<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Robert Dorrian &#187; malware</title>
	<atom:link href="http://blog.ten-24.co.uk/tag/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.ten-24.co.uk</link>
	<description>Computers, Coffee and Pedantry</description>
	<lastBuildDate>Sun, 07 Aug 2011 13:41:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Facebook Application Safety</title>
		<link>http://blog.ten-24.co.uk/2009/03/02/facebook-app-safety/</link>
		<comments>http://blog.ten-24.co.uk/2009/03/02/facebook-app-safety/#comments</comments>
		<pubDate>Mon, 02 Mar 2009 21:20:35 +0000</pubDate>
		<dc:creator>rob</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.ten-24.co.uk/?p=30</guid>
		<description><![CDATA[There&#8217;s been a recent outbreak of Facebook applications that spread by taking advantage of the notification system. The Gaurdian quote Mark Zuckerburg&#8216;s interview with the BBC, and he seems to think &#8220;an open system anyone can participate in is generally better&#8221;; does he not realise that most users are prone to social engineering attacks and [...]]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s been a recent outbreak of Facebook applications that spread by taking advantage of the notification system. The <a href="http://www.guardian.co.uk/technology/2009/mar/02/facebook-socialnetworking" target="_blank">Gaurdian quote Mark Zuckerburg</a>&#8216;s interview with the BBC, and he seems to think &#8220;an open system anyone can participate in is generally better&#8221;; does he not realise that most users are prone to social engineering attacks and the mentality of &#8220;guilty until proven innocent&#8221; is no-where near enough to protect the main populace?</p>
<p>As for the technically minded, we get to see all of these spam messages from the rouge applications whenever one of our friends add them.</p>
<p>A simple solution as I see it, is not to enforce full vetting of all applications, but to simply change the notification system so that it becomes blatantly obvious when messages are not genuinely from a friend initiated action, but from some application attempting to masquerade. I do support stricter control over applications, but perhaps an interim measure would be to modify the notification display.</p>
<p>The notification system allows too much flexibility over the format of the messages sent out, for those interested, this is what the <em><strong>Error Check System</strong></em> and <strong><em>Closing Down</em></strong> notifications look like.</p>
<p><img class="alignnone size-full wp-image-33" title="Error Check System Notifications" src="http://blog.ten-24.co.uk/wp-content/uploads/2009/03/error-check.png" alt="Error Check System Notifications" width="320" height="480" /> <img class="alignnone size-full wp-image-34" style="border: 1px solid black; margin: 5px;" title="Closing Down Notification" src="http://blog.ten-24.co.uk/wp-content/uploads/2009/03/violation.png" alt="Closing Down Notification" width="280" height="132" /></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ten-24.co.uk/2009/03/02/facebook-app-safety/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

