Billps Tudios

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label facebook. Show all posts
Showing posts with label facebook. Show all posts

Saturday, 5 December 2009

Who Gets Your Personal Information on Facebook?

Posted on 12:27 by Unknown


Are you one of the 350 million Facebook users? I’m a big fan of Facebook and like many I connect daily to see what my friends are doing and to share photos. As a security professional I am very careful about what I post and what information I allow to be shared. In that respect I’m unique. It surprises me how many of my friends will refuse to allow companies to share their information but eagerly give away their personal information to application developers on Facebook.

allowaccess

My friend Diana sent me some Christmas cheer. How could that be a bad thing right? Well, if I accept her cheer I’m sharing my personal information and all my friends with a company called Mob Science who has no physical address or privacy policy posted on their website.

Who are these application developers you’re giving your personal information too. One of the most popular developers is San Francisco based Zynga. They’re responsible for the games Farmville, YoVille, Mafia Wars, RollerCoaster Kingdom, Scrabble and dozens more. You’ll never be offered a chance to read Zynga’s privacy policy but the information is typical. They say only your name, address and gender are collected. As in most privacy policies they protect themselves with vague statements like “we don't generally collect any “Personally Identifying Information” about our users”.

I’m not saying the folks at Zynga are evil or have bad intent but I doubt most users realize they’re providing information to this or other little known companies. Most people mistakenly believe it’s just all part of the Facebook experience.

It’s not just the games. When you take a quiz, or even donate to “Causes” you’re providing access your personal information. When you create or join a “Cause” you’re registering your personal information with Berkeley based Philotic Inc, started by Sean Parker, one of the brilliant co-founders of Napster.


If you’re a fan of Farm Town, you’ve registered with Florida based SlashKey. Popular game provider MindJolt.com is another one that doesn’t include any physical address or privacy policy on their website. The number two Facebook developer Playfish acknowledges “We collect the following personal data from you … : your date of birth, gender and your contact details including the country where you live and any phone number(s) or email address(es) that you provide.” In addition, “We may use a third party to serve advertisements on our site. Cookies may be associated with these advertisements … We do not have access to or control of cookies placed by third parties.”

In the grand scheme of things the dangers from sharing your information with these companies may still be minor compared to other risks. I wanted to focus on 3rd party Facebook Applications because most people don’t understand why their Email Spam seems to know specific personal details.

Facebook Applications can access this info
Did you know when your friend allows an application, they give away all your information too?

When you sign up for Facebook all these boxes are checked as the default setting. That means if your friend allows an application, all the information you may have set to "Friends Only" is made available. Click Here to change your settings. (Update 12/9: Facebook has made some changes do don't be surprised if this page looks a little different)

Facebook has been slow to react to customer concerns but recently announced new privacy options. It’s still up to the individual user to check out their rights and options to protect themselves. If you’re a Facebook user please click here to read how you can update your privacy settings.

Updated 12/9
Facebook has updated their privacy options. Here's the replacement for the screen allowing you to restrict information shared by your friends.



Updated Facebook privacy



Facebook Simplifies Sharing your Personal Info
Read More
Posted in facebook, privacy | No comments

Friday, 10 April 2009

Privacy Warning using Facebook on a Network.

Posted on 11:01 by Unknown

First let me say, if anyone else wrote this I’d say they were crazy.

I had a big surprise this morning when I clicked on a Facebook link and saw I had new friends.   I was even more surprised when I noticed I wasn’t signed on as myself, but was signed on as Cindi my wife.


Using normal logic I would have thought my wife had used my computer. I knew that couldn’t be true because Cindi hates my computer.  My laptop is a ThinkPad x61 with a track-point and doesn’t even have a a mouse touchpad.  My laptop hadn’t left my side since last using Facebook and even if it had, she wouldn’t have been able to use it.


Thinkpad Trackpoint


How could this happen?  All the common sense within me says that Facebook would use cookies on my machine as a way to remember me. What I experienced today implies some kind of IP address related connection. That would be stupid right?


We both use the same wireless network but still, that shouldn’t have anything to do with it.  This makes no sense to me, and some might think I’m crazy but I feel a need to share it. It really did  happen so it can only be a flaw in Facebook or some kind of weird network error.


Do you use Facebook at work on a network?  Do you say anything you wouldn’t want you co-workers to see?  Even in private messages? Well, Stop.  The only reason I started to use Facebook was to write about privacy but I never expected this.


If this has happen to you or if anyone has a better explanation… please comment.

Read More
Posted in facebook | No comments

Friday, 13 February 2009

Social Networks are a Ponzi Scheme of Friendship

Posted on 09:37 by Unknown

Are you getting tired yet of the term Social Media or Web 2.0? Have your friends convinced you to join Facebook, LinkedIn, Twitter or some other social networking site? The truth of the matter is that Social Networking is a giant ponzi scheme.


When you first join a social network you start with only a few friends. It could only be your only friend is the one who convinced you to join.  The network typically has no real value until you add more friends and invite them to join.  Many networks will try to harvest your entire contact list in an effort to increase its membership.  So, you Email your friends and family and there’s a new layer of friends supporting the pyramid and the cycle begins again for them. Soon, you reap the benefits of “Friend of a Friend” and the network begins to have value.  As long as there are new users to join the network will be a success.


I don’t know if this is the year we’ll peak with social networks but they’re certainly hot.  According to Pew Internet & American Life Project, 11% of online American adults are now using Twitter. I’m not sure what defines an “online American” but I know I’m one of them.


I mentioned before that I am “Twitterpated” and you can follow me at http://twitter.com/BillP. I also have a WinPatrol information feed at http://twitter.com/WinPatrol that currently has 75 followers. You’ll me on LinkedIn,  Facebook  and you can read why people love WinPatrol on my Fans of WinPatrol page.  It’s only been active a couple weeks and we already have 143 members.  Click below to join. 


WinPatrol on Facebook


Now This is Important
You don’t have to be a member or participate on Twitter to benefit from its huge network of Tweeters.  Search.twitter.com  has become the Google of real-time and current information. Most news organizations are using Twitter to research stories.  When US Airways flight 1549 splashed down in the Hudson I heard it first on Twitter. While on board a ferry racing to the scene, @jkrunms shared a photo taken by his phone via Twitter. Before ABC announced this years line up for Dancing with the Stars, I already had the list from folks on Twitter. It takes Google some time to index the world wide web so if you need immediate info I recommend adding Search.twitter.com   to your favorite places.


Follow @BillP on Twitter!


As Phil Collins sang,  You follow me, and I’ll follow you or was it the other way around? 


 

Read More
Posted in facebook, twitter | No comments

Monday, 17 November 2008

Photo From Your IPAddress Has Been Uploaded

Posted on 05:48 by Unknown

It starts with an innocent message that you think comes from one of your Facebook friends. Below is a classic example of social engineering designed to steal your password.  It didn’t take a brilliant hacker to come up with this scam. It just took someone with evil thoughts and no life.


Facebook message from NOT a friend


I noticed this message on a friends Facebook page this morning and my experience told me right away that something smelled funny. When I cautiously went to the web page listed via my test machine it all become clear.


Bogus error message
First, they try and scare you.


 


Here's where you close your browser with Ctrl-Alt -Del
It might seems safe because they only want your Email right?


DO NOT ENTER YOUR PASSWORD!
If you entered your password, it’s time to go to Facebook
and other sites listed before and change it now.


There's more


Next Step


Here's where they finally get you so they know which password you gave them.
Now, they want to know where to use your name and password.



Final Screen
And finally, you get the final let down.


If you fell for this, you’re not alone.  Like most social engineering scams they use fear to throw you off.


 


 


 

Read More
Posted in facebook, IPAddress, Trojan | No comments

Friday, 7 November 2008

Passwords Up for Grabs on Social Networks

Posted on 07:18 by Unknown

I’m not a big fan of new Web 2.0 Social networks but I have participated in some new ventures. You won’t find me on MySpace, BeBo or other silly services. I am active on LinkedIn which is geared towards professionals and yes, I’m addicted to Twitter. I did join Facebook to write about their Beacon privacy problems and still participate now and then to see what my friends are doing.  I don’t participate in any of the Facebook applications because like many services they always try to trick me into sending invites to my friends.


The services I really hate are the ones who try to get you to hand over your address book so they can spam your contacts with invites to join. In many cases, they just want you to give them access to your Email accounts so they can suck out your contacts and automatically populate your new friends list.  While this might be convenient it can be very dangerous. 


The most annoying is a service called Tagged.
You've been tagged


It Gets Worse


Many sites will transmit your name and passwords as unsecured data. This makes your name and password visible to anyone along the Internet path.


When you’re entering or giving someone else access to your name and password you should first look to see if you’re on a page that is https:// or shows the locked symbol indicating a secure transmission of data.  There’s also a method which can be used encrypt data called OAuth but it’s impossible to know which sites actually support this. 


Recently, I joined BrightKite which allows me to integrate messages to Twitter. They tell me Twitter doesn’t support “OAuth” which means I sent my Twitter login information across the net unsecured. This is scary because there are a wide variety of tools which integrate with Twitter. None of them will encrypt your name/password when logging on to Twitter. So if you see me say something really stupid on Twitter, it might not be me.  Smile


I’m sure you don’t use the same password for different online sites ( cough cough) but in the case of social networks, it’s very important you create different passwords. Just like I periodically remind readers to review their backup procedures, and today is a good day to look at your current password scheme.


 


 


 


 

Read More
Posted in facebook, OAuth, passwords, twitter | No comments

Monday, 26 November 2007

Facebook Recommends IE7

Posted on 10:18 by Unknown

I may have mentioned once or twice that I’m not always the first to upgrade to new versions. When something works for me I’m happy and will continue using it until I have a good reason to upgrade. I still haven’t upgraded to Internet Explorer 7 and haven’t had a good reason to switch. Most of the time I use Firefox but I do occasionally use IE especially on my tablet PC which has some problems with Firefox.

I was surprised when I went to Facebook today and saw that they were encouraging me to upgrade to IE7.

Facebook screen I noticed today

Of course, they’re not just promoting Microsoft's Internet Explorer. They also provided links to Firefox and Opera.

According to my Blog reader stats 46% of my readers are using IE7. Only 16% are still on IE6. I guess it might be time to upgrade. I haven’t heard any horror stories from IE7 users lately. What do you think? Click on “Comments” below and let me know.

Read More
Posted in facebook, IE6, IE7, upgrade | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Support for Downloads without Surprises
    Last week I posted a message about the  packaging of ad supported programs along with popular software. It appears to be a common practice t...
  • Employee Manual to Prevent Cryptolocker and More
    A common way computers are infected or compromised has always been a simple yet well thought out deception. It can happen to anyone and the ...
  • What on Earth is “Cloud” Computing
    The new big buzz word in the computing world is “Cloud” computing. In the past I’ve been critical of the concept and even poked fun at Cloud...
  • SQLite C Code to Read Cookies
    While most of the technology leaking from my brain is for a wide audience, today’s post is very technical in nature. I expected the informat...
  • WinPatrol Cloud Edition Public Beta
    WinPatrol Adds the Newest Technology Available. You’ll now have access the knowledge of thousands of WinPatrol users shared in real-tim...
  • Four Secret Reasons Why Win7 is Ten Times Better
    It’s no secret that I’ve never been a fan of Windows Vista. I really wanted to love it but even as a designated Microsoft MVP I couldn’t dri...
  • Free #1 Tweak to Improve Windows Performance
    Every year billions of dollars are spent by folks just trying to improve the performance of their computers. Over the last couple years ther...
  • Forget the DVD & Save on your New Laptop
    I’ve written before about the coming death of the CD/DVD ’s for data storage.  While that time hasn’t come yet for desktop there is one real...
  • Can Facebook be Trusted?
    Last week Facebook rolled out another round of what they consider easy to use privacy settings. What they’re really doing is trying to appea...
  • TWITTER ALERT
    Anyone who uses Twitter, DO NOT use the Twitter web interface until further notice. There is a code injection vulnerability being used tha...

Categories

  • 2007
  • 3G
  • AAPL
  • ABC
  • accelerometer
  • Achilles
  • Acrobat
  • Activex
  • adobe
  • Ads
  • advertising
  • Adware
  • Adwords
  • Airlines
  • Albany Medical Center
  • algorithm
  • Amazon
  • amber alert
  • AMUST
  • Animation
  • antimalware
  • Antivirus 2009
  • antivirus2008
  • AOL
  • Apple
  • applets
  • AQuantive
  • archive
  • Aruba
  • ASC
  • Ask.com
  • ATI
  • Audio
  • Autorun
  • AutoUpdate
  • autoupdates
  • AVG
  • Azure
  • backup
  • badware
  • Bakugan
  • Baseball
  • battery
  • Ben Edelman
  • Beta
  • BillP
  • Birthdayware
  • Bitlocker
  • Blackberry
  • BlackViper
  • bloatware
  • Blogger
  • Blogs
  • Blogspot
  • Blu-ray
  • Bluehoo
  • bluetooth
  • boinc
  • Bonjour
  • Brazil
  • break
  • Breakaway games
  • Brookman
  • Browser wars
  • C64
  • camera
  • Carpal Tunnel
  • CBS News
  • cell phone
  • CES
  • charity
  • Child Safety
  • chinese
  • Chris Cook
  • Christmas
  • Chrome
  • CIPAV
  • clampi
  • Cloud
  • CNet
  • codec
  • comodo
  • conficker
  • Control Panel
  • copy
  • coupon
  • craplets
  • crapware
  • Crawford
  • credit
  • credit card
  • credit cards
  • ctfmon
  • daylight savings time
  • Dell
  • demo
  • Discount
  • Disney
  • DNS
  • Dollar
  • Domain
  • Donna
  • Doubleclick
  • Downadup
  • Dreamscene
  • droid
  • DVD
  • Dvorak
  • Easter egg
  • eclipse
  • Ed Bott
  • Edelman
  • egreeting
  • Email
  • Environment
  • Epilepsy
  • EU
  • eWeek
  • explorer
  • facebook
  • false positive
  • false-positive
  • FBI
  • file types
  • finnish
  • FiOS
  • Firefox
  • fireworks
  • fix
  • flash
  • Flashpix
  • Fort Drum
  • foxit
  • fraud
  • FTC
  • games
  • garmin
  • Gateway
  • GE
  • George Bush
  • Germany
  • global
  • Godmode
  • Google
  • Google Research
  • GotoMyPC
  • gps
  • green
  • Groceries
  • Habitat
  • Hacks
  • hallmark
  • Halo
  • hard drive
  • Harry McCracken
  • Harry Potter
  • Harvard
  • HD-DVD
  • help
  • hidden files
  • Hijack
  • History
  • Hiton
  • homeland security
  • Honor Flight
  • hosts
  • Hubble
  • IAC
  • ICANN
  • IE
  • IE6
  • IE7
  • IE8
  • installers
  • interface
  • Internet
  • IPAddress
  • iPhone
  • iPod
  • Iraq
  • iTouch
  • iTunes
  • java
  • Kaspersky
  • Kazaa
  • kenmore
  • key logger
  • keygen
  • Keylogger
  • Kosovo
  • LA
  • lady chalupa
  • langa
  • Laptop
  • lawsuit
  • Legoland
  • Levar Burton
  • Linksys
  • Little League
  • Live Writer
  • Live.com
  • localize
  • Logo
  • London
  • LOP
  • lottery
  • Lucasfilm
  • Macintosh
  • Malware
  • Marie Domingo
  • Mary
  • McCracken
  • Media
  • Memorial Day
  • mgrs.exe
  • Micosoft
  • Microsoft
  • Microsoft Surface
  • MiFi
  • mit
  • moon
  • Mossberg
  • Mothers Day
  • MPack
  • MSFT
  • msn
  • MTV
  • Multicore
  • Music
  • MVP
  • MVP09
  • nasa
  • NBC
  • Nero
  • Netbook
  • Network
  • network solution
  • New York
  • newsletter
  • Nintendo
  • Nintendo Wii
  • NNEDV
  • Norton
  • NYAG
  • OAuth
  • obama
  • Office
  • OLPC
  • Olympics
  • OpenDNS
  • oprah
  • optimize
  • optout
  • Paperghost
  • passwords
  • Patch
  • Patriot Flight
  • PC Guy
  • pc pitstop
  • PC World
  • pcmag
  • PCWorld
  • PDC
  • PDF
  • pedipaws
  • performance
  • phishing
  • photos
  • Photoshop
  • Pinnacle
  • Piracy
  • Pirillo
  • pogue
  • Porn
  • pornware
  • postcard
  • prediction
  • prefetch
  • Preview
  • Price
  • privacy
  • Prodigy
  • Programming
  • PSP
  • Public Relations
  • Pytlovany
  • Q-Link
  • Quicktime
  • quotes
  • radio
  • realnetworks
  • realplayer
  • RegCleaner
  • RegCure
  • regedit
  • Registry
  • registry cleaner
  • Release
  • remove
  • Research
  • return policy
  • review
  • RIAA
  • Rivera
  • RMS
  • Road Runner
  • rogue
  • router
  • RTM
  • Rumor
  • safari
  • safety
  • sale
  • Sales
  • Santa Monica
  • scam
  • Schenectady
  • Scoble
  • Scott Dunn
  • Scotty
  • sd
  • Search
  • Sears
  • Security
  • Services
  • seti
  • ShellExecute
  • Shirt
  • SimCity
  • site advisor
  • slingbox
  • snopes
  • social engineering
  • social network
  • solid state disk
  • Sounds
  • Sp3
  • space station
  • SPAM
  • spamhaus
  • Special
  • speedtest
  • Spyware
  • SSD
  • Startup
  • Stats
  • Steve Bass
  • stopbadware
  • storm
  • STS-125
  • Sugar
  • Sunbelt
  • support
  • Symantec
  • tagged
  • Task Catcher
  • Task Scheduler
  • taskbar
  • Tax
  • Techorati
  • techwatch
  • teens
  • temp
  • Thinkpad
  • Thurrott
  • tinyurl
  • Tips
  • TiVo
  • TLD
  • Today Show
  • Toolbar
  • toolbars
  • top ten
  • topten
  • toys
  • Translator
  • transunion
  • Tree
  • Trend Micro
  • tricks
  • trillian
  • Trojan
  • tweaks
  • twitter
  • UAC
  • UI
  • Ultimate
  • Unbox
  • Unboxed
  • update
  • Updates
  • upgrade
  • url
  • USB
  • Utility
  • Valentine
  • Verizon
  • versions
  • Veteran
  • Video Games
  • Vista
  • Vulnerability
  • wall-e
  • war
  • Washington
  • web2.0
  • Webslice
  • WGA
  • Widget
  • WiFi
  • Wii
  • WiiItis
  • wiimote
  • Win7
  • Windows 7
  • Windows Secrets
  • Windows Update
  • Windows7
  • WinPartrol
  • WinPatrol
  • winpatrolflash
  • WinPatrolToGo
  • Winter
  • Wireless
  • Wristband
  • WSJ
  • WWII
  • x64
  • Xbox
  • XO
  • XO Laptop
  • XOActivity
  • Xobni
  • xolaptop
  • XP
  • XP SP3
  • xp3
  • Yahoo
  • Zero Day
  • Zone Alarm
  • Zwinky

Blog Archive

  • ▼  2013 (31)
    • ▼  November (2)
      • Employee Manual to Prevent Cryptolocker and More
      • My First State-Sponsored Attack
    • ►  October (1)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  June (5)
    • ►  May (2)
    • ►  April (3)
    • ►  March (2)
    • ►  February (5)
    • ►  January (5)
  • ►  2012 (30)
    • ►  December (3)
    • ►  November (3)
    • ►  October (2)
    • ►  September (2)
    • ►  August (2)
    • ►  July (3)
    • ►  June (2)
    • ►  May (1)
    • ►  April (4)
    • ►  March (4)
    • ►  February (2)
    • ►  January (2)
  • ►  2011 (28)
    • ►  December (4)
    • ►  November (2)
    • ►  October (4)
    • ►  September (2)
    • ►  August (2)
    • ►  July (2)
    • ►  June (2)
    • ►  May (2)
    • ►  April (2)
    • ►  March (2)
    • ►  February (3)
    • ►  January (1)
  • ►  2010 (44)
    • ►  December (2)
    • ►  November (3)
    • ►  October (3)
    • ►  September (4)
    • ►  August (3)
    • ►  July (3)
    • ►  June (3)
    • ►  May (4)
    • ►  April (4)
    • ►  March (3)
    • ►  February (3)
    • ►  January (9)
  • ►  2009 (90)
    • ►  December (6)
    • ►  November (8)
    • ►  October (6)
    • ►  September (4)
    • ►  August (4)
    • ►  July (12)
    • ►  June (6)
    • ►  May (11)
    • ►  April (7)
    • ►  March (9)
    • ►  February (9)
    • ►  January (8)
  • ►  2008 (122)
    • ►  December (9)
    • ►  November (11)
    • ►  October (14)
    • ►  September (6)
    • ►  August (9)
    • ►  July (9)
    • ►  June (10)
    • ►  May (13)
    • ►  April (8)
    • ►  March (10)
    • ►  February (10)
    • ►  January (13)
  • ►  2007 (155)
    • ►  December (15)
    • ►  November (14)
    • ►  October (12)
    • ►  September (14)
    • ►  August (12)
    • ►  July (13)
    • ►  June (11)
    • ►  May (19)
    • ►  April (17)
    • ►  March (21)
    • ►  February (7)
Powered by Blogger.

About Me

Unknown
View my complete profile