IT Reseller Magazine
Article Search: Go To: Keyword 
 
   

FREE Subscription to IT Reseller Magazine






Internet Security
Internet control, email and network protection


New Facebook profile design marred by security slip-up
July 21, 2008  

Privacy breach exposed users' hidden dates of birth

Sophos, a world leader in IT security and control, has warned computer users that Facebook accidentally publicly revealed personal information about its members, which could be useful to identity thieves. Earlier this week, the full dates of birth of many of Facebook's 80 million active users were visible to others, even if the individual member had requested that the information remained confidential.

According to Graham Cluley, senior technology consultant at Sophos, a security slip-up by the website during the process of a public beta test of its new design for members' profiles left birth date information exposed.

"I was shocked to see people's full date of birth revealed, even though I knew they had their privacy set up correctly to supposedly hide the information," said Cluley. "It's essential that users of social networks should have confidence that their privacy will be protected - and it's especially important with information like your date of birth, which can be a golden nugget for a committed identity thief."

Cluley says he informed Facebook as soon as he discovered the flaw, which now appears to have been fixed.

"It's good that Facebook fixed the problem - but can people feel confident that this kind of mistake won't happen again in future?" he asked. "My advice to Facebook users would be, even if your date of birth is set to be non-visible, change it to a made-up date in case this kind of blunder happens again. Facebook and other social networking websites need to be more careful about protecting their members' data, or risk losing users."

Sophos noted that birth dates were exposed via the new design that Facebook is trialing for its personal user profile pages, which currently can be accessed via www.new.facebook.com. According to the Facebook developer’s blog, Facebook will start rolling out the new profile page design to users this week.
 
Facebook's new design for its profile pages, revealed members' personal information even if privacy settings had stated it should be hidden.

Last year, Sophos published results of a identity theft probe into Facebook which uncovered that 41% of users, more than two in five, would divulge personal information - such as email address, date of birth and phone number - to a complete stranger.

Sophos has published a video on its YouTube channel, demonstrating the security hole.


About Sophos

Sophos enables enterprises all over the world to secure and control their IT infrastructure. Sophos's network access control, endpoint, web and email solutions simplify security to provide integrated defenses against malware, spyware, intrusions, unwanted applications, spam, policy abuse, data leakage and compliance drift. With over 20 years of experience, Sophos protects over 100 million users in nearly 150 countries with its reliably engineered security solutions and services. Recognized for its high level of customer satisfaction and powerful yet easy-to-use solutions, Sophos has received many industry awards, as well as positive reviews and certifications.

Sophos is headquartered in Boston, US and Oxford, UK


Other Internet Security News Security White Papers
Sourcefire launches Razorback, delivering a framework for multi-vendor threat detection and protection
Sourcefire, Inc., the creator of Snort and a leader in intelligent cybersecurity solutions, has launched Razorback, an open source framework designed to deliver deep inspection capabilities for combating today's most complex threats.
Trusteer warns financial malware is attacking leading US banks using Visa and MasterCard
Trusteer has announced that the Zeus (Zbot) financial malware is targeting online banking customers of 15 leading US financial institutions by exploiting two trusted credit card security programs.
Barracuda spam & virus firewall offers broader outbound email content filtering capabilities
Barracuda Networks Inc., provider of security, storage and networking solutions, has announced new features to its flagship Barracuda Spam & Virus Firewall that enhance full inbound and outbound email scanning from the same appliance.
Over half of IT professionals are still leaving mobile security to chance
As threats to corporate data grow, and the cost of breaches increase, a survey of alleged security conscious professionals has remarkably revealed that over half of respondents (52%), who admit to carrying company data on a USB stick, do not encrypt it.
Webroot announces channel expansion in Ireland
Webroot has announced its plans to recruit an additional ten strategic channel partners in Ireland, to expand the availability of Webroot Web Security Service, Webroot Email Security Service and Webroot Email Archiving Service.
What every CEO should know about advanced persistent threats and industrialised hacking
The world of hacking has evolved into two major varieties: industrialised attacks and advanced persistent threats (APT).

More >>

Understanding the value of outsourcing network security services
This white paper will examine the many new challenges that are facing today’s network owners, the pros and cons of using in-house resources and outsourcing for your network assessment and day-to-day monitoring, as well as guidelines to help select and maximize the value of outside resources.
GFI warns one anti-virus engine is not enough to protect your business
Although 99% of large British companies use anti-virus products, 43% were still infected by viruses (UK ISBS Survey 2006)
CONTENT FILTERING SOLUTIONS TECHNOLOGY REPORT APRIL 2006
Source: West Coast Labs/Netintelligence
The Trend of Threats Today: 2005 Annual Roundup and 2006 Forecast
Trend Micro
The report that follows is not only an account and analysis of 2005 threat
incidents. It also serves as a forecast of what the future holds in 2006 and
onwards. Through Trend Micro‘s extensive research and analysis of the 2005
incidents, this paper documents how threats evolved into the multi-purpose
threat regime – thus providing corporate and home users information on what
to do to ensure they remain protected against future threats. Download free white paper.
If you can't beat it, manage it
David Caughtry of Computerlinks looks at the challenges facing IT managers with the growing use of Instant Messaging in the workplace.
Are you becoming a one-stop security shop?
David Ellis, director of e-security at Unipalm discusses best practice security management and the evolution of protection technology.

More >>

advertisements


 



Related Articles


Let the news come to you!
Subscribe to our weekly newsletter and the digital edition of IT Reseller Magazine!

Email Address:   



© Copyright 2006, IBC - Interactive Business Communications

Help | Contact Us | PrivacyRSS Feeds | Site Map | Advertise
YourTechTV.com Only Technology Videos