Slashdot Log In
Social Networking Sites Full of Security Holes
Posted by
CmdrTaco
on Mon Aug 06, 2007 01:21 PM
from the 2.0-is-harder-than-1.0 dept.
from the 2.0-is-harder-than-1.0 dept.
athloi writes "Social networking Web sites such as MySpace.com are increasingly juicy targets for computer hackers, who are demonstrating a pair of vulnerabilities they claim expose sensitive personal information and could be exploited by online criminals."
Related Stories
[+]
New Apps Enable Social Network Snubbing 68 comments
beafpeat writes "Both The Boston Globe and NPR are reporting on new apps such as Enemybook and Snubster that parody the social networking phenomenon. 'Tired of bogus online friendships... [the creators] hope to encourage people to undermine, or at least mock, the online social communities sites such as Facebook were designed to create.'" Relatedly News.com wonders, with the opening of the Facebook API and the ensuing app frenzy, how much is too much of a good thing?
This discussion has been archived.
No new comments can be posted.
Social Networking Sites Full of Security Holes
|
Log In/Create an Account
| Top
| 76 comments
| Search Discussion
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Hey...Wait a minute (Score:5, Funny)
(http://www.globaltics.net/)
Now, so many holes in social networking sites your data is already in the hands of criminals.
Re:Hey...Wait a minute (Score:4, Funny)
"It's Time for Social Networks to Open Up" (Score:5, Funny)
(Last Journal: Friday November 09, @12:32PM)
Hey, site vulnerabilities are an API! Right?
XSS is Web 3.0.
Re:Hey...Wait a minute (Score:5, Informative)
(Last Journal: Tuesday December 19 2006, @05:12PM)
In the end it's hardly surprising. These sites aren't designed with security in mind, and they allow user code on the pages. Game over man, game over. Blah blah blah SSL, blah blah blah strong passwords, blah blah blah restrict user code...This stuff is all basic.
My God....It's full of holes! (Score:5, Funny)
(Last Journal: Wednesday September 05, @08:49AM)
Of course it's full of holes. How else would it connect to the series of tubes?
Re:My God....It's full of holes! (Score:4, Funny)
I'd say the real threat isn't holes, but ho's (Score:5, Insightful)
Re:I'd say the real threat isn't holes, but ho's (Score:4, Insightful)
(http://slashdot.org/~Spy+der+Mann/journal/ | Last Journal: Saturday November 10, @01:50AM)
The other day i could watch a demonstration of a XSS attack on meebo due to lack of server-side validation.
Now add a little AI / data mining to this:
(New entry, mo/day/yr) "Here's a picture of me and my daughter Jessica playing on the NN. park" -> AI -> name: Jessica. Picture: (insert here). Last seen on: MMDDYY. Location: NN. Park.
There! You could make a database of potential victims for threats, blackmailing, and what not. The only thing that makes me feel safe is that such AI data mining technology hasn't been developed... yet.
As a rule of thumb, follow Murphy's law: What can go wrong, WILL go wrong (remember the recent SSN leaks?) Unless social networking sites have been PUBLICLY certified as having greater security than Fort Knox, stay away.
Perhaps ran into one of these (Score:1, Interesting)
Re:Perhaps ran into one of these (Score:4, Informative)
(Last Journal: Tuesday December 19 2006, @05:12PM)
Not much you can do about it other than turn of javascript by default. It's pretty annoying actually...These vulnerablities have been known forever, but patching them would break a lot of code, so they stay open.
Applause (Score:1, Funny)
Whew! I'm Glad I'm a 15-year-old girl! (Score:5, Funny)
(http://www.perfectreign.com/)
At least I don't think they can get to me!
Re:Whew! I'm Glad I'm a 15-year-old girl! (Score:5, Funny)
And your little dog, too.
A Net is a Bunch of Holes Sewn Together (Score:4, Insightful)
(http://slashdot.org/~Doc%20Ruby/journal | Last Journal: Thursday March 31 2005, @01:48PM)
i wouldn't be surprised (Score:5, Insightful)
I know, and they keep sending me Friend requests (Score:3, Funny)
Oh, wait a second, you said 'Holes'. Oh. Carry on, then...
Security Holes? (Score:1, Funny)
perverts? (Score:2, Funny)
No SSL (Score:3, Insightful)
'increasingly juicy targets' (Score:2)
(http://marcrust.blogspot.com/)
/haven't tried, myself
Stereotyping? (Score:5, Insightful)
(http://www.people.cornell.edu/pages/atd7/)
Just a LITTLE bit of stereotyping in the article title I think?
They really don't care about the end user... (Score:2, Insightful)
What I find funny is the fact that most of the poor souls that go to such sites looking to connect with other people are on a site where the people in charge couldn't care less... I signed up for My(waste of)Space when it showed up on the net because for some people I knew it was the only means to reach them any longer. I canceled my ISP and switched since then, asking the OZ like people running the show to please update my e-mail to reflect this change, more than a year has gone by. Has my e-mail been changed? Nope. Do I waste my time on MySpace anymore? Nope.
When you refuse to acknowledge the community you "support" sub-par quality is what you must expect. Now if those MySpace people want to reach me they have to track me down via other means. To limit yourself to one medium of communication is sad anyway. Pidgin for everybody.
Full of holes? No problem... (Score:5, Funny)
I'm sure Tom will get right on it.
A patch has been issued (Score:1, Funny)
Myspace hole that's funny (Score:3, Informative)
(http://infaux.net/ | Last Journal: Thursday September 01 2005, @02:08PM)
Then there was the time I was on myspace, and a banner ad tried to send me a virus. You would think Myspace would be a bit more discretionary who it lets send banners over. Tsk tsk!
Of course, not as fun as the images directory being left open on all angelfire pages. Some of those were fun to sort through, showing pictures not intended for the public(ie nudity, etc).
News? (Score:2)
But Celebrities are doing it... (Score:1)
user-submitted HTML content bad (Score:2, Insightful)
That's not nice to the girls. (Score:2)
Oh we're talking about security? My bad.
Try Deleting Your Facebook Account (Score:2, Informative)
Stop the presses! (Score:1)
What sort of fiend would pray on people who clearly state there name, address, age, and often occupation, hangouts, favorite things.
I mean really, how much security did you expect. There is no anonymity on Myspace or Flicker, so who the hell would be surprised when it gets hacked. There are probably a million people out there that hate Myspace (or flicker/other social sites) some of them must have the desire to program with malicious intent. It's a big fat whale carcase just waiting for the sharks to arrive.
MySpace is the boogeyman (Score:1)
And now you go and post this? Despite the headline having no real basis in the article, and that the context implies that this exploit is not in the wild yet, it's going to be used to justify every past and future accusation.
If I'm lucky, my employers will only knee-jerk at the headline. If not, they'll read the entire article, knee-jerk at the headline anyway, and based on the statement, "it only affects older versions of the Firefox Web browser and does not affect Internet Explorer," argue that IE is superior in every way to Firefox. Just watch.
Thanks a lot,
Re:No!!! (Score:2)
Nah, you look more like you did in that faked YouTube video where you had a pineapple shoved up your butt.
At least I'm *assumuing* it was faked...