ARN

Facebook tool could be exploited by cyber-bullies

Personal attacks capable with new Facebook tool, security vendor warns

A recent Facebook feature can be exploited to be a cyber-bullying tool in the wrong hands, a security vendor warns.

Facebook's new feature – "reply to this e-mail to comment on this status" – gives attackers a way to post messages on other people's Facebook pages, according to a blog by security vendor F-Secure.

These messages could include personal attacks that seem to come from a user but are actually written by someone who has compromised that person's e-mail account, for instance.

The intent of the feature is to allow Facebook users to respond directly from their e-mail when they receive e-mail notifications that include messages that have been posted to their Facebook accounts. They can respond without having to go to the Facebook site first, eliminating a step and thereby saving time.

But eliminating that step can also leave a crack in Facebook's armour, according to F-Secure security adviser for North America Sean Sullivan. Authenticating to the Facebook site before writing a reply drops out of the equation, so someone other than account holders can post. "They can put words in my mouth," he says.

If a user's e-mail account is compromised via phishing or direct hacking, spammers can respond to any Facebook notifications they come across, Sullivan says. It has posted a demonstration of how this can work here.

Facebook users can opt out of receiving the e-mail notifications altogether by adjusting their settings.

Nominations for the 2012 ARN IT Industry Awards open on Tuesday, June 12.

More about: Facebook, F-Secure
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the ARN comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
rhs_login_lockGet exclusive access to ARN's news, research and invitation only events.
ARN Distributor Directory
ARN Vendor Directory

iAsset is a channel management ecosystem that automates all major aspects of the entire sales,marketing and service process, including data tracking, integrated learning, knowledge management and product lifecycle management.