Sunday, January 17, 2010

Yeah, privacy's dead when it's this easy to be someone else

I can't help but love this story.  Shoot, I can't help but love this story title:

Dumbfounded: Smart phones breach Facebook security

This is beyond cool. Who cares if you can watch Sunday football through an AT&T coverage map, when what little network they've got will let you seamlessly login to someone else's Facebook account via your smartphone?

"Fortunately, the vulnerability would be of limited use to a hacker interested in pulling off widespread mayhem because the hole would let him access only one account at a time."

I beg to differ. I think the amount of mayhem a creative miscreant could pull off would vary greatly depending on whose account they accessed, not how many. C'mon, people, let's start thinking about quality vs. quantity here. Sarah Palin's Yahoo mail hack pales into insignificance. Zuckerberg's entire personal photo album plastered on Gawker suddenly seems boring. To heck with being ->insert your dream/nightmare here<- for a day - how about an hour? Or even five minutes? Oh, the possibilities!

Four questions immediately spring to my mind:

Is this another Facebook (non)privacy feature giving users exactly what they want?

How soon will Google work this into the Nexus?

Is there an iPhone app for this?

Am I gonna burn for all eternity because my imagination is in overdrive and I've got a serious case of the giggles...?

Saturday, January 16, 2010

This Luddite still cares about privacy

Apparently, privacy is not only really, really dead, but anyone who cares about that fact, or thinks there's any point in guarding any last spark of life remaining, is out of step with the rest of humanity, and in fact, a complete Luddite.

Move over, fellow Luddites, here I come. Count me as one of the I am not We Tribe.

From where I sit tending my little fire, it appears the Privacy Is Dead advocates largely fall into two groups:

Those who don’t care about others privacy because they stand to make a pile of money off it;

Those who don’t care about their own privacy because they’ve already sold it.

That much of our privacy is already long gone isn’t even a relevant argument. All we’ve really done is complete yet another circle and come back to the lack of privacy people took for granted when everyone DID still live in caves.

Eventually, though, some people probably started picking out their own corner of the cave so they could get a *little* privacy. I don’t know if they got whacked with a mammoth bone by one of the cave Social Leaders and told “Don’t bother trying that, your privacy’s already so much sabertooth scat.”, but if they did and they didn’t like it, they had the option of going out and finding a cave of their own. If they turned around and invited a whole bunch of other people to join them, well, that was their choice.

What the Privacy Is Dead theory tries to convince us is that we don’t have that option anymore, and with that I disagree. I’d go even further and say it seems some (marketers) are determined to pound home (with or without mammoth bones) the notion that we don’t even have the right to TRY to have that option, and with that I REALLY disagree.

I’m not going to give up fighting for my own corner of the cave. If I have to go find another cave and start over, so be it. If I do, you’d better believe I want control over who – if anyone – I decide to invite to join me.  Maybe I'll just visit with a few like-minded neighbors from the caves next door.

I’m not worried about keeping out the sabertooths, either. I’m pretty handy with those mammoth bones. :-P

Friday, January 15, 2010

Haiti shake up leads to cyber shake downs

When disaster strikes, there's a bunch of people who mobilize with lightning speed, calculated precision, and numerous approaches of varying creativity. Unfortunately they're not with the Red Cross, the United Nations Foundation, or even PETA (a group definitely known for quick mobilization). They're the scamming sharks of cyberspace, and they're in a full fledged feeding frenzy.

They spread attention grabbing rumors laced with dangerous links via Twitter, Facebook, and other social networks. They churn out sweeptakes winning volumes of spam. They heavily seed their existing driveby download websites with related keywords to increase their search rankings, and rush to register new domain names, where they may later set up more malware traps at their leisure.

I applaud the good will of those who give the benefit of the doubt, but sadly I'm far too cynical to believe that (most of) these domains are being parked for legitimate purposes. 1,000+ Haiti disaster related domain names snagged since the event? By the time this stampede of Good Samaritans goes back and adds any legitimate functionality to all those websites, Haiti will be several generations past the current crisis. Maybe they're just really forward thinking. Having so many websites already set aside could save hours, even days, up front in the event of another disaster.

However, rather than checking back on where these potential avenues of aid may lead, it's probably a better idea stay on paths already known, and heed warning signs along the way. It's a shame there are so many who will take advantage of people trying to do the right thing, in order to do the wrong thing. If folks keep their wits (and wallets) well enough to do the right thing the right way, the victims will more likely get the help they so desperately need.

Tuesday, January 5, 2010

Chain emails - the gifts that won't stop giving

I'll start off here with a disclaimer: not every chain/mass email is a malware spreading missive of misinformation, or yet another piece of scammer spam. Some truly are amusing, inspirational, or even informative. I've received things that have made me laugh out loud, moved me to tears, or been worthy of sending on in turn to other potentially interested parties. But like just about everything else on the intarwebs, the noise to signal ratio is high, and gems among the junk are far and few between.

A few months ago, I received yet another chain email from a friend who seems to do little with her inbox other than forward the daily contents to everyone in her address book. We've all got one: that friend or relative who happily shares every junk item they receive, apparently with the belief that someone, somewhere, will find it of some value, or perhaps with the fear that they really will get run over by a transit bus if they don't forward Oprah's Secrets For Success to at least seven people. Filtering my nearest and dearest straight into the spam folder isn't a viable option, and requests to be excluded from future mass mailings seem to be the one type of email that never gets through, so I usually just hit [delete] and move on.

However, this email was not only utter garbage, it was utterly outdated garbage. If you're going to send me crap, at least make an effort to send current crap. This time, I was compelled to compose and send a thorough reply.

Either $Friend ignored my reply or never saw it (I'd bet the latter; it probably got buried in a pile of Acai Berries), because the very next morning I received several more spam servings from her. With a little luck, she at least stayed true to form and forwarded my email to everyone in her address book. In case she didn't, and for the benefit of the few people left on the planet who aren't in her address book, I am posting an "open letter" version of my reply here. Hopefully it will resonate with many...and actually sink in with a few.

Dear Friend,

You know I love you dearly, but you need to not be forwarding this kind of stuff. I'm not even sure you DID forward it on purpose; this sort of spam often is spewed out by an infected computer behind the scenes without the owner even knowing it is happening. Hubby got the same email from you, and when he opened it, it suddenly copied itself all over his inbox - viral red flag behavior for sure. Girl, we want to see you SAFE, online and off. We can't do much about the latter, but we do the former for a living as best we can, for anyone and everyone (un)lucky enough to get on our radar. So, here goes:

1) "THIS TOOK TWO PAGES OF THE TUESDAY USA TODAY - IT IS FOR REAL"

No, it's not. It never was, never has been, and never will be. Honestly, just about every time I see something that blares out in all capital letters "IT IS FOR REAL", that's a dead giveaway it's NOT. And the more "!!!!" that follows said blaring, the more fake it generally is. That it was supposedly real in USA TODAY is the final capper. C'mon - when was the last time anything in USA TODAY was for real?? ;-P

2) "SORRY EVERYBODY.. JUST HAD TO TAKE THE CHANCE!!! I'm an attorney"

All tacky lawyer jokes aside, no self respecting attorney would be forwarding junk chain-email. Unless they're A) really bored and doing it for a joke or, B) their infected computer is doing it for them behind their back. Oh, and notice it's ALL CAPITAL LETTERS and has 3 "!!!" after it. DING DING DING - THAT'S A FAIL!!!

3) "Bill Gates sharing his fortune."

No, he's not. Bill Gates won't even share his fortune with his own kids, from what I hear. Oh, and FYI, Big Bill retired from Microsoft over a year ago - that IS a fact.

4) "It's all marketing expense to him."

No, but somewhere along the line it's probably "marketing" *income* to the yellow bellied pondscum sucking mouthbreathing spammer(s) who *start* these kinds of things, and who obfuscate themselves so that they're nearly impossible to trace. You are not "bound to get at least $10, 000.00". All you are bound to get, eventually, is bounce back notices from friends whose email inboxes have filled to capacity from viral emails like these. Or whose computers have crashed all together.

5) "Please forward this to as many people as possible." <-- **DANGER WILL ROBINSON, DANGER** If there's one written phrase in the English language that'll make me immediately smack the delete button, it's that. Well, that and hearing from some Nigerian banker that an Uncle I never knew I had just got killed in a plane crash and left me $5,000,000. All I have to do to claim it is send Mr. Noobiscam my bank account information and contact his lawyer perrymason@hotmail.com. Um, yeah. I'll get right on that. IMPORTANT (yeah, I know, all caps. So contact the "attorney" who sent this and sue me. ;-)): just how many email addresses are now attached to this sucker anyhow...? To: (MASSIVE EMAIL LIST WITH MULTIPLE FORWARDS - note: in my original note, I copied in roughly a half a page of email addresses, and that was less than half the email addresses in the multiple forwards)

That isn't even all of them, I was just making a point. Guess what? At best, that's how many more times this junk mail has circulated, and how many more people have to pick through it. At worst, that's how many computers are now infected if you've unwittingly forwarded a chain email that contains a link to a "driveby download" website, or worse, an embedded malicious payload. And no, badware doesn't have to come in an attachment anymore. It can be stuck right into the body of an email, if that email contains code or scripts that will run when the message opened.

Girlfriend, if I didn't care, I wouldn't have taken the time to write such a lengthy reply. Please, update the antivirus on your computer and do a scan NOW. And please, please, please, do not forward these sort of emails, and don't answer them. It's entirely possible the person you got it from didn't even send it on purpose. If they did, there *is* one email you can forward on to them - this one.

Give yourself, your husband, and the kids hugs from me and hubby, and if *they're* forwarding junk chain emails, whack them with a keyboard for me. 'kay?

Your sis,

-Peg



So, in closing, if you must forward, forward with some forethought, and not just for the sake of forwarding (and I promise, if you DO get run over by a transit bus, it won't have anything to do with bad email juju...unless you've been forwarding mass quantities of spam to a distribution list of bus drivers). If you take the time to weed out the junk and share only the gems, they're far likelier to actually be read, and even appreciated, by the recipient(s). Don't spread the spam. Think about it: do you stuff all the credit card offers, pizza coupons, and real estate flyers you get in your mailbox into an envelope and mail the whole mess off to your best friend, or your mom?

Oh, and if you get an unexpected email exhorting you to "CLICK HERE" in large red letters - like I just did - just don't.

Don't forward it, either. ;-)

Tuesday, December 29, 2009

Shiny, happy advertisers. Really!

I finally logged into Facebook this morning to do a bit more than just make sure I remembered my password. Poking around the "My Account" section for the first time since the Great Privacy Update, I received the following popup when I hit the "Facebook Ads" tab:


Advertisers using my photos? Misleading rumors? Get the whole story? I'll give 'em this: they know how to hook a person.

The Facebook blog entry is an interesting read in and of itself, but more interesting to me is the reference to "two entire advertising networks" being unfriended by the big FB itself (actually the number now stands at four). Turns out there's also a list of ad networks that are still considered friendly, for the time being anyway.

Presumably Facebook is aware of the members on this list, even if the "providers are not approved by nor affiliated with Facebook", since the content on the Facebook Developer Wiki "is created by the Facebook team with help from our developers". You still might want to weigh just how evenly matched your social standards are with Facebooks, seeing as how RockYou! isn't very careful with its users passwords, Offerpal recently ditched a foul-mouthed CEO, and Zedo-induced spyware/adware has long been a gift that keeps on giving. Neither of these latter two are getting great reviews from my trusty Firefox plugin, either. I could spend the rest of the day playing in this sandbox with my little bucket and shovel, but I think you get my drift.

Granted it's possible to dig up dirt on just about anyone or anything, and everybody's got a skeleton or two rattling around (I've never kicked a puppy, but I've stuck a few mirrors in front of Siamese Fighting Fish). Facebook taking a shot across the bows of lowend malvertising is a step in the right direction. The Facebook community trying to set some standards with a list of who is nice (or at least not blatantly naughty) is another step in the right direction. That doesn't mean it should be taken at face value, or that the shiny, happy advertisers who made the Nice List are there because they met a bar, rather than just slid underneath it.

It is a place to start, at least for the conscientious crowd who have their eyes set on a long term, sustainable business model as opposed to a short term, rake-it-in-and-run racket. If consumers back them up by voting with their wallets, there may even be a light at the end of the "Scamville" tunnel.

Wednesday, December 23, 2009

Facebook updates gone wrong

Evidently there are people out there who really, truly don't care about their online privacy OR the new Facebook privacy controls. I admit I'm wondering if this guy, in addition to keeping his fugitive status updates current, is also updating his photo album...? And does he prefer Farmville or Mafia Wars? My play money is on the latter.

Anyone else think the cops should check to see if he's reporting in on Foursquare as well?

Update: as of 12/27/09, "Lazie" is still keeping in touch, so at least he's not slacking there. Apparently he has a little help, as he's given public kudos to his "admin staff".

Um...admin staff? Now there would be some interesting profiles on LinkedIn.

The guy needs to give his admin staff a poke and have them get serious about an advertising campaign. They might start by studying the "relevant" ads that are showing up on his Facebook page. Car insurance? Not so much (although an agency whose ad shows up on Lnych's page is probably not too picky). Drop blood pressure by as much as 60 points? Now that's relevant.

There's plenty of affiliates I'm sure who would fall all over themselves, and if he pimps the right products*, he could make a tidy sum. That might come in handy for bail one of these cold, rainy days.

*no, I'm not going going there. Well, not yet anyway.

Friday, December 18, 2009

Facebook's new path to privacy - a call to common sense

A friend of mine asked me recently if I planned to write any fiction. I gave her my standard response: "No, because I couldn't make this stuff up". Seriously, I can't, and I have a pretty active imagination. They say sometimes life just hands you material. I say life always hands you material; you just have to be able to gather it all up. Right now, my basket is overflowing.

First there was the gathering storm of Facebook revamping its privacy controls, which some viewed as a tempest in a teapot. Then came the rollout. Then came the fallout, with cries of outrage ranging far and wide. To prevent this post from becoming nothing more than a collection of linkbait (and it's already hovering dangerously close), if you want a sampling of these cries, just plug "Facebook privacy fiasco" into your favorite search engine and knock yourself out.

The fun, however, was really just beginning. The highlight for many people - I know it was for me - was the revelation that Mark Zuckerberg, Facebook's own BMOC, apparently didn't understand the new privacy controls himself, and inadvertently left a bunch of less than flattering photos available to friends of friends of friends of casual acquaintances of total strangers, or something like that. This was followed by stout claims that he really meant to do that, although the hypocrisy of these claims is hard to overlook in view of the fact that Zuckerberg's transparency clouded over shortly after it went massively public. I personally also have to question some of the justifications put forth, certainly in the piece I just referenced:
Bottom line: People don't care about the concept (really an illusion) of privacy nearly as much as other people think they do.
Maybe I'm wrong, but I think they do. Based on the thousands of comments I've seen over the past week, I think I'm right.

I think people do indeed care about their privacy, and more than other people think they do (or at least more than the executives at large internet companies think they do *cough*). What a lot of people don't understand is the difference between the illusion and the reality. In the world of the intarwebs, there is a wide gulf between the two, and for many people "using various Web sites to post personal stuff in a very public way", it is an invisible divide. Out of sight, out of mind. Until something happens which brings the invisible divide into sharp relief.

Among the various opinions being voiced at varying volumes regarding this latest spotlight on the illusion versus the reality of online privacy are calls for action ranging from lynchings to lawsuits. Even the FTC may be getting involved (whether they want to be or not).

What really needs to be happening is a wake up call to common sense. Maybe, with a little luck, that is what's happening, and maybe Facebook is the trumpet sounding (whether they want to be or not). They probably don't want to be the blast that opens a lot of eyes - especially when those eyes are mostly glaring at them with anger - but what's not so good for Facebook could, ultimately, be good for a whole lot of other folks. It certainly will be if it gets a whole lot of folks to finally grok that the "concept" of "privacy" is "really an illusion".

Online privacy is an oxymoron to begin with. I'd like to have that on a bumper sticker. Or a t-shirt. Or both. Anything to help raise awareness that out in cyberspace, the only one who can really safeguard your privacy is YOU.

Might even help a few people avoid getting their insurance canceled.