New security settings coming to Facebook
blog.facebook.com
blog.facebook.com
When a user has to tag someone they are given standard sized box to drag over the person you want to tag while the face recognition systems selects only the face of the person no matter how big or small it is on the picture.
This way, when I know it's me logging in, I can just ignore the text, but if it isn't me (some hacker in Germany, for instance), I can immediately bump them off, and I don't have to wait for the damage to be done to reclaim my account.
If you're in a place where it's likely your computer could be compromised then this keeps your regular password secure.
Haven't the social captchas been used for some time now? I'm sure I've seen them before.
Except they're not really doing that yet. Read the full section: some facebook sections, and most applications aren't yet HTTPS. And it's off by default. And the setting is hidden deep inside your advanced security settings.
They do say it will be default at some point in the future, which is exciting. But for the moment, this HTTPS step is just a small one.
My biggest privacy complaint is my inability to change my application/privacy settings to keep other people from changing MY profile page by tagging me in pictures.
I do not want people tagging me in photos, and while I explicitly tell people not to, they still do. I can remove the tag once Facebook notifies me, but I don't hover around my computer waiting for notices, so there is a period during which these pictures appear in my status, my albums, my wall, and I have no ability to keep people from seeing them. This is a violation of my privacy, to which the only solution is deleting my account to make myself untaggable; something I don't want to do, because I truly enjoy using Facebook.
This really needs to change. Please add a privacy/application setting that either makes you "untaggable", or at least prevents tagged pictures from being automatically put into your status feed / wall / albums.
People tag themselves wrongly. A lot of my friends are people from when I was young - I don't know how they look anymore.
And in Africa for example, you are often using Satellite connections, so depending on the internet Cafe, you log in from Israel, then Kenya, then South Africa, all in one day. And you get locked out each time.
Practically, it's very, very retarded.
1: Load the social captcha
2: Load your entire friend list
3: Look at the first photo of a friend, then examine every one of your friends (the average user has a couple hundred) and match them up, assuming that their profile photo is similar to the randomly-selected photo from the social captcha
4: Repeat this whole process two more times
Social captchas protect you against somebody from Nigeria hacking your account, and makes this process more computationally intensive. Even if they did login to your account after all this work you'd end up getting an email and SMS saying that there was a login from an unrecognized computer.
The example posted on the FB site looked like a multiple-choice selection was to be made, so the putative hacker would only have to look up those six friends, not look through all of your connections.
Can anyone answer me how it is safe to have the advertising accounts which require credit card information to make payments, not be HTTPS like they are currently? How has there not been a serious breach with all the kiddies running around with fire sheep and the like?
Fuck the social captcha, how about Facebook nationalizes the best non obtrusive apps (I don't know of any, but maybe there are some) and eliminates third party shit from the site entirely. Third party crap apps will destroy the site if not kept in check.
Looks like they are more concerned about the security of their accounts than men do.