I’d like to say we actually went a few weeks without having to talk about Facebook because they weren’t in the news, but in reality, they were. I was just exhausted with the punishment they have been taking in the media ring, and rang the bell out of mercy rather than letting them continue to get pounded, at least on this blog. But break time is over and its time to lace up. Facebook did come out swinging earlier this week, publicizing their last quarter efforts to clean the place up: over half a billion fake accounts have been banned since the start of 2018, and they have removed nearly one billion posts that violated the social media giant’s guidelines. But the wind was snatched from their sails with news of a yet another breach of user privacy as researchers at New Scientist uncover a leak of three million users’ extremely confidential data gathered by an app called My Personality. The app, designed by psychometric researchers affiliated with Cambridge University, gathered in-depth psychological data on over six million users, half of whom agreed to share their data anonymously with 3rd-parties for research purposes.
Pinky-swear to keep this data confidential?
While I’m sure they didn’t intend to out three million people to the internet, a class project uploaded to a popular code-sharing website by university students was found to contain a login and password to the protected database built by the My Personality team. Whoops. And that data was there, available for the public to access, for 4 years. Double-whoops. Here’s the thing: in order to gain access to this data originally, one had to register for access, and were supposedly bound by a strict confidentiality clause. Two-hundred and eighty people from 150 companies did register, but you can bet at least an equal number (and probably many more) did not, once they discovered the “backdoor” uploaded to GitHub. And the thing with data, once it’s out of the barn, there is no telling where it went from there. There’s a hard lesson to be learned from all of this: it’s extremely difficult to control data once you relinquish any control on it, and this control all but vanishes literally one step from that first line of control, as managing the chain of custody scope expands exponentially. You can liken this to the old party game of “Telephone”, but instead of the message getting muddled with each person, the security and responsibility get hopelessly mangled literally in the next whispered exchange.
We might be setting a blog record as Facebook makes our front page for the fourth week in a row. Lest you think I’m resting on my laurels and taking easy swings at low hanging fruit (mixed metaphors for the win!), Facebook’s fall from grace might be the biggest tech story of the decade, and this is happening alongside Intel’s monstrous security flaw, the Equifax breach (remember that one?), and the dismantling of Net Neutrality. And those are just the ones I can recall off the top of my head! I’d love to be writing about other things, but due to its sheer size and global reach, this evolving disaster is something from which we cannot (and must not) look away. The Cambridge Analytica debacle is the gift that keeps on giving, but unfortunately it’s the mother of all white elephants as far as Zuckerberg et al. are concerned, and I’m sure a large helping of “do not want” is being served around the table at Chez Facebook.
It’s like watching a slow-motion derailment
Mark Zuckerberg may be one of the richest technocrats on Earth at the moment, but that didn’t stop Congress from skewering him in a multi-hour, publicly televised congressional hearing. On the whole, I’d say he’s lucky some of the Senators are in their 60’s and 70’s, and clearly did not have a solid grasp of Facebook’s technology, allowing him to sidestep some of the more naive or ill-informed questions. But several, more savvy Senators put him square into a glaring spotlight that he could not dodge: What is Facebook doing to combat hate speech? Is Facebook a Monopoly? Are Cambridge Analytica and Russian “troll farm” Internet Research Agency somehow connected? Was Facebook selectively biased towards left-leaning content? Perhaps most telling was Sen. Durbin’s (D-Ill.) line of questioning: “Would (Zuckerberg) share the name of the hotel he stayed in last night?” to which the CEO responded, “No, I would not choose to do that publicly here.” Audible laughter from the room rang that point home.
Given the attention focused on digital privacy, two US Senators have hitched a new bill to the hype train named the CONSENT (Customer Online Notification for Stopping Edge-provider Network Transgressions) Act which calls for much more strict and well defined consent from consumers, putting the onus on providers to secure a user’s affirmative consent, ie. “opt in” as opposed to the current policy trend of requiring users to “opt out.”
And in case you need any more confirmation that Facebook might not have your best interests at heart, California’s own Senator Kamala Harris zeroed in on what I believe is a key takeaway from this current circus. When asked by Sen. Harris, point-blank, about the decision made at Facebook in 2015 to not notify users that their data had been inappropriately shared with Cambridge Analytica, Zuckerberg admitted, “in retrospect it was a mistake.” This was an important question, as Facebook’s failure to notify users of this breach is probably a direct violation of a deal the internet company reached with the SEC in 2011 that barred the company from making misrepresentations about the privacy or security of consumers’ personal information.
In case you are curious as to whether your information was shared with Cambridge Analytica in the breach mentioned above, you can click this Facebook link for an immediate look at what, if any, of your personal information was shared.
Last week’s breach of Italian security firm Hacking Team exposed documentation that detailed the firm’s use of previously unknown security weaknesses in Adobe’s pervasive Flash platform. Typically known as “zero-day” vulnerabilities, these types of holes are being exploited by cybercriminals from the moment they are discovered, and companies will scramble madly to patch the problems and distribute the fix to their customers. Apparently fed up with the ongoing security failures of the plugin and Adobe’s lackluster speed at fixing them, Mozilla has started blocking outdated Flash plugins from running in Firefox, and Facebook’s security czar has called for the troubled platform to be retired:
It is time for Adobe to announce the end-of-life date for Flash and to ask the browsers to set killbits on the same day.
— Alex Stamos (@alexstamos) July 12, 2015
What this means for you:
If you are the owner of a website that uses Flash, you should review whether its use is optional or required, with the latter choice presenting numerous challenges, including alienating a large segment of your mobile browsers; both iOS and Android require special, third-part apps to run Flash that are typically not free. Adding this to Google’s latest ranking algorithm which disfavors sites that aren’t mobile friendly, and you could end up with a website that gets relegated to a dark corner of the internet.
As a website visitor, at minimum you should update your Flash plugin immediately, and only do so by getting the latest version from Adobe’s website. Do not follow links or popups that appear while visiting websites – 99% of the time they are not legitimate and will lead to a malware infection. If you’d prefer to stop using Flash altogether, you can follow these instructions to make Flash ask for permission every time it runs:
Like the predictable “tick-tock” of a clock, reports are coming in of an infection spreading rapidly through Facebook via a fake Flash Update. The “tick” in this case was the report last week of a zero-day Flash vulnerability, and the subsequent legitimate update of the Adobe Flash plug-in. Not wanting to miss an opportunity, cybercriminals have released the “tock” – a video on Facebook is tricking clickers into installing a set of malware that can take complete control of the victim’s computer. Over 100k have fallen for this scam which is only 2 days old as of this writing.
What this means for you:
If you see a warning pop up on your computer that software on your computer may be out of date, it may be legitimate, and it may not be. With Adobe Flash, it’s very easy to check by going to Adobe’s own Flash website http://helpx.adobe.com/flash-player.html. Also be wary of the source of the update warning, such as that which comes from clicking on a dodgy link on Facebook or in an email. Doublecheck it against a legitimate source. Not sure what that source might be? Your trusted IT professional is only a quick call away. Spending five more minutes to vette that update warning is certainly worth avoiding a malware infection, right?
If you’ve spent any time at all on the internet, you are probably painfully aware of how people can do and say dumb things on online. For most, it’s probably fortunate that their antics were merely foolish, as the American justice system has begun to take a rather dim view of online threats by throwing internet loudmouths behind bars. Among those made an example of is Anthony Elonis, a Pennsylvanian man who served nearly 3 years in prison for making a variety of threats on his Facebook page against his ex-wife, co-workers and law enforcement. All the alleged threats were, according to him, merely expressions of creativity, “rapping to his Facebook friends.” Surprisingly, the US Supreme Court has decided to hear Anthony Elonis’ appeal of his conviction on the basis that he never intended to carry out these threats, and there may be legal precedents that support this position.
What this means for you:
I’m no Supreme Court Justice, but I do know that things published on the internet, particularly social media sites like Facebook, rarely stay private, and I think it’s a safe bet that publishing something on Facebook means that you want people to notice what you posted. However, things like Facebook and the Internet also cloud the determination of whether the poster actually intended for offended or threatened parties to view that content at all. The cynical among us will say, “Of course they wanted this to be read by everyone, including their target. This is the Internet. Nothing is private.” But, Facebook promises us that our posts will only be as public as we allow them to be, right? Only our small circle of Facebook friends can see this, right? A US court has already ruled in favor of one internet loudmouth who, in a drunken stupor, threatened to shoot the President on a Yahoo discussion forum.
Were these online bozos behaving poorly and exhibiting terrible judgement? Absolutely. Did they commit an actual crime? It’s still up for debate, says the Supreme Court. For the time being, my advice on this subject remains the same: Never say anything online (email, Facebook, Twitter, whatever) that you wouldn’t want plastered all over the CNN website front page the next morning.
Image courtesy of Stuart Miles / FreeDigitalPhotos.net
It’s an unfortunate but not unexpected state of affairs that hackers continue to take advantage of our voracious appetite for news. As has been happening with hot news stories for at least a year or more, malware links are cropping up to exploit the media frenzy surrounding missing Malaysian Flight MH370. Taking advantage of the viral nature of sharing prevalent on Facebook and Twitter, fake links promise “shocking video” revealing the fate of the missing flight. Clicking them takes you to a counterfeit survey designed to look like the Facebook surveys many app-makers use to gather info on users before granting access to their app or content. Instead of course, you are giving your info to hackers on a fake website which will undoubtedly be used to annoying, or worse, nefarious ends.
What this means for you:
If I’ve said it once, I’ve said it 1000 times: don’t click links in Twitter, Facebook or email, doubly so if the source isn’t someone you trust or recognize, and you can’t clearly see the destination URL. Most links shared on Twitter use a URL shortener which obscures the final destination, a technology designed originally to compress long URLs into tiny ones and now used as a trick by spammers and hackers to lure you to a fake website. All it takes is a simple page load (no typing or filling in forms required) for an out-of-date browser or OS to be compromised, and once they have a toe in the door, it’s all down hill from there.
From this point forward, you should expect hackers will exploit hot news items to take advantage of our natural curiousity. If part of your online brand-building, either professionally or personally, includes re-sharing or retweeting internet links, be careful you don’t inadvertently share a fake news item to your friends and followers.
Image courtesy of Stuart Miles / FreeDigitalPhotos.net
I can count on one hand the number of people that have said to me, “There’s not enough stuff on Facebook!” without using any fingers (and she was new to Facebook). More often, I hear, “I can’t keep up,” or “I have to sort through a lot of fluff to find anything good.” According to an opinion piece published in Business Insider, Facebook appears to be collapsing under the weight of its market dominance that is only exacerbated by the ease of posting anything to their stream from just about any device. So take this fire hose of updates from everyone you know and add video advertisements that will automatically play as they appear (sound muted…for now).
Yep, Facebook is adding commercials to your already overflowing news stream.
What this means for you:
If you weren’t already avoiding Facebook, in-line video advertisements might just push you over the edge. Advertisers seem to be salivating at the prospect, with some analysts predicting 1-day 30-second spots costing millions of dollars, but with the potential of reaching billions of viewers. Seeing as Facebook can segment their users into just about any size demographic target, they may start carving up the ad space into more affordable chunks, giving us the social media equivalent of late-night cable community channel or local TV station commercials. I’m only guessing, but this might raise the banality factor a bit too high for most folks, and Facebook could continue to see an exodus of its highly-prized 18-24 demographic as they move on to more focused and less spammy social media platforms like SnapChat, Instagram and WhatsApp.









