Showing posts with label Twitter. Show all posts
Showing posts with label Twitter. Show all posts

Aug 9, 2010

Robin Sage revisited

I recently blogged about a ComputerWorld interview with Tom Ryan who posed as cyber-hacking ingenue, Robin Sage, to see what kind of friends Robin could connect to in the intelligence business. This experiment, while unscientific, had the potential to reveal some interesting data points on how people connect, trust, and accept identities.

Accordingly, Mr. Ryan delivered his findings at the BlackHat conference a couple of weeks ago. My friends over at SecurityCurve posted a disappointed review of the talk.

It’s not that the discussion didn’t lay out how Tom Ryan did what he did – oh sure, there was plenty of that. He even had the woman whose picture he pilfered in attendance. But at the end of the day, the discussion was very heavy on the titillation factor: from the girl he exploited to the practitioner he embarrassed via their connection to a wife swapping site. But why do we care? So he tricked some people into friending him… And (surprise, surprise) Facebook and Twitter make it easy to link together various information about someone – that’s the point. So if you went into that talk wondering why you should care, you came out of it the same way.

It's really too bad Mr. Ryan didn't dig a bit deeper into the security ramifications of the ease in creating relationships on-line. BTW Diana at SecurityCurve told me that the name Robin Sage is likely to be a red flag for anyone trained in covert operations, which is probably why no one in the CIA or FBI accepted the friend request.

Still, despite the anemic analysis of the Robin Sage experiment, the issue still stands; what are the criteria that people use to make on-line connections and how deep does that trust go? Clearly Mr. Ryan experienced more than a cute face and a blue-chip pedigree gets you connected. His final comment in the CW interview points to the fact that it was Robin's contacts that got noticed:

Toward the end of the experiment, there was this massive influx of Arabs from overseas that were trying to get on the Robin page where all the military stuff was. I didn't really care for it. That was a bit scary.

Aug 2, 2010

Will the real Robin Sage please stand up?


"I had access to e-mail and bank accounts. I saw patterns in the kind of friends they had. The LinkedIn profiles would show patterns of new business relationships."

This is a quote from a ComputerWorld interview with Thomas Ryan, a security professional who created a fake persona to see how much information he could access via social networks. He stacked the deck by creating a young, cute, and highly intelligent woman, Robin Sage, and put her out on Facebook, LinkedIn and Twitter. The flirtatious cybergeek was able to make a few hundred friends in Intelligence and Government circles and gained access to sensitive information. It's an interesting lesson based on common sense: "The big takeaway is not to friend anybody unless you really know who they are." Like the recent Soviet Spy discovery, a cute face with a smarty pants background goes a long way in how we "trust" someone.

Fake femme fatale shows social network risks - Computerworld

May 21, 2010

Herre we go again...

Sigh, this is classic for anyone who's worried about data privacy when developing web-based apps. The WSJ reports today that:

The practice, which most of the companies defended, sends user names or ID numbers tied to personal profiles being viewed when users click on ads. After questions were raised by The Wall Street Journal, Facebook and MySpace moved to make changes. By Thursday morning Facebook had rewritten some of the offending computer code.

Advertising companies are receiving information that could be used to look up individual profiles, which, depending on the site and the information a user has made public, include such things as a person's real name, age, hometown and occupation.

So if you click on an ad from your profile page, the referring URL is sent to the advertiser without being scrubbed. Looks like steps are being/have been taken by at least Facebook, but this is a rookie mistake. To ameliorate the sting of yet another Facebook privacy smack-down, other social networks are doing the same:

In addition to Facebook and MySpace, LiveJournal, Hi5, Xanga and Digg also sent advertising companies the user name or ID number of the page being visited. (MySpace is owned by News Corp., which also owns The Wall Street Journal.) Twitter—which doesn't have ads on profile pages—also was found to pass Web addresses including user names of profiles being visited on Twitter.com when users clicked other links on the profiles.

And don' tell me advertisers armed with URL referrers back to user profile pages are making sure they are getting user's consent before looking at the profiles.

Facebook said its practices are now consistent with how advertising works across the Web. The company passes the "user ID of the page but not the person who clicked on the ad," the company spokesman said. "We don't consider this personally identifiable information and our policy does not allow advertisers to collect user information without the user's consent."

A URL referrer (i.e., user ID of the page) is a technicality; if it goes back to the user's profile page then it is a breach of a policy not to divulge personally identifiable information to 3rd parties.

I repeat myself, I'm glad all of this is happening. The social media is growing up and it's the consumers that are ensuring that things are getting safer out there. Apparently when experts expose security issues the fixes languish:

The sharing of users' personally identifiable data was first flagged in a paper by researchers at AT&T Labs and Worcester Polytechnic Institute last August. The paper, which drew little attention at the time, evaluated practices at 12 social networking sites including Facebook, Twitter and MySpace and found multiple ways that outside companies could access user data.

I know it's hip to buck the established/academic technology world in social media tech circles, but sometimes these smarty-pants can actually help to prevent some embarrassing moments.

Facebook, MySpace Confront Privacy Loophole - WSJ.com