Showing posts with label Facebook privacy. Show all posts
Showing posts with label Facebook privacy. Show all posts

Wednesday, October 19, 2016

Can we please stop falling for this Facebook privacy hoax?

We've been debunking this hoax for seven years now, and here we are doing it again.

No, Facebook hasn't changed its privacy settings.
 
No, what you post doesn't belong to Facebook now. 
 
A note is doing the Facebook rounds claiming, yet again, that you need to post a legal gibberish to your status or you'll lose copyright control of your pictures and other content you share with your family and friends. 
 
Here's part of what you're supposed to post:
"The content of this profile is private and confidential information. The violation of privacy can be punished by law (UCC 1-308- 1 1 308-103 and the Rome Statute). NOTE: Facebook is now a public entity. All members must post a note like this. If you prefer, you can copy and paste this version. If you do not publish a statement at least once it will be tactically allowing the use of your photos, as well as the information contained in the profile status updates. DO NOT SHARE. Copy and paste."
 
Please. Don't.
 
We get that you don't want Facebook to own your weird bathroom selfies, but you need to stop sharing this post. 
 
It's not true. 
 
"Anyone who uses Facebook owns and controls the content and information they post, as stated in our terms. They control how that content and information is shared. That is our policy, and it always has been," Facebook said in a statement.
 
If you're still skeptical, try reading Facebook's actual terms of service....you know that contract that you blindly agree to when you sign up.

Monday, August 11, 2014

If you use Facebook on your mobile device, you have surely seen this message to upgrade. We urge you not to.

If you’re anything like your neighbor…you probably use Facebook on your phone way more than you use it on a computer. You’ve been sending messages from the Facebook app and it probably always asks you if you want to install the Facebook Messenger App.

It’s always been optional but coming soon to your Facebook experience….it won’t be an option…it will be mandatory if you care to send messages from your phone.

No big deal one might think…but the part that the average Facebook User doesn’t realize is the permissions you must give to Facebook in order to use the Facebook Messenger App. Here is a short list of the most disturbing permissions it requires and a quick explanation of what it means to you and your privacy.
  • Change the state of network connectivity – This means that Facebook can change or alter your connection to the Internet or cell service. You’re basically giving Facebook the ability to turn features on your phone on and off for it’s own reasons without telling you.
  • Call phone numbers and send SMS messages – This means that if Facebook wants to…it can send text messages to your contacts on your behalf. Do you see the trouble in this? Who is Facebook to be able to access and send messages on your phone? You’re basically giving a stranger your phone and telling them to do what they want when they want!
  • Record audio, and take pictures and videos, at any time – That means that the folks at Facebook can see through your lens on your phone whenever they want..they can listen to what you’re saying via your microphone if they choose to!!
  • Read your phone’s call log, including info about incoming and outgoing calls – Who have you been calling? How long did you talk to them? Now Facebook will know all of this because you’ve downloaded the new Facebook messenger app.
  • Read your contact data, including who you call and email and how often – Another clear violation of your privacy. Now Facebook will be able to read e-mails you’ve sent  and take information from them to use for their own gain. Whether it’s for “personalized advertisements” or if it’s for “research purposes” ….whatever the reason..they’re accessing your private encounters.
  • Read personal profile information stored on your device – This means that if you have addresses, personal info, pictures or anything else that’s near and dear to your personal life…they can read it.
  • Get a list of accounts known by the phone, or other apps you use – Facebook will now have a tally of all the apps you use, how often you use them and what information you keep or exchange on those apps.
After reading more about it and studying the permissions, I will personally avoid downloading the new app to my phone. I still have my Facebook app, but I just won’t use the messaging feature unless I’m at a computer.

Source: CBS Local

Thursday, August 1, 2013

So your teenager wants to open a Facebook account...here's how to handle it.

There are plenty of reasons Facebook, Instagram, and other social networks have a minimum age limit. Here's just one: Children aren't born with internal privacy settings.

Moms and Dads can't assume teens know what they should and shouldn't share online. And just because children meet the minimum age requirement (for Facebook, it's age 13), that doesn't mean they should rush to create an account. Colby Zintl of Common Sense Media, a nonprofit family and children's advocacy group, said kids are probably better equipped to deal with the not-always-kid-friendly content and situations found on social networks when they're 14 or 15.

Once everyone's in agreement about when to get online, parents should show kids how to go about it. Walk them through the privacy settings. Show them how to unfriend people and delete posts. Make sure that only their friends can view their profile.

Zintl suggested that parents activate the setting that allows kids to approve all posts before they're added to their timeline. "Talk to your child about the importance of that," Zintl said. "It relates to the concept of a digital footprint -- everything is permanent. If a child is going to post on your child's wall, there should be some barrier to entry there."

The current generation of kids are growing up as digital natives, so they're often comfortable with social media, but they still need to be careful. And thanks to proud parents and grandparents, their lives are probably well-documented. Said Zintl: "Parents posting pictures of their babies starts a kid's digital footprint for their entire life. They're creating a lifetime of photos and history online."

Common Sense Media urges parents to emphasize to kids that the Internet is written with a permanent Sharpie, not pencil. "Once a photo, or a comment, is out in cyberspace, there is no getting it back. Even if you take it down from Facebook, another kid could have forwarded it," Zintl said. "There is no such thing as a real eraser button in social media, and that is an important reminder to share with kids over and over again."

Source: CNET

Tuesday, July 30, 2013

5 simple methods to improve your privacy online.

It wasn't long after the Internet came into widespread use that online privacy became a growing concern. After all, anytime people are connected through their computers and sharing resources online, there's the potential for prying and abuse.

1). Browser Settings
There are some easy things that can be done to configure a browser for better security and privacy. Among the basics, go into your Web browser's preference settings and set the browser not to accept cookies from sites you haven't visited, also known as third-party cookies. Generally, you'll want to accept cookies from the sites you visit.

Apple's Safari blocks third-party cookies by default; Mozilla intends to make this the default setting soon in Firefox, but for now you'll need to opt for the setting. You have to choose these settings in Microsoft's Internet Explorer and Google's Chrome.

Also, the newest versions of Internet Explorer, Mozilla Firefox, Google Chrome and several others offer settings for "Do Not Track," a proposed header field that requests that a Web application disable its site and/or cross-site tracking of user activity.

Consider setting your browser preferences to automatically clear cookies when you close the browser.

2). Cloud Storage
Storage of anything private and personal in the cloud should use the strongest form of encryption possible. Strengths of encryption come in various standards. RSA 2048-bit key encryption provides the best possible strength when used with public key infrastructure. The chance of cracking an RSA 2048-bit private key is not nil, but it would take so long that attempting it is not practicable using today's raw computing power.

A strong cipher is the most important consideration. Close behind, however, are the questions of where you should use encryption and with what method.

If you have any data stored on the Internet that you would like to ensure never gets seen by anyone other than yourself, then this is a good candidate for encryption.

The strongest and safest method today for encryption of cloud data is Zero Knowledge. Zero knowledge means that your cloud ISP will have no knowledge of what is being stored on their site. The private key to unlock your data will be created by you on your local drive. Thus only you will have the ability to unlock the data -- not even the cloud ISP will be able to do so.

SpiderOak and Wuala are two examples of ISP Software as a Service sites that offer ZK data encryption.

There are now quite a few SaaS encryption vendors from which to choose, but those that support Zero Knowledge are the safest bet for those with privacy in mind.

3). Two-Factor Authentication
The use of hack-prone password-based access is being gradually replaced by technologies like fingerprint scan, keyfob-generated keys and two-factor authentication methods.

If your ISP uses password-based access, make sure you maintain strong passwords. A password's strength is measured by its ability to avoid being guessed. Many ISPs and portals will test the strength of your password as you create it. Pay attention and be sure that the test returns "strong."

Do not use the same password for multiple accounts. Instead, use strong passwords that are unique to each account - and that's particularly important for your most sensitive online accounts, such as for banking, email, and social networks.

Two-factor authentication is another method that's growing in popularity. Google Gmail now offers a free two-step authentication service. The goal is to avoid having your login stream (which includes your password) from being intercepted by a "man-in-the-middle" attack. Criminals equipped with programs called packet analyzers (also known as "sniffers") can see your streaming data and steal your password.

With two-factor authentication, in addition to entering a password, the system will send to your phone a unique ID number that must be input for authentication as well. Using such a method means the "man-in-the-middle" cannot and will not know what is on your personal phone and so cannot intercept such information.

If your ISP offers two-step authentication, you'd be wise to use it.

4) Encryption for Chat and Email
With Google Talk and Google Hangouts, one can set the chat session to "off the record" to ensure that the chat session is never permanently stored on Google's chat servers.

Also, installing Pidgin for both Windows and Linux - it's a popular multiprotocol messaging software application - along with its "off the record" plugin will ensure that your chat session will remain encrypted and private. This ensures that an additional encryption layer is added to the stream using OTR, regardless of what the underlying protocol provides.

The same encrypted vs. nonencrypted concept applies to email. If you don't want your email read, then it is imperative that you encrypt it. The good news is that encrypting email is technically feasible using GnuPG, PGP or S/MIME standards, for example. The bad news is that few software applications are in circulation that make preparing and sending encrypted email "drop-dead" simple and foolproof in terms of usability by the general public.

5) Surf the Internet Anonymously
Finally, if you really feel strongly about keeping your Internet surfing habits anonymous, you may consider using a proxy for your Internet surfing - though even that won't guarantee complete anonymity.

A more difficult-to-trace method for surfing the Web is called Tor. Essentially, when you install Tor software, you log onto a peer-to-peer (P2P) network representing millions of people, much in the way BitTorrent works. It is encrypted and fully decentralized, meaning not only that it is self-sustainable but also that there is no central server which, if shut down, will stop its Internet activities.

What happens in the Tor scenario is that your IP travels in a random path along the Tor encrypted tunnel and reaches a random endpoint, where your traffic then jumps on the Internet using one of the P2P computing devices as its proxy. That endpoint proxy could be a node anywhere in the world.
If you do try Tor, just go to Google and note which country shows. It will vary from minute to minute - an indication of Tor's anonymity at work.

Saturday, June 22, 2013

New Facebook bug exposes some contact information.

A newly discovered Facebook bug may have inadvertently compromised the contact information of 6 million users, the company says.

The bug, which has since been repaired, was part of the Download Your Information tool, which lets Facebook users export all the data from profiles, such as posts to their timeline and conversations with friends. People using the tool may have downloaded inadvertently the contact information for people they were somehow connected to.
 
Some people upload their contact lists or address books to Facebook, which the company then uses to suggest new friends they can connect with who are already using the service.
 
Though the number of people impacted is sizable, the actual spread of their contact information appears to be limited. The phone numbers and e-mail addresses were not exposed to developers or posted publicly. It is only shown to people they had at least a tentative connection with, and who may have already had their contact information. Even in that pool, it was only exposed to people who had used the data-exporting tool.

"For almost all of the email addresses or telephone numbers impacted, each individual email address or telephone number was only included in a download once or twice. This means, in almost all cases, an email address or telephone number was only exposed to one person," Facebook's security team said in a post.
 
The company says it has no evidence that the bug was "exploited maliciously" and that there have been no complaints so far.
 
The social media company announced the bug on Friday afternoon. The issue was discovered by a third-party security researcher who submitted it through Facebook's White Hat program.
 
Facebook's White Hat program is set up so that people such as security researchers can report any vulnerabilities they find on the social network and get a reward for $500 and up in return. These types of programs are common at Internet companies.
 
"Your trust is the most important asset we have, and we are committed to improving our safety procedures and keeping your information safe and secure," read the post.
People who were affected by the bug will receive an e-mail from Facebook.
 
Source: CNN

Friday, March 8, 2013

Despite increased privacy concerns, Facebook users are sharing more personal information.

Carnegie Mellon University conducted a study following more than 5,000 Facebook users over six years, from 2005 and 2011, and found that changes in the social network's privacy policies caused users to share more -- not less -- personal data. Lest you think this means that users suddenly trusted the site more, Carnegie Mellon says that Facebookers became more and more protective of their personal details as the social network grew in membership -- and that the uptick in shared information is a result of increasingly granular privacy settings. If you recall, Facebook introduced new in-depth privacy controls in 2010, and the study found that the release of these new settings corresponded to users sharing more personal data, both within their network of friends and with strangers and third-party applications.

It's been quite some time since the new privacy policy was introduced, but the university says the sample group didn't reduce the amount of info shared with non-friends on the network, even as of 2011. The takeaway? Well, it's safe to say that more privacy controls doesn't equal more vigilance in protecting personal data, and it's certainly not a stretch to call Facebook's settings confusing. The researchers' comparison of the struggle for privacy to the eternal plight of Sisyphus? That might be a touch more dramatic.

Source: Engadget