Stay out of my inbox
By Simon Bisson & Mary Branscombe in Editorial
Posted in Security on
Is this another Beacon moment? Keeping apps out of the Facebook inbox is good security. Even though the new Facebook plan to give apps access to the contents of user inboxes is restricted to whitelisted apps, that doesn’t mean they’re safe apps. Despite Google’s airy claims, just because something runs online, in the browser, does not mean it is safe (I’m still boggling security professionals with the claim by the Google gears team at Google IO that “everything in the browser is inherently safe”). Whitelisting means the app isn’t only malicious, but it doesn’t guarantee it’s not vulnerable.
If you’ve ever spent time drilling into the Facebook APIs (and the FBML language) you won’t be surprised at just how much data a not-so well-behaved application can harvest and take back to its own servers. Sure, it helps build more complex games and powers the viral explosion of memes across Facebook, but it’s a whole heap of security violations just waiting to happen. Yes you have to opt-in to every request, but ticking boxes and clicking OS is what we’ve been doing on Facebook for the last couple of years. Why change your habits now?
And making inbox access opt in doesn’t make it safe. We’ve trained the monkey to click OK on just about any dialog box if what the dialog offers is tempting enough - or if the dialog box is in the way of what I really want to do. Put a dialog box between me and my plan to dash off a quick update as I jump in the taxi to the airport and I might not read that dialog with the same due care and attention you were counting on.
And Facebook is full of career-limiting, security-breaching detail. Bank security questions? I bet I can answer them if I can see what memes you’ve been answering. Last three things you bought, first pet, second school you went to? There’s a meme for that. What’s in your inbox that you wouldn’t want posted on some random Web site?
Inbox access is the latest opt-in feature for apps; but they can do a lot more than throwing sheep…
I’ve been waiting for the Google backlash for a couple of years now; the blanket promise ‘not to be evil’ is no replacement for a thorough security lifecycle and privacy policy. Facebook’s Beacon advertising obviously didn’t make people too worried; the recent collection of ‘resignation by incautious Facebook status update’ proves that. Facebook users want to share; it’s up to Facebook to make sure that the platform doesn’t turn that enthusiasm into a threat.
There’s a petition against app inbox access over at http://www.keepmyinboxprivate.com/?ref=nf, which takes you in turn to
http://apps.facebook.com/keepmyinboxprivate/; ironically, the petition itself is an app that asks if it can publish a link to the petition on your Facebook Wall.
–Mary
Trackback by - February 9, 2012 on 5:33 am
greenpeace tee shirts…
[…]well as fencing leader Per Henrik Ling (1777-1839), who examined massage on China[…]…
Trackback by - February 9, 2012 on 8:31 am
will smith son…
[…]a central factor of passe-temps stroke, physiotherapy, osteotherapy, anxiety leadership and relaxation therapy.[…]…
Make a comment
Tag cloud
Archives
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006
Most commented posts
- Java's SSVAGENT.EXE: training the monkey
128 comments
- When Windows 7 upgrades won’t hibernate (the solution)
- Do you need IPv6 for DirectAccess? Yes and No
- Chrome OS: what happens when "always connected", isn't?
- The ColdFusion Renaissance
- Make Adobe Acrobat Pro deactivate
- Is there a showstopper bug in Windows 7 CHKDSK?
- There’s a reason smartphones are locked down
- At sixes and Windows 7s
- The LHC isn
Highest Rated Blog Posts
- Songs of distant satellites (100%)
- Nobody knows what Web 2.0 really is (100%)
- Log in and lock in (100%)
- Top tips for speeding up Vista (100%)
- Mommy, why is there a home server in the office? (100%)
- Employees are our most valuable asset (snigger) (100%)
- Locking down IT or blocking creativity (100%)
- Consumer BlackBerrys are good for business (100%)
- HD Trek (100%)
- Join the (beta) community (100%)


