard said.

"In 15 minutes of doing Google searches, we were able to collect enough information to steal her identity."

So what can users do to protect themselves in this candid new world?

"Best practice, really: don't let information out like that," Howard said, adding that the "intoxicatingly interesting" nature of social networking is inherently at odds with best practices.

Liam Tung of ZDNet Australia reported from Sydney.

See more CNET content tagged:
Facebook, iDefense, VeriSign Inc., identity theft, social networking

Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Dell planning to ditch factories

    CFO Brian Gladden has said the company has "more work to be done" to improve profitability. Now The Wall Street Journal reports that Dell is planning to lower costs by selling off its factories.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • Negative Approach

    Net-connected game consoles set to reach $8 billion in '13

    Revenue possibilities for games continue to grow, at least for the big console manufacturers, according to a report.

  • Beyond Binary

    Microsoft begins big ad push

    Microsoft's multi-year push, estimated at $300 million, begins with a spot featuring Bill Gates and Jerry Seinfeld aired during Thursday's NFL game.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Wireless

    Was EarthLink's failed citywide Wi-Fi a blessing in disguise?

    Wireless Philadelphia, the nonprofit charged with providing broadband bundles to low-income families in Philadelphia, may be better off in the long run without EarthLink.

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Gaming and Culture

    Behind the prototyping of 'Spore'

    Many of the components of Will Wright's highly anticipated evolution game started out as small concept projects that are now available to the public.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • The Cheapskate

    Record TV in style with a refurbished TiVo HD, $179.99 shipped

    TiVo is offering refurb HD units for cheap, though you'll still have to pay for the TiVo service.

  • News - Politics and Law

    McCain talks up oil drilling, green energy

    Republican presidential candidate says we need to drill new wells now, while supporting innovative transportation technologies and "the use of wind, tide, solar and natural gas."