Facebook's Mandatory Anti-Malware Scan Is Invasive and Lacks Transparency
wired.com
wired.com
That the feature couldn't detect the user's OS (had her download a Windows binary even though she was on a Mac) doesn't lend much confidence though
I mean, you still can :)
Haha - says you.
A closed version of the internet controlled by a corporation? We should be yelling from the rooftops not nitpicking things like this story
just get it overwith, you'll be better off.
Happily, so far, they don't ask from Firefox.
I have no desire to personally be on FB anymore, but I would like to maintain the pages + ads for business purposes.
The first time I get a Facebook demand to scan my computer, while locking me out of the account, is the last time I use my Facebook account.
Interestingly, a friend showed me his contact list entry for me (I believe created through a 3rd party OSX app), and in the Facebook field it had the name used on the admin/ads account I have. Given I don’t use my real email address on the Facebook account I am amazed (but not particularly surprised) that the connection was made.
> A Facebook spokesperson said Charity may have been asked to download the wrong software because some malware can spoof what kind of computer a person is running
Just changed the user agent?
2. run the malware scan
3. everything shows up as clean
4. ???
not defending facebook or anything, but that seems relatively easy to bypass.
Another reason not to use Facebook.
I guess you could copy the entire browser profile so it thinks it's the same machine, but that's even harder for your regular user.
"Yes, father. VirtualBox.org... Yes, .org, not .com... Without spaces, yes... Remind me, do you have Windows 32bit or 64bit?"
So this would probably work, but if you go back to your main machine then whatever config was mistaken for malware will trip the alert again.
it should be pretty easy for you to match your host machine's browser config on the VM, so unless the scanner drops some sort of plugin/addon to signal the whitelisting, it should at least whitelist you for a while.
That said, I'm on Linux, so it would be pretty tricky for me to fix this issue if it happened to me.
I realize internet companies all always hate offering info about data use, much less binding agreements. But "let us and a third party touch and modify every single byte on your machine to use our product" is a gigantic ask, and deserves at least some good-faith effort to keep the results walled off from everything except security initiatives.
Beyond that, the intent seems fine. I still think it's hubris, though - Facebook is ostensibly just a website, and attempting to remotely diagnose and treat malware is something they ought to acknowledge they're not going to do well.