Contributor

As predicted, social networks are fertile ground for hackers.

Opinion
Oct 17, 20081 min
facebook logo

In retrospect predicting that Facebook and MySpace worms would arise seems like a no-brainer.  The researchers at F-Secure describe a new threat from Net-Worm.Win32.Koobface.bp which spreads by inducing you to watch a YouTube video that asks you to “update your Flash player,” a fake-codec-update technique. When you install the “update” you get infected, the worm looks for Facebook cookies, goes to Facebook, and sends a message to your Friends to look at the video, thus propagating widely.  Apparently the payload does no more damage. What can I say?  The social networking sites, Facebook and MySpace in particular, are going to have to start detecting this type of activity and blocking it.  It takes a lot of abuse to destroy a popular social medium. But it happens. Look at Newsgroups. Have you tried Craigslist lately?  It is the private hunting ground of predators and scam artists. Facebook and MySpace have limited time to address this. If they don’t their very existence is threatened.

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author