How Do Social Networks Create Security Risks?

445 views
β€’
March 28, 2012
by
RSAC Cybersecurity
YouTube video player
How Do Social Networks Create Security Risks?

TL;DR

Responsible social-network use requires considering how a post can harm other people, employers, and organizations, not merely the person publishing it. Public details about locations, travel, purchases, relatives, workplaces, and technical systems can help criminals, stalkers, terrorists, and targeted attackers identify victims and plan attacks.

Transcript

Hi there. Let's see. Now that the mic might be working, I, I, I would love you to applaud for another 18 more minutes, but I guess they want me to talk in the meantime. Um, okay, so I've got about 40 seconds a slide, so we'll see how it goes. But anyway, this presentation came about because social networking, I mean, I thought it was the dumbest th... Read More

Key Insights

  • Social networking predates Facebook and Twitter by decades, with bulletin board systems, IRC, Usenet newsgroups, mailing lists, CompuServe, AOL, dating sites, and blogs already supporting online interaction and information sharing.
  • Responsible use is the central recommendation, because refusing all social networking would be unrealistic and would ignore its legitimate value for keeping in touch and communicating with groups.
  • Careless posting can harm third parties, including relatives, colleagues, employers, and organizations, even when the person publishing the information accepts the personal consequences of disclosure.
  • Public workplace discussions can support targeted attacks, because the presenter used information from Usenet newsgroups during penetration tests to understand companies and identify more effective ways to target them.
  • Operational security failures can endanger families, as shown by a destroyer's crew webpage that identified its captain, his relatives, and where he lived after the ship launched missiles toward Osama bin Laden.
  • Location and travel services can advertise vulnerability, because check-ins and itinerary posts may show where a person is, where the person plans to go, and when a home may be unattended.
  • Combined personal data can reveal more than isolated posts, because searches, email, calendars, location information, photographs, social connections, purchases, and travel plans collectively create a detailed picture of someone.
  • Organizations can contribute to disclosure risk, because marketing staff and other company representatives may release sensitive information even when employees are expected to exercise greater discretion online.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How do social networks create long-term security risks?

Social networks preserve and distribute personal, professional, and operational details that other people can collect and combine. Posts about relatives, employers, photographs, travel, purchases, locations, calendars, and technical systems may help criminals or targeted attackers understand a potential victim. The resulting harm can extend beyond the account holder to families, coworkers, companies, and other innocent parties.

Q: Why is responsible social-network use better than avoiding it entirely?

Responsible use recognizes that social networks can be useful for maintaining family contact, communicating with groups, and supporting other legitimate activities. The recommendation is therefore not to reject Facebook, Twitter, or every similar service. It is to think before sharing, apply discretion, and consider whether a disclosure could expose another person or an organization to harm.

Q: How can employee posts expose a company to attack?

Employee posts can reveal internal details about a company, its technology, its people, and its activities. The presenter describes using Usenet discussions during penetration tests to research target companies and select effective attacks. He also argues that companies sometimes worsen the problem when marketing staff publish information that should have received greater scrutiny before becoming public.

Q: What personal information is dangerous to share on social networks?

Potentially dangerous disclosures include a person's current location, future travel, home address, relatives, workplace details, purchases, photographs, and technical information. A single item may appear harmless, but several services can be combined. A travel plan, location check-in, and purchase announcement could indicate that someone is away while valuable property remains at home.

Q: How can social-media posts harm people who did not publish them?

A post may identify relatives, colleagues, customers, or other associates who never agreed to accept the exposure. The presentation describes a military captain's family becoming a potential target because a crew webpage connected the captain, his home, and his relatives to a destroyer that had launched missiles toward Osama bin Laden. Careless disclosure can therefore transfer risk to innocent people.

Q: Why are location check-ins and travel posts risky?

Location check-ins and itinerary posts tell observers where someone is or where that person expects to be. The presentation warns that services such as Foursquare, TripIt, and Google Latitude can expose movement and absence from home. When location data is paired with purchase information or personal profiles, criminals may gain useful information for selecting targets and timing their actions.

Q: How did older online communities enable cybercrime?

Older communities such as Usenet newsgroups, IRC, bulletin board systems, mailing lists, dating sites, and blogs enabled people to publish information and interact long before modern platforms became dominant. According to the presentation, those disclosures supported cyberstalking, helped attackers identify computer addresses and suitable attacks, and made it easier to research companies and individual targets.

Q: Why does combining data from several online services increase risk?

Combining data turns separate disclosures into a more complete account of a person's intentions, relationships, schedule, location, interests, and possessions. The presentation points to searches, Gmail, applications, calendars, location tools, YouTube activity, social connections, and purchase information. Together, these sources may reveal far more than users recognize when evaluating each service or post independently.

Summary & Key Takeaways

  • Social networking did not begin with Facebook or Twitter. Bulletin board systems, IRC, Usenet newsgroups, mailing lists, CompuServe, AOL, dating sites, and blogs already enabled people to interact and disclose information online. Newer platforms combined these earlier functions, expanded participation, and made personal disclosures more immediate and visible.

  • The central recommendation is responsible use, not abandoning social networks. A person who shares carelessly can expose relatives, colleagues, employers, and other innocent parties. Organizations therefore have an interest in advising employees about discretion because individual posts may reveal operational, personal, or technical details that create risks beyond the account holder.

  • Location services, travel posts, purchase disclosures, photographs, calendars, searches, and workplace discussions can become valuable intelligence when combined. Examples include criminals learning when someone is away, attackers researching target companies, and terrorists identifying a military captain's family after his ship participated in a missile operation against Osama bin Laden.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š