Identity Theft and the Social Web
Posted in Privacy, Security, Social Engineering on April 9th, 2009 by blakangelBruce Scheiner is covering an interesting security aspect of Web 2.0 over at his blog: identity theft scams. Though I believe a more apt category would be social engineering, because this vulnerability is not limited to solely ID theft. This demonstrates the need to be vigilant in deciding who to friend on these social networking sites. But not even that will protect you, because your friends or your friend’s friends may not be as security-conscious as you are, and that leaves a way in for the enterprising social engineer. I mean, I’ve been on facebook all of 2 weeks, and every day the site itself asks me to friend some person I don’t know. And how many of us have seen the profiles with 1000’s of friends? Come on, no one knows 1000’s of people well enough to actually consider them friends.
