Technology Review - Published By MIT
Advertisement

Turning Social Networks Against Users

Continued from page 1

By Erica Naone

Monday, September 15, 2008

smaller text tool iconmedium text tool iconlarger text tool icon

A key problem is that it is so difficult for users to know what a social-networking application is actually doing. "You cannot really check what an application is doing, being a user," says Roel Schouwenberg, a senior antivirus researcher at Kaspersky Lab, in Belgium. "As a security professional, that doesn't give me nice feelings."

Social factors also play an important role, Hamiel says, because social networks foster an atmosphere of trust that is easy to exploit. For example, a malicious program recently spread via Facebook in the form of a fake update for Flash that was forwarded from one friend to another. "It was the social aspect that drove them to do something technically stupid," Hamiel says.

The companies behind social-networking sites are just starting to wake up to the issue of security. Facebook, for example, recently created a security page to educate users about potential risks that they could face. The company adds that its security team "is dedicated to investigating and auditing our own code for holes, as well as reaching out to people in an extended community to let us know if we've missed anything."

Hamiel warns that it may be nearly impossible to eliminate all malicious programs, and he notes that an attacker could build a legitimate application, wait until a large number of users have installed it, then make the application "go bad" by updating it with malicious code.

Limiting all applications' capabilities does not provide a solution because it would destroy what makes them so attractive to users. "You're in a tough position because the goal of a social network is to facilitate creativity and communication," he says. "If you start being too restrictive, you're basically restricting what the social network is all about. You have a functionality arms race."

A more effective solution, according to Athanasopoulos, would be to hire programmers to audit the code being used by external applications. But he acknowledges that the expense of this could make it unattractive for most companies.

As social networks become increasingly popular, Hamiel expects to see many more attacks. "People don't have the same respect for software running in their browser as they do for something they would download and install," he says. In the future, he adds, that may have to change.

Comments

  • Credit and trustworth is the base of SNS
    Definately I agree to the points. Mostly every SNS has its own plugins or GUI softwares installed at users' desktop. Credit and trustworth is the base of SNS.
    Rate this comment: 12345

    zhaol
    09/18/2008
    Posts:1

Log In

Forgot your password?     Register »
Advertisement

Videos

Laser-Triggered Chemical Reactions
Featured Content
Sponsored by:
White Papers

Twelve ways to reduce costs with SQL Server 2008
Find out how to reduce costs and get more efficient

Download

Total Economic Impact of SQL Server 2008 Upgrade
Forrester reports on increasing productivity and management capabilities

Download 

Achieving Cost and Resource Savings with UC
How Office Communications Server R2 and Exchange Server can make your business smarter and more efficient

Download 

The Compelling Case for Conferencing
Read how you can improve workload support and find IT efficiencies

Download

How Windows Server 2008 R2 Helps Optimize IT and Save you Money
Read how you can improve workload support and find IT efficiencies

Download

Windows Server 2008 R2 Hyper-V Live Migration
See how Windows Server 2008 R2 and Hyper-V enable virtualization and Live Migration

Download
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.