Attacks/Breaches
5/2/2013
02:31 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Facebook Turns Friends Into IT Support

Facebook's new Trusted Contacts option lets friends assist with account recovery, so Facebook personnel don't have to.

Microsoft Surface: Round Two
10 Ways Microsoft Could Improve Surface Tablet
(click image for larger view and for slideshow)
Just as companies have warmed to the financial benefits of employee-supplied devices and have embraced the rent savings of offices that are open but smaller under the pretense of promoting interaction, Facebook has recognized the economic and security promise of deputizing users to provide customer support.

The social network, ever keen to increase user engagement, wants you to designate friends as Trusted Contacts who can restore access to your Facebook account "if you ever have trouble logging in." Don't call us, call a friend.

Why might you have trouble logging in? Facebook doesn't say. A hacked account is one possibility, but presumably anyone who hijacks your account could alter your Trusted Contact list. And Facebook maintains a separate account reset process for hacked accounts, at facebook.com/hacked.

[ Wondering what it's like to wear Google's new high-tech glasses? Read Google Glass: First Impressions. ]

The most common scenario for resorting to Trusted Contacts is a forgotten password. This could be a relatively frequent occurrence, given that Facebook tends to keep users logged in, thereby obviating the need to type one's password and making it easier to forget.

Account recovery processes, however, have a long history of insecurity. For example, in 2008, the Yahoo Mail account of then vice presidential candidate Sarah Palin was hacked when a University of Tennessee student reset the account password by answering what turned out to be obvious password recovery questions. The following year, Yahoo Mail's account recovery process was abused again to gain control over a Twitter administrative account.

A Facebook spokeswoman in an email said that there are also occasions when users lose access to the email account through which they log in to Facebook.

Facebook in a blog post suggests that the Trusted Contact account recovery process represents an improvement on answering security questions. "With trusted contacts, there's no need to worry about remembering the answer to your security question or filling out long web forms to prove who you are," the company says. "You can recover your account with help from your friends."

There's another security benefit too: Account compromises often occur as a result of social engineering attacks. While customer service personnel can be tricked into revealing personal information by people posing as account holders, friends presumably are less likely to be duped by an imposter soliciting sensitive data.

With Trusted Contacts, Facebook support personnel can expect fewer emails from users who can't log in to get their their social fix. What's more, Trusted Contacts could create a user retention halo effect: Users will probably be less likely to drift away from Facebook when their friends have entrusted them with the keys to their accounts.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Cara Latham
50%
50%
Cara Latham,
User Rank: Apprentice
5/6/2013 | 12:41:24 PM
re: Facebook Turns Friends Into IT Support
It sounds like a manipulative trick Facebook is playing if the company really is thinking that Trusted Contacts would create a scenario in which users would be "less likely to drift away
from Facebook when their friends have entrusted them with the keys to
their account."

Then again, I think most users would be wary of providing even their "trusted contacts" with access to their accounts. On a small level, think of the possibility of someone posting an obscene status update on your behalf. On a larger level, it could possibly tie you to the site for a long time.

My reaction is to avoid it. I have survived many years without needing to add Trusted Contacts to my account, so I think I will do without them in the future.
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3341
Published: 2014-08-19
The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616.

CVE-2014-3464
Published: 2014-08-19
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers ...

CVE-2014-3472
Published: 2014-08-19
The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors.

CVE-2014-3490
Published: 2014-08-19
RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have...

CVE-2014-3504
Published: 2014-08-19
The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Dark Reading continuing coverage of the Black Hat 2014 conference brings interviews and commentary to Dark Reading listeners.