harmony guy, facebook, privacy, application, session secret, hack, faxx, security, socialmediasecurity.com, developers
You are not logged in. Access is limited. Login or see membership information. • Streetwise Security Zone Community
You Must Be Logged In
You must be a member of this group and logged in to rate this post. Please see the links above on joining this group and/or logging in.

To see the list of all blogs, including Scott Wright's Security Views Blog and the Streetwise Security Zone Podcast click HERE. You also can subscribe via an RSS reader, or check the "Watch This" box in the left column to receive news by email of new articles.


Watch this Blog Notify me by e-mail any time a new post is made to this blog.

Scott Wright's editorials on a variety of security issues for non-technical business managers and home computer users. Please feel free to comment and help spread the word that managers need to think about their information security risks.

The Virus Time Machine (e-Book)
Product ID: 00000007

... What You Need to Know (and Wish You Knew Before) About Removing Virus and Malware Infections Before you start down the path of trying to fix a virus infection on your computer, you should really understand what's invol ... More »

Non-Member Price: $4.99

December 2009 Posts

Archives

  Scott Wright's Security Views
Blog Entry

Our Facebook privacy super-hero - The Harmony Guy - don't let him retire before the battle is won

Sunday, December 20th 2009 @ 10:35 PM (not yet rated)    post viewed 2210 times

If you use Facebook, you should thank your lucky stars for people like "The Harmony Guy". This masked avenger - and fellow socialmediasecurity.com blog contributor - spends his spare time fighting to protect your privacy, and all he asks is that Facebook take his well-researched recommendations seriously. But in his latest blog post, The Harmony Guy recounts his futile attempts over the past year to convince Facebook to put some reasonable amount of effort into creating a more secure platform for Facebook applications - like "Photos I Love" - that are used by millions of people, and to keep to its word about monitoring malicious or exploitative Facebook applications. And what is Facebook apparently doing in response to the detailed information about serious vulnerabilities he provides?

He who prefers not to be named says (click HERE for his first-hand account) that Facebook has offered to copy him on their email responses to developers who have questions about securing their applications - presumably so that he can provide a quality check on their advice. This is pretty disturbing. Why on earth would any company that's valued at over a $1 Billion not dedicate a competent, fulltime staff position to  something as important as doing continuous security vulnerability assessments on their own application framework - something The Harmony Guy has been doing up to now in his spare time? I don't blame him for being close to giving up on this thankless mission.

But let's not allow him to throw in the towel just yet. If you read about the series of security holes in Facebook that The Harmony Guy has uncovered - even if you don't understand any of the technical details - it becomes evident that this is a huge, fundamental problem for all Facebook users.  What he's telling us is that he has demonstrated several times how malicious application developers can currently collect more private information about you than your friends can, even when you think your privacy settings are configured to protect your information. If this is the case, you might as well be posting your private information, comments and photos on a public Web page. Shouldn't we be cheering him on to convince Facebook to show us some real commitment to security in order to earn our trust as users?

Until we see more evidence of properly implemented security features, I'm recommending that people assume the worst. Don't put anything into Facebook, or other similar social networking sites, that you wouldn't want to have shown on Fox News tomorrow - no matter what your privacy settings are. This includes any information about your employer, clients, partners or your job that may be sensitive.

Thanks to The Harmony Guy for keeping us informed about the risks he's found in using Facebook and its associated applications. We should not have to depend on the volunteer efforts of security professionals to keep the applications we use safe. Please give him your support and encourage Facebook - and all other software product or service vendors - to invest in professional security  resources if they want us to trust them with private information.

What do you think? Will we ever be able to trust social networking sites with any private information, and what will it take to convince us that the sites are trustworthy?

I am now offering monthly briefings, tailored to organizations that want to build and sustain security awareness for staff. Just because your security team is too busy to do its own training and awareness doesn't mean you can't have an economical way to address human security risks. Please call or email me at the coordinates below...

Scott Wright

The Streetwise Security Coach

Join the Streetwise Security Zone at:
http://www.streetwise-security-zone.com/join.html

Phone: 1-613-693-0997
Email: scott@streetwise-security-zone.com
Twitter ID: http://www.twitter.com/streetsec

To receive weekly security tips and other notices about helpful content available on this site, please make sure you are on my list by clicking HERE, and entering your name and email address.

 

 

Site Meter

 rate this post: very bad poor average good fantastic!
Comments

RickLeir
Personal
RickLeir said on Monday, December 21st 2009 @ 6:28 AM:

For fun, visit facebook with Noscript enabled in your browser. Yesterday Noscript warned us about XSS vulnerabilities when we started a Facebook game. It is time for Facebook to clean up its act. cheers -- Rick


ScottWright
Group Administrator
ScottWright said on Tuesday, December 22nd 2009 @ 11:44 PM:

This just in from "The Harmony Guy"...

"Btw to clarify, Facebook was going to copy me on emails to developers about holes I'd reported to Facebook, not just on general emails."

Thanks for the clarification, THG...

- Scott