Fact, fiction and the Internet

Mining social networking sites for unreliable information

  • Email to a friend
  • Print this article
  • Bookmark this page
  • RSS feed

In their simplest form, many social networking sites are not much more than online diaries. Whether you're thinking of Bridget Jones or Adrian Mole, Alan Clark or Samuel Pepys, most of us realise that a diary is just someone's personal view, and not a reliable source of indisputable information. Most of us except for financial institutions, that is, or so it appears.

In a recent blog post, security expert Roger Thompson related how an authentication check by his credit card company resulted in their asking him a question to verify his identity, using information publicly available – as opposed to, or in addition to, the use of the sort of information we share with such institutions as "secret questions", for instance. The required answer in this case concerned the age of Thompson's daughter-in-law, to whom they referred to by her maiden name. The only public resource that he could think of that would connect the two of them is Facebook, though other commentators have pointed out that genealogy sites are used in identity checks too.

For a while now, some security researchers have advised people to be economical with the truth when using chatrooms, forums and social networking sites. Why would you give your true date of birth to a site that doesn't need to know it and that can't be trusted to keep it private? Is it a good idea to let all your Facebook friends know you're on holiday next week when you may not have met them all personally and can't be sure how much of your information is available to their friends? If you must use your dog's name as a password (you really shouldn't be using names for passwords), talking about Fido on Facebook gives a determined attacker a good start along the password guessing route. How much easier is it to harvest information about a target when their place of birth or current home town is public knowledge?

In the security industry, we talk a lot about the dangers of social networking and sharing information that may be valuable to burglars and scammers, or even spies (if you happen to be married to the head of MI some-number-or-other). But it isn't just about what you do, or information that you give away. Other people can give away information that impacts on you, like that current, dated photo of you next to Niagara Falls that your friend posts to his Facebook page, giving clear notice that you aren't at home right now.

This latest revelation about how information posted to websites is being used (or misused) suggests a potential scenario where false information might actually be seen as more valid than true information, simply because it's "publicly available" and your bank assumes that you, or someone within your social network, will never lie to a social networking site.

There is probably more misinformation than information in the online world, whether it's deliberate deception, propaganda, fraud, well meaning lack of comprehension, or just data that are no longer current. So any instance of an organisation relying on the accuracy of data from a wider (more public) range of resources raises concerns about inaccuracy and perhaps even the deliberate poisoning of data. How can individuals keep track of and validate everything that is "known" about them when presumed-valid information is pulled from who knows where? More so, if the organisation pulls that information long after it has supposedly already validated you as a customer.

While a bad guy who has access to all the information that a bank has may not need to change it in order to profit from it, there are several scenarios where he might want to. This might include hampering remediation, influencing the presentation of data he can write to even when he can't read it (a more common situation than one might think) and compromising public data as part of a social engineering attack. The objective could also be to block legitimate access to information as well as or instead of impersonation.

Regulation of data is nowhere near keeping up with the Internet age. The possibility of an organisation using one customer to validate (or invalidate) another poses more awkward ethical and practical issues than most of us have thought of. It might benefit us all to think for a moment about the long-term impact that our next Facebook update or tweet may have on ourselves or our friends, before we put fingers to keyboard or keypad.

We should also start looking into the practices of organisations which are making ill considered use of such [mis]information.


Contact Us

For editorial queries:
Max Cooter max_cooter@techworld.com

For website issues:
Email webmaster@techworld.com

For commercial queries
Russell Kearney russell_kearney@idg.co.uk


For more contact details click here.

What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related Security news

Pwn2Own sponsor betting on Internet Explorer, iPhone

White hats will take down Microsoft browser

Weak states leave EU open to cyberattack

But UK is well defended

Estonia defence minister: Cyberattacks will grow

Three years after attacks, cyber war is on the global political agenda

Google, Facebook criticised by US communications regulator

Step up to protect privacy, says FTC commissioner



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Email archiving: Top 10 myths and challenges

This survey looks at a number of challenges and myths around email archiving that may also slow adoption of full archiving.

Download Whitepaper

Strategic mobile deployments

Deploying mobile applications? Supporting multiple devices? See why mobile platforms should be part of your IT strategy.

Download Whitepaper

Creating an AUP: Common myths & mistakes

Avoid the common myths & mistakes when implementing your AUP

Download Whitepaper

Legal risks of uncontrolled email and web use

Exploring the challenges facing IT Mangers today and vital steps to ensure safe internet an email use by employees.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Virtualisation 2.0
Driving to higher ground beyond the basics

Virtualisation can deliver unparalleled efficiency and cost reductions to your business, allowing direct access to servers and guaranteeing a dependable, rapid response in times of crisis. Read this e-book to learn more about consolidation, discover the latest technologies and find out how to reduce the TCO of virtualisation.

Download E-Book
COLT White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One

Techworld are running a short survey to discover how UK businesses are managing Internet and email misuse in the Enterprise.

Complete Survey

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *