Facebook sharing addresses and phone numbers?
By Tom Brewster,
Facebook third-party application developers have been granted access to home addresses and mobile phone numbers of users, it has been warned.
Although members have to allow third-party applications to access such data, Sophos said the move by the social network could leave users in more danger from “rogue apps.”
These apps can be found across Facebook, often posting spam to users’ walls or linking to surveys which will earn the scammers money through commission.
Others have even tricked users into handing over their mobile numbers.
"Now, shady app developers will find it easier than ever before to gather even more personal information from users,” said Graham Cluley, senior technology consultant at Sophos, in a blog.
“You can imagine, for instance, that bad guys could set up a rogue app that collects mobile phone numbers and then uses that information for the purposes of SMS spamming or sells on the data to cold-calling companies.”
The move will also open up more avenues for cyber criminals to steal someone’s identity.
“It won't take long for scammers to take advantage of this new facility, to use for their own criminal ends,” Cluley added.
“Wouldn't it [be] better if only app developers who had been approved by Facebook were allowed to gather this information? Or - should the information be necessary for the application - wouldn't it be more acceptable for the app to request it from users, specifically, rather than automatically grabbing it?”
A Facebook spokesperson said developers have been handed the ability to request permission to access addresses and mobile phone numbers "to make applications built on Facebook more useful and efficient."
"You need to explicitly choose to share your data before any app or website can access it and no private information is shared without your permission," the spokesperson added.
"As an additional step for this new feature, you're not able to share your friends' address or mobile information."
Koobface spreading
A variety of threats can be found on Facebook and Websense has warned a fresh Koobface scam has spread across the social network.
The illicit initiative has sent out direct messages from compromised accounts. One tactic employed by the cyber criminals was obfuscation of a malicious URL linked to in each message.
“Another tactic is the use of open redirects on the facebook.com domain itself. This gives the URL a more credible look (social engineering), as well as helping it pass basic security checks,” Websense warned in a blog.
“Usually, Facebook alerts users if they're about to browse to a link outside of its domains, but no alert is triggered in this case.”
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.






RE:
As the trend continues into 2011 for cybercriminals to use popular online trends to trick users into revealing personal information http://bit.ly/i71bId it is necessary for users to be aware of such 'rogue' apps. Particularly when there are a number of young users online who may be naive to these actions, Facebook surely has an obligation to protect its vast number of members.
By MSC_247 on Tuesday Jan 18