Showing posts with label Information Security. Show all posts
Showing posts with label Information Security. Show all posts

Sunday, December 6, 2009

Facebook Intends to Maintain Privacy for Users

As many college students and people all over the world know, Facebook has become the largest online social networking website over the past five years. We have seen it grow from merely a college networking website to a global connection source. However, as Facebook has grown to an astonishing 350 million users, the privacy standards have somewhat diminished due to the consistent growth and additions Facebook has made over the past five years. While it is no fault of Facebook founder Mark Zuckerberg that the privacy standards been somewhat impaired, there are significant problems that have arisen in the privacy department as Facebook has grown in users. As stated in the open letter from Mark Zuckerberg on December 1, 2009,

"Starting with the very first version of Facebook five years ago, we've built tools that help you control what you share with which individuals and groups of people. Our work to improve privacy continues today."

As we have seen through this class, many information that we share online is subject to identity theft and online criminals around the globe. It has become such a complex situation that now people across the world can access information on any single person and use it to purchase and steal merchandise as well as money. The internet while very valuable and useful has also aided to one of the largest criminal acts in a very long time. Facebook has contributed to networking and is a social utility that is great for maintaining relationships throughout our nation and across the world. However, with the original setup of allowing people to access information and material through accessing a specific network, such as a school, country, or even a company, our privacy in many ways has been compromised. For this reason, Mark Zuckerberg has tried to develop a new way that Facebook will allow users to connect.

In his letter on December 1, 2009, Zuckerberg stated that he will remove the regional“networks” as he called them (which basically is countries and cities that can be used to join Facebook), stating that over 50% of all users use area networks to access material of other people, making it a complicated and difficult practice to implement privacy controls. He stated, “The plan we've come up with is to remove regional networks completely and create a simpler model for privacy control where you can set content to be available to only your friends, friends of your friends, or everyone.” This makes the privacy controls simpler and easier to maintain by the 350 million users, and will prevent people who are not granted access to uploaded and posted material by users within that network.

These new privacy controls will allow Facebook users to maintain a certain aspect of privacy while allowing them to share what they want with whomever they want. While these controls seem to be the answer to keeping the integrity of profiles on Facebook, we know that somewhere along the line privacy will always be an issue in the online community and the safest way to maintain privacy is to abstain from posting anything not wanted on that specific website.

Source:

http://blog.facebook.com/blog.php?post=190423927130


Friday, December 4, 2009

Internet message boards and attacks

Have you ever wondered where widespread internet jokes come from? All of us have probably seen, and enjoyed, many internet based jokes. Whether you laughed at the youtube video Chocolate Rain, viewed "lolcatz", or you were a victim of a rickroll prank, you are familiar with how fast and widespread these jokes can be.

For the most part, these jokes were started, or at least popularized by the website 4chan.org. WARNING: THIS SITE IS HIGHLY OFFENSIVE, AS BOTH EXPLICIT CONTENT ON THEIR MESSAGE BOARDS AND ADVERTISEMENTS ARE WIDESPREAD. This site has a large subculture following.Though mostly immature humor, sometimes the users of this site come together to take part in mischievous behavior.

The users are known for widespread attacks known as raids. Typically, many users will take part in a raid at the same time to cause widespread problems. In one instants, users "raided" a white supremacist website through a DoS Attack, causing the website to go offline. In another instance, a user of 4chan posted the Google HTML numeric character reference for the swastika symbol. A multitude of users than searched the code and pushed the symbol to the top of Google's hot trends chart. Later, Google removed the symbol. 4chan users have also caused problems for the Religious movement, Scientology, by taking parts in raids on the official website.

For the most part, the 4chan raids are harmless mischievous pranks. On the other hand, they tend to be offensive and cause harm to the sites they target. 4chan does show the potential of mass attacks taken out by an enormous amount of users, through techniques as simple as Google search.

http://en.wikipedia.org/wiki/4chan#Media_attention

Friday, November 20, 2009

Google Chrome OS

In 2010, Google will attempt to break into the operating system market with the release of Chrome OS. The driving principal behind the operation system is speed. Google’s engineers goal were to produce an experience similar to television, with regards to speed.
From a security point of view, one advantage of Chrome OS will have over the established PC model is that Chrome will not allow applications to install locally or make changes to the operating system. In laymen’s terms, instead of installing programs to the hard drive, like the established PC model, the programs will be available through the internet, like iphone apps. All of your data and applications will be automatically synced to the cloud. Matt Papakipos, engineering director on the projected, summed up this move by saying, "If I lose my Chrome OS machine, I should be able to go get a new machine, and have everything back up running in seconds" via the automated cloud backups.
As for encryption, all user data on every Chrome device will be encrypted, in case the device is lost or stolen. Another aspect of the boot process enhances security. “A verified boot process applies cryptographic signature keys to each chunk of code, so the system can check the validity of module of the operating system before it is allowed to execute. In the event that some element of code doesn't check out--due to malware or other corruption, the system will run an automated recovery procedure repair itself by redownloading the appropriate version of Chrome and reimaging the OS” (Strohmeyer).

http://www.pcworld.com/businesscenter/article/182655/google_chrome_os_unveiled_speed_simplicity_and_security_stressed