LinkedIn, Facebook, Twitter Users Beware

Social networkers have more reason to be careful than ever.

By Bill Brenner
Thu, January 08, 2009

CSO — When reports surfaced this week about attacks on Twitter and LinkedIn, I took notice. I use these social networking programs extensively, along with Facebook.

Looking at the specific nature of the attacks, this seems like more than FUD. It is something to be taken seriously, given the deep penetration of these sites in the business world. But don't be spooked by headlines suggesting this threat is something new. It has existed since the day these programs went live.

Social networking is increasingly part of our daily lives. For some, it's as natural as breathing. People post status updates to their Facebook pages from their mobile phones (my dopey but lovable cousin likes to do this while driving to work at rush hour). The line between real business and personal business is mushy and deteriorating. This makes it a tempting target for those who would exploit security holes in the technology. That's especially true when it comes to social engineering attacks—where the bad guy sends out what appears to be legitimate messages from legitimate contacts, duping people into opening messages and URLs that are laced with malicious code.

My use of these programs shows how the line between the personal and professional has blurred.

I use LinkedIn exclusively for business. I use it to build my base of contacts in the security world and it has become an online Rolodex of sorts. When I'm looking for people to interview for something I'm writing or I want to assign guest columns, I reach out to people on LinkedIn. From there, I set up phone interviews or go back and forth by e-mail for those who are more strapped for time. It has become what the old-fashioned phonebook and Rolodex were to me 15 years ago, when my journalism career began.

I use Twitter to make quick contact with my security sources and to ask general questions of those in my network. But it often becomes a place where we just chat about everyday life, TV shows and the weather. The casual nature of it makes Twitter a particularly easy target, as we saw with the recent Twitter incidents.

Then there's Facebook, the grayest program of all for me. Most of my security contacts are on there and I often use it to get a business-related message out. I also use it to display all the content I create for CSOonline, as do many of my colleagues and industry associates.

Continue Reading

attacks

Get up to speed on mobile security.

Learn More »
Loading...
Most Recent Security Stories
This whitepaper by Marc Staimer, Dragon Slayer Consulting, reviews urgent issues facing organizations such as the inability to recover and restore data when required and mounting financial and legal risks. It also covers an on-demand approach that instantly and cost-effectively solves these issues.
Managing the security and availability of email is complex. This paper will discuss the wide variety of challenges associated with email security and availability and illustrate how integral email is to the operations of any organization.
Based on a survey of 273 IT managers, we reveal the top ten web threats to business and outline a solution that uses MessageLabs Security Safeguard.
Online spam campaigns have become more sophisticated and precisely targeted. Spammers routinely disseminate millions of fraudulent emails which sap bandwidth and productivity. Learn how a hosted anti-spam service provides multi-layered protection against spam, improves employee productivity and lowers costs.
Users are increasing influencing IT security decisions, according to new research from IDG Research Services, and IT is somewhat ill-prepared to embrace this trend. Workers are flocking to mobile devices and are becoming increasing vocal about the types of devices they want to use in the corporate world.
Discover how Citrix Delivery Center provides an efficient and secure architecture for virtual workforce success.
Enterprises are adopting cloud technologies for speed to market, business flexibility and cost control. But serious questions still abound on the security vulnerabilities of cloud deployment. Midsized to large enterprises face entirely different issues than smaller companies when considering cloud technology.
This virtual meeting for IT managers and CIOs is based on a new IBM study. Senior Vice Presidents and a Chief Technology Officer provide guidance on business resiliency, security and cloud computing. What steps should you take to achieve a more pro-active, comprehensive approach to risk management?
With almost everything now connected through the Internet, organizations become more vulnerable to cyber intrusion. As a result, cyber security is a senior management issue, not just a technical problem. Join Accenture and Forrester to explore the current global cyber security situation and learn how your organization can adopt a proactive cyber security approach.
The economic downtown has forced many companies to rethink the way they approach IT. CIOs are increasingly being asked how they can drive competitive advantage through technology. Many organizations have recognized that workforce mobility and collaboration are important drivers of increased productivity. These forces are creating a new challenge: the need for dynamic security.

In this webcast, Phil Go, CIO of Barton Malow, discusses how this leading national construction firm is tackling these issues, along with the technology he is adopting to ensure mobile security.
Learn how RSA, the Security Division of EMC helps companies create the intersection of IT operations and Security o...
Moderated by CSO Publisher, Bob Bragdon, hear from this esteemed panel as they share practical approaches to simpli...
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Resource Center