Researcher shows how to "friend" anyone on Facebook within 24 hours
arstechnica.com
arstechnica.com
Furthermore, this is an opt-in feature.
EDIT: tried to find a better source for that, came up with https://www.facebook.com/notes/facebook-security/national-cy...
Looks like the feature is still being rolled out, and the attacker doesn't get to choose which friends he trusts.
EDIT: Yeah, apparently it does. Sweet. Time to scour /b/ for some truly horrible shit to plaster peoples' profiles with. Also highly recommended: changing their birthday to tomorrow.
We want to make sure that your account and the information in it stays safe, so once you set up a security question on your account there’s no way to update it. Sorry for the inconvenience.
http://arstechnica.com/old/content/2008/05/ars-technica-acqu...
Security was one of the big issues for me. My brothers account had been hacked, and the hackers managed to get some cash out of some of his friends.
But I digress, and this off topic, but I don't miss FB at all. I still maintain genuine relationships outside of FB and find I have more time for proper conversations with people via Skype and email. FB to me was crack, I hated to love it. Now I love to hate it.
Does anybody out their maintain genuine relationships through FB? (Serious Question) Why are we using it? Is it an addiction?
I think this speaks to Facebook as a status symbol not as a communication tool. Why do you upload pictures of your vacation? Because you want grandma to see them and enjoy seeing your lovely face or is it to impress all your friends with this awesome life you have. I think it is mostly the latter.
Clearly, the relationship isn't going to depend on if I have a Facebook profile, but both women want their friends to be able to see that they have a 'real boyfriend' with real interests, pictures, etc. In effect they want to show off for their friends.
And perhaps also position themselves defensively with regards to other men. It seems to me that listing a name with no hyperlink is something you could do to "fake" having a boyfriend, and thus might not be a very effective deterrent to unwanted attentions from another man. An actual FB account linked in that section is much stronger proof that a woman is unavailable, so please don't bother me.
It seems to me that if you have some significant portion of your social life online, indicators of that sort can be rather important. I know that when I was still married and could publicly portray myself as a "woman who has been married with children for a very long time" I did not have to deal with certain kinds of things in online social settings. I joined one forum after it was clear to me and my spouse that we would divorce but at a time when our status was still publicly presented as "married, with children". When I was at a point where I was ready to publicly admit I was facing a divorce, I suddenly had online social situations to deal with that simply did not crop up when everyone figured I was about as off limits as a woman could get. So my personal situation had not really changed (as I was still "facing a divorce" and not really available) but there were very noticeable social consequences when how I presented my social status changed.
I'm not on Facebook. I deleted my account earlier this year and never used it that much and I think everyone I knew on Facebook was probably either female or only interested in me due to my medical diagnosis. So I never dealt with that aspect of Facebook. But I know that I do deal with the need to signal my "currently unavailable" status in other online social settings. It's simply far easier and more effective to just make it generally publicly known that I am not currently available than to try to deal individually with every potential inquiry.
So my guess would be they are not simply showing you off to their friends. It probably serves a broader purpose similar to an engagement ring or other offline relationship status signal, and that means it may also have implications for things like what types of social invitations that single women friends might extend to them (ie "I'm no longer available for girls night out, where we go out drinking/partying" or something). Whether there is a hyperlink vs just a name listed may have hard to quantify but real impact on how others interact with them.
Facebook doesn't make it clear about what types of data they do and don't keep beyond saying they disassociate you from the information, but retain some for 'technical' reasons. I can't really imagine what those would be.
[1]http://www.facebook.com/help/?faq=125338004213029#What-is-th...?
Probably the thing about databases getting fragmented, so they delete large swaths of data and optimize all at once, rather than piecemeal when the users delete it. It's well known that when you "delete" a photo from Facebook, if you save the direct link to it first, you can still access it (go ahead, try it). But the one time I tried it, the photo did finally disappear after about a week (although I have seen some people claim that they could access deleted content via direct links for up to 6 months).
Like, "Car thieves who want to steal your car can construct an exact replica of your street, house, and garage, so that you're actually parking right in the thief's carpark, security researchers reported today."
I agree that accidentally friending a fake account probably won't lead to much further online problems: the trusted friends example used in the article is far-fetched (and other HN comments indicate it's complete bogus), and they're not going to get your credit card info or account passwords. However, it's still a privacy concern. Anyone from an estranged ex-lover to a private investigator could get information like home address, vacation times, etc.
Only if you put information on Facebook that you're not comfortable sharing with the whole world.
Are you singling out Facebook, or just referring to web services in general? Would you also say that you shouldn't have data on Gmail that you're not comfortable sharing with the whole world? What about online banking? All of those things are probably vulnerable to social engineering.
That's the end-result of "having insensible privacy defaults, and having confusing privacy controls." It happened when they changed their privacy model, and things that were private-only became public by default. But, normally, it's not that Facebook ignores your settings, but, rather, people assumed things were more private than they actually are. See people's recent reaction to the real-time updates of what your friends are doing on Facebook - many of the people I am friends with where aghast at this, because I don't think they realized all of that stuff was already public.
Basically, I think the privacy-model on Facebook is complicated, but I think it's an inherent complexity. It's not complex because Facebook is inept, it's complex because the problem of determining who in your large social network should know what is actually a complicated question. That privacy model is too complicated for people to grapple with every time they share something on Facebook, so they don't grapple with it. I don't want to grapple with it, either. Hence, I only share things on Facebook I'm comfortable sharing with the world. My Facebook page - wall, photos, info, comments - are all public. Then I have a very simple decision to make: am I okay saying this to everyone? If not, I don't say it. Hence, I don't say much on Facebook.
The internet is an inherently public place. Facebook puts a megaphone on the internet.
Would you also say that you shouldn't have data on Gmail that you're not comfortable sharing with the whole world?
In general, yes, although even I have difficulty with that one. But email is just plain text (unless you encrypt it, and very few people do) bouncing around the ether. It's out there, and you have little control over it. Banking is different, as the information is only shared between you and your bank. Not so with email, which always has at least one other party involved.
Seems about proportional to the difference between having a stolen car and having a fake friend account. I mean honestly what are you going to do with that? Find out some posts that hundreds of other people know about and would probably tell you if you called them up and asked? Stage an elaborate ruse with the fake account that will fall apart the second the target communicates with the real person on a non-Facebook channel? I mean I guess someone might have there reasons, but there's a million crazy things a stalker can do in real life too.
Depending on the victim, this may or may not pose any real concern. Some people probably share their entire profile and activity to their entire network, and probably don't post anything dangerous. However, some people are selective with their friends, and may very well share more private things (e.g. health/employment status, home address, phone number, etc.).
You're probably right that the average Facebook user wouldn't be at risk, since they probably already share with hundreds of quasi-friends and therefore don't post anything too personal or risky. The thing is, that probably applies to most Gmail accounts too, yet everyone recognizes a compromised Gmail account as a bad thing. I don't understand why you're minimizing the potential impact of having a bogus friend on your friends list.
Privacy is a matter of not using Facebook.
The same principal works for real life too.
If you don't mind Facebook knowing what you said, you can send a private message.
That may not be a solution that people like, but it's what I do, and I think it's what we will all end up doing eventually.
And that's the point.
If a current offering such as Facebook is "not a solution that people like", then that creates an opportunity for a solution that people _do_ like.
Will that opportunity be exploited? If not, why?
If someone only wants to tell something to some of their friends, and assuming "some" is not a large number, does the network have to be "large"?
If so, why?
There are ways to share secrets with a small number of friends online, but even among technical people, very few people do it. I can see that it's possible to create a service around, say, PGP encrypted messages, and I can even see abstracting out the technical details of it. (That is, not forcing the users to think about keys, instead saying "Tell us who you want to be allowed to know the secret" and making and distributing public-private keys on the fly.) But I think even that level of conceptual overhead is more than lay-people are willing to deal with.
My question was about the size of the _network_.
In any event, following your line of thought, do you think it's possible to have a many _small_, separate networks that were somehow part of a large service?
Regardless of your answer, does our solution have to be a "service"?
What if it is a "product" that creates small networks as overlays on a larger, existing network such as the one all your friends are connected to: the internet?
You said: "I can see that it's possible to create a service around, say, PGP..."
What if you could see that it's possible to create a service (or product, or both) around, say, a scheme that involved only a single shared password and a single shared encryption key? That is, each friend has to remember only two strings for each network to which she belongs, sort of like, say, a username and password.
What if you could see that such a scheme might not require logging on and logging out as frequently as a web-based service such as Facebook?
Would that change your thoughts at all?
You said, when referring to a PKI scheme like PGP: "But I think that [the] level of conceptual overhead is more than lay-people are willing to deal with."
I once thought the same thing about Amazon's S3 service. When I saw the Dropbox product, my thoughts changed.
There may be one situation in which technology helps, which is when you want to discuss a secret while remaining anonymous. For that, we have 4chan, reddit, forums, IRC, etc.
With respect to "telling something to some of your friends", and attempting to do so "privately", there are certainly ways to do this without using Facebook.
However, that was only a specific example I chose, in line with veb's example of telling people you rub lettuce on your face, to use to illustrate to scott a point about whether only large networks could be useful in order to stay in touch with a small number of people, i.e., your friends. In theory, I could use any online activity or any service/protocol as an example to illustrate what the "solution" (a small private network) aims to achieve.
Talking (VOIP e.g. SIP), smtp (email), IRC and http (web forums), to use your examples, are examples of services/protocols that can be run over a network. Of course it is not an exhaustive list.
You could run them over the open internet, i.e. a very large, public network (of networks).
You could also run them over a small private network to which only a selection of people belong, e.g., your friends.
In theory, anything you could do with your friends on Facebook you could also do with your friends on your own small private network.
Multiplayer games is something for which this idea of "being on the same network", all at the same time, is well-suited. This is not a new concept. It is a very old one. Consequently, it's time-tested.
But playing games is only one example of what you can do.
The internet supports many services.
Theoretically, so too can your smaller network.
An obvious difference between doing things on the open internet (Facebook) and doing them on your own network is: _privacy_.
You do not have to invite advertisers and countless others to your private network if you do not want to. Might this be important to some people? That is an open question.
_Privacy_, of the kind discussed in the Facebook context, is the goal which the "solution" we are discussing aims to address.
Not simply "private mesaging" but privacy in everything you do with your friends online.
Rest assured, even if such a solution did exist and could be shown to work (NAT and whatever other issues you might predict have been solved), all the Facebook-type user interface doo-dahs are noticeably absent.
As such, it is a non-starter for any friend who cannot use a command line, unless some very good user interface developers got behind it.
And all the mainstream messaging services to date have been centralised, at least in the sense that they involve interacting with a third party server.
When each friend can be both a client and/or a server, no third party servers are necessary. In theory (and practice), this is something you can achieve on a small network consisting only of your friends.
What if all your friends want to be online at the same time?
What if they want to share photos and video while online at the same time?
What if they want to play games with each other while online at the same time?
You can currently do these things with the mainstream web-based services like Facebook. But they are recording everything you say and do _and_ selling that information for profit. You don't receive any portion of that profit.
Is everyone OK with this?
It's an open question, I guess.