Is social networking a threat to your security?

By Natasha Lomas, Special to ZDNet Asia
Tuesday, July 24, 2007 11:49 AM

Social networking sites could be exposing consumers and businesses to increased security risk, it has been claimed.

According to credit information provider Equifax, fraudsters could make off with users' personal information in order to commit ID theft--and the company is urging Web users to limit the amount of info they post online.

Neil Munroe, external affairs director for Equifax, said in a statement: "The problem is that people don't realize the significance of the kind of information they are putting out on the Web and who may be accessing it." He cited details such as date of birth, e-mail, job and marital status as the kind of data frequently posted online by unwary users.

Munroe added: "Fraudsters can use this information to steal an individual's identity and open accounts in their name."

And Mark Murtagh, technical director of security company Websense, warned the rise of Web 2.0 applications is creating "security and productivity challenges" for European small businesses.

When it comes to Web security, research from Websense highlighted what it dubbed SME workers' 'blind confidence' in their IT departments--66 percent of workers believe in-house techies are protecting them from all Internet security threats. Moreover, it found the vast majority (98 percent) of IT managers believe their technology and security processes are adequate, while more than half (53 percent) believe their company is very well protected against security threats. A quarter even feels completely immune.

This is dangerous complacency, said Websense. Out of a list of nine potential security risks, the survey showed that not a single company protects against all threats.

And while the majority (84 percent) of European SMEs said they do have Internet usage policies, only a quarter (25 percent) ensure employees sign them. And fewer than half (47 percent) automate their policies by using Web filtering software. In addition, the survey found 15 percent of businesses believe firewall and antivirus solutions are sufficient protection for their business.

The issue of data theft should be of particular concern for SMEs, according to Websense--not least because close to half (45 percent) of survey respondents admitted to engaging in activity that could put their company's data at risk.

Murtagh blamed "smaller IT budgets and fewer technical staff" for punching holes in SMEs' Internet security systems but also emphasized the data-theft risk resulting from companies' failure to control the use of peer-to-peer applications or to block access to phishing Websites.

According to the survey, only six percent of SMEs block iPods or other USB-based storage devices; 22 percent block peer-to-peer apps; 30 percent block instant messaging attachments; and 31 percent block phishing sites. Meanwhile, a quarter of SME staff surveyed said they could not live without P2P file-sharing during their work day and 17 percent said they use free software download Websites at work.

The Websense study questioned 750 IT managers and general employees in companies with up to 100 to 250 employees in France, Germany, Italy, the Netherlands and the U.K.

Equifax has issued a list of top tips for users of Facebook et al, including the following:

  • set up privacy on your profile so only close friends can view it
  • don't use common verification such as your date of birth or your mother's maiden name
  • be wary of the intentions of anyone you meet on these sites
  • Natasha Lomas of Silicon.com reported from London.


    WORTHWHILE?

    0

    0 votes
    Blog

    Talkback 1 comments

    Surely the underlying issue is banks/credit card issuers and others using easily obtained information for authentication purposes. Dates of birth, former addresses, and even social security numbers can be obtained these days regardless of whether you post on social networking sites - it's high time the insecurity of these identifiers is recognized.
    Posted by John Bowser on Thursday, July 26 2007 08:49 AM


    Tech Jobs Now!

    Search for your ideal tech job:

    OpenAmplify developer's diary - part three: Topic intention comparisons

    Web Development

    Justin James chronicles his process of using Hapax's OpenAmplify Web service to create an application that can match documents with content that is similar or identical to the source document.


    Read more »



     
    Virtualize your way to cost savings
    Build an infrastructure that is flexible, scalable, and economical, as you strive to become a truly agile business.

    Red Hat Outlines Its Virtualization Strategy and Roadmap for 2009
    » Watch the video




    What Y2K can teach us about 2012

    Blog thumbnail

    Dec. 21, 2012. It's a big day on the calendar, particularly because some believe it marks the last day of the world as we know it. The apocalypse. Armageddon.

    The..... by Eileen Yu

    Read more »

    Tags

    1. advertisement
    2. blog
    3. facebook
    4. google inc.
    5. internet
    6. internet advertising
    7. microsoft corp.
    8. network
    9. revenue
    10. search
    11. social networking
    12. software
    13. u.s.
    14. video
    15. web
    16. web 2.0
    17. web browser
    18. web services
    19. web sites
    20. yahoo! inc.