Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

Anonymous Threats To Kill Facebook: Another Hoax?

Security experts question whether the plot against Facebook is real, noting odd Twitter accounts used to launch the campaign.

Top 15 Facebook Apps For Business
(click image for larger view)
Slideshow: Top 15 Facebook Apps For Business
"Join the cause and kill Facebook for the sake of your own privacy."

That exhortation comes via a FacebookOp channel YouTube post, Message from Anonymous: Operation Facebook, Nov 5 2011. While the video was uploaded last month and announced via Twitter, the video's page views only approached one million views recently, as multiple news outlets referenced the post, warning of an impending Anonymous attack against Facebook.

But as with the recent study tying browser usage to IQ, released by a Canadian consulting company, widely reported as fact by numerous media outlets, and then revealed to be a hoax, security experts are questioning whether the plot against Facebook is real.

"Pay attention to the strange Twitter name they used and links to websites with adverts," said security expert Eugene Kasperky in a Twitter post, reported The Register. "The news around #Anonymous to attack #Facebook on Nov 5 most probably is fake."

Interestingly, the first statement about "FacebookOp" from a regular Anonymous source also didn't back the campaign, and may have even botched the official hash tag. "FYI - #OpFacebook is being organized by some Anons. This does not necessarily mean that all of #Anonymous agrees with it," read the post to the Twitter channel "GroupAnon," which has served as a reliable source of information about Anonymous-backed activities.

The post suggests that there may be confusion on the part of Anonymous participants as to whether "some Anons" are even involved, or whether it's all just a hoax. Then again, as shown by the swift arrest of two people in Britain who are accused of posting messages on Facebook inciting others to riot, any armchair campaign--run by a regular Anonymous member or not--has the potential to become a real-world rallying cry.

Regardless of whether the anti-Facebook campaign began as a hoax, the call to arms does tie into Anonymous mythology. Namely, the date designated for the forthcoming attacks, November 5, is Guy Fawkes Night in Britain, celebrating the botched revolution known as the Gunpowder Plot of 1605, in which a band of English Catholic rebels in possession of a large cache of explosives--which Guy Fawkes was found guarding--failed to assassinate the Protestant monarch, King James I of England, and install a Catholic monarch in his place. Fawkes and his co-conspirators were executed, and British people now annually burn him in effigy.

Outside Britain, however, the holiday has gained some notoriety thanks to being featured as the day of revolution in the movie V For Vendetta, in which the protagonist sports a Guy Fawkes mask. That mask, in turn, was adopted as the symbol of the pro-WikiLeaks hacktivist collective Anonymous, most recently officially known for leaking data relating to 56 different law enforcement agencies.

Hence, whether or not the attackers are practicing members of Anonymous, they at least appear to have done their homework. But as to Facebook privacy transgressions and the aforementioned movie's tagline, "beware the 5th of November," the jury is still out.

The vendors, contractors, and other outside parties with which you do business can create a serious security risk. Here's how to keep this threat in check. Also in the new, all-digital issue of Dark Reading: Why focusing solely on your own company's security ignores the bigger picture. Download it now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Major Brazilian Bank Tests Homomorphic Encryption on Financial Data
Kelly Sheridan, Staff Editor, Dark Reading,  1/10/2020
Will This Be the Year of the Branded Cybercriminal?
Raveed Laeb, Product Manager at KELA,  1/13/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-3683
PUBLISHED: 2020-01-17
The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and...
CVE-2019-3682
PUBLISHED: 2020-01-17
The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node.
CVE-2019-17361
PUBLISHED: 2020-01-17
In SaltStack Salt through 2019.2.0, the salt-api NEST API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.
CVE-2019-19142
PUBLISHED: 2020-01-17
Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmware.cfg URI.
CVE-2019-19801
PUBLISHED: 2020-01-17
In Gallagher Command Centre Server versions of v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prior to v7.80.960(MR2) and v7.70 or earlier, an unprivileged but authenticated user is able to perform a backup of the Command Centre databases.