online social networks: 5 threats and 5 ways to use them safely

17
Online Social Networks 5 threats and 5 ways to use them safely Photo provided by http://flickr.com/photos/luc/1804295568/ via GNUCITIZEN

Upload: tom-eston

Post on 28-Nov-2014

6.775 views

Category:

Technology


1 download

DESCRIPTION

I spent the last few months doing research on various social networks specifically MySpace, Facebook, LinkedIn. Many of us either use these sites or know others that do. Users of these sites have been increasing at a dramatic rate for several years. For example, MySpace was the most visited website in the US with more than 114 million global visitors in 2007, and Facebook increased its global unique visitor numbers by 270% last year alone. With this massive increase in social network usage, online social networking is now becoming the fastest growing area of privacy concerns and security threats.

TRANSCRIPT

Page 1: Online Social Networks: 5 threats and 5 ways to use them safely

Online Social Networks

5 threats and 5 ways to use them safelyPhoto provided by http://flickr.com/photos/luc/1804295568/ via GNUCITIZEN

Page 2: Online Social Networks: 5 threats and 5 ways to use them safely

What are Online SocialNetworks?

Online community of Internet users Users share common interests

− Hobbies− Religion− Politics− Friends− Schools

Multiple ways for users to interact such aschat, messaging, email, video, voice chat, filesharing, blogging, discussion groups...

Page 3: Online Social Networks: 5 threats and 5 ways to use them safely

Who uses Online SocialNetworks?

Most popular with“Generation-Y”

“Teens and Tweens” “Generation-X” and

older is the latesttrend

Page 4: Online Social Networks: 5 threats and 5 ways to use them safely

Most Popular Social NetworkingWeb Sites

Page 5: Online Social Networks: 5 threats and 5 ways to use them safely

Top 5Threats to Online Social Networks

Page 6: Online Social Networks: 5 threats and 5 ways to use them safely

#1Cyberbullying, stalking, and sexual predators

Teens bashing other teens... Megan Meier suicide MySpace released a report in 2007 showing

29,000 registered sex offenders on MySpace

Page 7: Online Social Networks: 5 threats and 5 ways to use them safely

#2 Vulnerabilities in Applications/Widgets

Widgets, third-party applications XSS (Cross Site Scripting) Samy/Quicktime Malicious banner ads/background images (Alicia

Keys’) Be careful! Some applications will override privacy

settings!

From the blog post: “Invading the Space: Alicia Keys’ MySpace and… RBN?”http://blog.trendmicro.com/invading-the-space-alicia-keys-myspace-and-rbn/

Page 8: Online Social Networks: 5 threats and 5 ways to use them safely

#3 Spear Phishing and SPAM

Fake “friend requests” Emails that look like they are legitimate!

Screen shot courtesy of Paul Asadoorian, pauldotcom.com

Page 9: Online Social Networks: 5 threats and 5 ways to use them safely

#4 Collection and aggregationof personal data

Most privacy policies are very vague Think about it...$35 per user when MySpace

was sold to News Corp in 2005 Sites like Plaxo aggregate all of these social

networks together

The following is an example of a privacy statement:

“[SNS Provider] also logs non-personally identifiableinformation including IP address, profile information,aggregate user data, and browser type, from users andvisitors to the site. This data is used to manage thewebsite, track usage and improve the website services.This non-personally-identifiable information may beshared with third-parties to provide more relevantservices and advertisements to members.”

- From the ENISA position paper “Security Issues andRecommendations for Online Social Networks

Page 10: Online Social Networks: 5 threats and 5 ways to use them safely

#5 Evil Twin Attacks

Fake profiles Reputation slander Corporate espionage (LinkedIn) Weak authentication of the user (are you who

you say you are?)

Chris Pirillo by Alan Berner - The Seattle Times

Page 11: Online Social Networks: 5 threats and 5 ways to use them safely

Top 5Ways to Safely use

Online Social Networks

Page 12: Online Social Networks: 5 threats and 5 ways to use them safely

#1 Set appropriate privacydefaults

All Social Networking sites have wide-openprivacy defaults!

Page 13: Online Social Networks: 5 threats and 5 ways to use them safely

#2 Be careful with third-partyapplications/widgets

Some of these applications will overrideprivacy settings

Example: “Secret Crush” Facebookapplication− Installed adware “worm”

Photos from Fortinet: http://www.fortiguardcenter.com/advisory/FGA-2007-16.html

Page 14: Online Social Networks: 5 threats and 5 ways to use them safely

#3 Limit personal information

Don’t post your full name, SSN, address...etc... Be cautious about posting information that

could be used to identify you or locate youoffline

Careful with choosing an online alias and whatit says about you

“The more info you share, the more valuable you are”

Page 15: Online Social Networks: 5 threats and 5 ways to use them safely

#4 Only accept friendrequests/connections from people

you know directly Most are SPAM Most are bots that want to trick you! LinkedIn

− Be aware of corporate espionage!

Page 16: Online Social Networks: 5 threats and 5 ways to use them safely

#5 Only post information your motheris comfortable seeing!

Anyone can view these photos includingemployers, friends, and enemy's

Don't trust a private profile!

“Use common sense!”

Page 17: Online Social Networks: 5 threats and 5 ways to use them safely

Questions?

[email protected]

http://spylogic.net