Attacks/Breaches
5/2/2013
02:31 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Facebook Turns Friends Into IT Support

Facebook's new Trusted Contacts option lets friends assist with account recovery, so Facebook personnel don't have to.

Microsoft Surface: Round Two
10 Ways Microsoft Could Improve Surface Tablet
(click image for larger view and for slideshow)
Just as companies have warmed to the financial benefits of employee-supplied devices and have embraced the rent savings of offices that are open but smaller under the pretense of promoting interaction, Facebook has recognized the economic and security promise of deputizing users to provide customer support.

The social network, ever keen to increase user engagement, wants you to designate friends as Trusted Contacts who can restore access to your Facebook account "if you ever have trouble logging in." Don't call us, call a friend.

Why might you have trouble logging in? Facebook doesn't say. A hacked account is one possibility, but presumably anyone who hijacks your account could alter your Trusted Contact list. And Facebook maintains a separate account reset process for hacked accounts, at facebook.com/hacked.

[ Wondering what it's like to wear Google's new high-tech glasses? Read Google Glass: First Impressions. ]

The most common scenario for resorting to Trusted Contacts is a forgotten password. This could be a relatively frequent occurrence, given that Facebook tends to keep users logged in, thereby obviating the need to type one's password and making it easier to forget.

Account recovery processes, however, have a long history of insecurity. For example, in 2008, the Yahoo Mail account of then vice presidential candidate Sarah Palin was hacked when a University of Tennessee student reset the account password by answering what turned out to be obvious password recovery questions. The following year, Yahoo Mail's account recovery process was abused again to gain control over a Twitter administrative account.

A Facebook spokeswoman in an email said that there are also occasions when users lose access to the email account through which they log in to Facebook.

Facebook in a blog post suggests that the Trusted Contact account recovery process represents an improvement on answering security questions. "With trusted contacts, there's no need to worry about remembering the answer to your security question or filling out long web forms to prove who you are," the company says. "You can recover your account with help from your friends."

There's another security benefit too: Account compromises often occur as a result of social engineering attacks. While customer service personnel can be tricked into revealing personal information by people posing as account holders, friends presumably are less likely to be duped by an imposter soliciting sensitive data.

With Trusted Contacts, Facebook support personnel can expect fewer emails from users who can't log in to get their their social fix. What's more, Trusted Contacts could create a user retention halo effect: Users will probably be less likely to drift away from Facebook when their friends have entrusted them with the keys to their accounts.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Cara Latham
50%
50%
Cara Latham,
User Rank: Apprentice
5/6/2013 | 12:41:24 PM
re: Facebook Turns Friends Into IT Support
It sounds like a manipulative trick Facebook is playing if the company really is thinking that Trusted Contacts would create a scenario in which users would be "less likely to drift away
from Facebook when their friends have entrusted them with the keys to
their account."

Then again, I think most users would be wary of providing even their "trusted contacts" with access to their accounts. On a small level, think of the possibility of someone posting an obscene status update on your behalf. On a larger level, it could possibly tie you to the site for a long time.

My reaction is to avoid it. I have survived many years without needing to add Trusted Contacts to my account, so I think I will do without them in the future.
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0619
Published: 2014-10-23
Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.

CVE-2014-2230
Published: 2014-10-23
Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) dest parameter to adclick.php or (2) _maxdest parameter to ck.php.

CVE-2014-7281
Published: 2014-10-23
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for requests that reboot the device via a request to goform/SysToolReboot.

CVE-2014-7292
Published: 2014-10-23
Open redirect vulnerability in the Click-Through feature in Newtelligence dasBlog 2.1 (2.1.8102.813), 2.2 (2.2.8279.16125), and 2.3 (2.3.9074.18820) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter to ct.ashx.

CVE-2014-8071
Published: 2014-10-23
Multiple cross-site scripting (XSS) vulnerabilities in OpenMRS 2.1 Standalone Edition allow remote attackers to inject arbitrary web script or HTML via the (1) givenName, (2) familyName, (3) address1, or (4) address2 parameter to registrationapp/registerPatient.page; the (5) comment parameter to all...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.