UK Home >  OUT-LAW News >  News Archive >  2009 >  December 2009 >  Facebook users have yet to learn privacy lessons, finds study

Facebook users have yet to learn privacy lessons, finds study

OUT-LAW News, 09/12/2009

Facebook users still give out their personal information far too readily two years on from a report which first came to that conclusion, according to security company Sophos.

advert: Data Protection Update Sessions by Amberhawk and Pinsent Masons. London, Manchester, Edinburgh. £95+VAT

Two years ago Sophos conducted an experiment amongst UK Facebook users. It created a fictional character and asked 100 people to befriend it; 43 did. It has just conducted the same experiment in Australia and found that social networking users have not learned to be more careful.

The survey found that 46% of users in a fictional 21 year old's age group accepted the offered friendship, while 41% of a fictional 56 year old's peers did.

On Facebook once someone has been accepted as your 'friend' they can see more information about you, but you can still choose to hide information from those friends or limit it to specific groups amongst your online friends.

Sophos found that once the fictional characters had been accepted as friends they had access to huge amounts of data that is exactly what scammers need in order to impersonate someone.

"Both groups were very liberal with their email addresses and with their birthdays," said Sophos head of technology in Asia Pacific Paul Ducklin. "This is worrying because these details make an excellent starting point for scammers and social engineers."

"Nearly half of the youngsters, and nearly one-third of the 50-somethings, also offered up details about friends and family – again, information which scammers and identity fraudsters can exploit to build up an accurate and abusable profile of you and your lifestyle," he said.

Scammers can use all sorts of information to access a victim's bank accounts, company records or gain credit in their name. Email addresses are often user-names for services, and many people use their birthdays as the basis of passwords.

Information about a person, such as their marital status, family arrangements and even pets' names, can be useful in pretending to be a person and 'socially engineering' access to their goods or records.

"Ten years ago, getting access to this sort of detail would probably have taken a con-artist or an identify thief several weeks, and have required the on-the-spot services of a private investigator," said Ducklin. "Sadly, these days, many social networkers are handing over their life story on a plate."

Sophos published guidelines to follow to prevent important information falling into the wrong hands.

"Don't blindly accept friends," it said. "Treat a friend as the dictionary does, namely 'someone whom you know, like and trust.' A friend is not merely a button you click on. You don't need, and can't realistically claim to have, 932 true friends.

"Learn the privacy system of any social networking site you join. Use restrictive settings by default. You can open up to true friends later. Don't give away too much too soon.

"Assume that everything you reveal on a social networking site will be visible on the internet for ever. Once it has been searched, and indexed, and cached, it may later turn up on-line no matter what steps you take to delete it."

 

Disclaimer: We hope you find OUT-LAW’s content useful. It’s prepared by the lawyers at Pinsent Masons. Please remember, though, that it’s intended as general information only. It’s not legal advice. If that’s what you’re seeking, please contact us. See also: our full disclaimer

 

OUT-LAW Recommends

This week's podcast
Football snap spat


Advert: How can I manage the costs of my litigation? Our forensic accountants can help

UK Home | 
2010 | 
2009
2008 | 
2007 | 
2006 | 
2005 | 
2004 | 
2003 | 
2002 | 
2001 | 
2000 | 
Fun | 

 

Pinsent Masons named Legal Firm of the Year 2009 at Finance Directors' Excellence Awards

OUT-LAW star: link to the home page
Disclaimer: This was printed from OUT-LAW.COM, a service of international law firm Pinsent Masons. We hope you find this content useful. However, please note that nothing in this document constitutes specific legal advice. You should consult a suitably qualified lawyer on any specific legal problem or matter. Any questions, please email info@out-law.com.