Attacks/Breaches
5/2/2013
02:31 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Facebook Turns Friends Into IT Support

Facebook's new Trusted Contacts option lets friends assist with account recovery, so Facebook personnel don't have to.

Microsoft Surface: Round Two
10 Ways Microsoft Could Improve Surface Tablet
(click image for larger view and for slideshow)
Just as companies have warmed to the financial benefits of employee-supplied devices and have embraced the rent savings of offices that are open but smaller under the pretense of promoting interaction, Facebook has recognized the economic and security promise of deputizing users to provide customer support.

The social network, ever keen to increase user engagement, wants you to designate friends as Trusted Contacts who can restore access to your Facebook account "if you ever have trouble logging in." Don't call us, call a friend.

Why might you have trouble logging in? Facebook doesn't say. A hacked account is one possibility, but presumably anyone who hijacks your account could alter your Trusted Contact list. And Facebook maintains a separate account reset process for hacked accounts, at facebook.com/hacked.

[ Wondering what it's like to wear Google's new high-tech glasses? Read Google Glass: First Impressions. ]

The most common scenario for resorting to Trusted Contacts is a forgotten password. This could be a relatively frequent occurrence, given that Facebook tends to keep users logged in, thereby obviating the need to type one's password and making it easier to forget.

Account recovery processes, however, have a long history of insecurity. For example, in 2008, the Yahoo Mail account of then vice presidential candidate Sarah Palin was hacked when a University of Tennessee student reset the account password by answering what turned out to be obvious password recovery questions. The following year, Yahoo Mail's account recovery process was abused again to gain control over a Twitter administrative account.

A Facebook spokeswoman in an email said that there are also occasions when users lose access to the email account through which they log in to Facebook.

Facebook in a blog post suggests that the Trusted Contact account recovery process represents an improvement on answering security questions. "With trusted contacts, there's no need to worry about remembering the answer to your security question or filling out long web forms to prove who you are," the company says. "You can recover your account with help from your friends."

There's another security benefit too: Account compromises often occur as a result of social engineering attacks. While customer service personnel can be tricked into revealing personal information by people posing as account holders, friends presumably are less likely to be duped by an imposter soliciting sensitive data.

With Trusted Contacts, Facebook support personnel can expect fewer emails from users who can't log in to get their their social fix. What's more, Trusted Contacts could create a user retention halo effect: Users will probably be less likely to drift away from Facebook when their friends have entrusted them with the keys to their accounts.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Cara Latham
50%
50%
Cara Latham,
User Rank: Apprentice
5/6/2013 | 12:41:24 PM
re: Facebook Turns Friends Into IT Support
It sounds like a manipulative trick Facebook is playing if the company really is thinking that Trusted Contacts would create a scenario in which users would be "less likely to drift away
from Facebook when their friends have entrusted them with the keys to
their account."

Then again, I think most users would be wary of providing even their "trusted contacts" with access to their accounts. On a small level, think of the possibility of someone posting an obscene status update on your behalf. On a larger level, it could possibly tie you to the site for a long time.

My reaction is to avoid it. I have survived many years without needing to add Trusted Contacts to my account, so I think I will do without them in the future.
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0103
Published: 2014-07-29
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.

CVE-2014-0475
Published: 2014-07-29
Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.

CVE-2014-0889
Published: 2014-07-29
Multiple cross-site scripting (XSS) vulnerabilities in IBM Atlas Suite (aka Atlas Policy Suite), as used in Atlas eDiscovery Process Management through 6.0.3, Disposal and Governance Management for IT through 6.0.3, and Global Retention Policy and Schedule Management through 6.0.3, allow remote atta...

CVE-2014-2226
Published: 2014-07-29
Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtains sensitive information via unspecified vectors.

CVE-2014-3020
Published: 2014-07-29
install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.

Best of the Web
Dark Reading Radio