Home
Documents
Blog
Community
My Profile
Community Members
Group Directory
Group Details
Discussions
Announcements
My Inbox
Community Events
July 4th
Knowledge Base
Support
Contact
Hosting Services
Site
Web
Search
Login
|
Register
You are here:
Blog
Best Practices
Security
Blog
Current Items
|
Archives
|
Search
26
Facebook Launches Social Login and HTTPS
NDD-Support
posted on January 26, 2011 17:31 |
There has been much fuss over security during the last few days at Facebook. First there were reports about
Facebook getting hacked in Tunisia
. And then another report came up about Facebook CEO
Mark Zuckerberg’s Facebook page getting hacked
. And to top all this, another supposed
XSS
hack plagued Facebook wherein a lot of users are seeing a status update from a Roy Castillo whom they are not even friends with. In order to counter all these security issues, Facebook has introduced 2 "new" features (
really?
). Realistically, any measures taken are useless as long as Facebook keep gleaning your personal information for corporate gain. But, it's my blog...so here are the features and my first take on them.
Social Login
Unlike many who say this is innovative, it's not, it's been around awhile and frankly,it stinks. Social Login is meant to verify real users rather than using CAPTCHAS. Using the Social Login feature (or Social Authentication as Facebook calls it), users will be shown a few pictures of their friends and then they will be asked to name the person in those photos.
This may be innovative but I don't think I would like to agree with Facebook on their statement - "Hackers halfway across the world might know your password, but they don't know who your friends are" as it won't be very hard for a hacker to find out the Picture of an user's friend. Here is a screenshot of Social Login at work:
So I have to match a certain number of pictures with the right person. The summary makes it sound clever and good, it is anything but. Here's the problem, the first photo may be a friends face, no problem. The next one could be some kid. A relative of one of my friends? A neighbor of one of my friends? Shoot could have even be one of my friends as a kid, I have no idea. All I know is I've got a 1 in 4 chance of guessing who this belongs to and if I'm wrong I've just used up my one wrong answer.
Next photo is an inanimate object. I don't know remember what it was any more. A pie or some food of some kind I think. Which friend is this?! I don't know. Best guess it is something one of my friends ate once. Who does it belong to? Once again, I wouldn't the slightest, but as you can guess, I wouldn't be allowed to log in!
No here's a big issue for those who "friend" everyone! That don't have a clue who may have tagged a Jr. High School picture from long ago. Personally I don't think I'd be able to pick out High School friends with any certainty! And another small issue is people who are
faceblind
, make you wonder if they can be sued under the Americans with Disabilities Act.
HTTPS
HTTPS seems to be a common solution to all security problems faced by big websites. Even Facebook will from now on let users to choose if they want to switch to the HTTPS mode for browsing Facebook. You should do the following immediately. Users can find these options in the "Account Security" section of the
Account Settings
page.
Posted in:
Security
,
Web Development
Actions:
Related Articles
Facebook "the Most Appalling Spy Machine" Ever
Facebook "the Most Appalling Spy Machine" Ever. That according to WikiLeaks spokesman Julian Assange. There is a reason that I'm not a Facebook fan, a...
Why Facebook Won't Stop Invading Your Privacy
Facebook and its developers could bring in as much as $1 billion this year; only a bozo would think that Mark Zuckerberg will give that up to protect ...
Is it Facebook, or the users?
A directory containing personal details about more than 100 million Facebook users has surfaced on an Internet file-sharing site. The 2.8GB torrent w...
Post Rating
1
2
3
4
5
Comments
There are currently no comments, be the first to post one.
Post Comment
Only registered users may post comments.
Login
Sign Up
Categories - Topics
Best Practices (9)
..Security (9)
WordPress (1)
Product Review (7)
Software Development (7)
..Database (1)
..DotNetNuke (12)
Web Development (14)
Web Design (2)
Technology (8)
Tags
DNN
social
release
Microsoft
social networking
Facebook
dotnetnuke
ctp
Silverlight
IIS 7.5
beta
IS 7.5
Expression Encoder 3
Expression Studio
Expression Web
Flash
Telerik
Blog
SEO
support
AppPool Identity
database
ERD
jQuery UI
privacy
Review
Google
Google+
SQL
WikiLeaks
contest
website
dnnWerk
RadEditor
knowledgebase
module
chat
swirl
HTTPS
Social Login
MakeDNNSite
blackberry
verizon
help desk
c#
Internet Explorer
FireFox
Chrome
Maqetta
HTML5
OpenAjax
IBM
business
ROI
communication
network
Wi-Fi
software
development
Ventrian
© 2011 Net Data Design, LLC
Terms Of Use
Privacy Statement