Opinion: Dear Facebook, it's time to act like a grown-up about security
Computerworld - Dear Facebook,
I appreciate your service. I really do. I'm sure that many of your 400 million active users appreciate it as well. But now that you have a market value estimated at billions of dollars, it is time for you to start acting like a grown-up company. That means you have to provide basic security for your customers. And it means responding when your customers try to contact you, as I did recently to talk about an important security issue. Do you think you will be able to hold on to 400 million users if you treat them that way, and if you put their computers at risk? I don't.
As you can see, I have had to resort to writing an open letter on Computerworld's Web site, because all other attempts to get through to you were unsuccessful. I will be interested to see whether you respond to representatives from the media, or if you ignore everyone equally. Maybe you figure you have all 400 million of us over a barrel, since you provide a primary method of business contact and personal communication. Just keep in mind that MySpace was once the premier social networking site, and it was replaced -- by you.
Here is what I wanted to talk to you about, though: You are leaving your users open to a major security risk. Five minutes ago, I clicked on a page on your site, causing a new window to open that urgently warned me that my system was loaded with viruses. I was encouraged to click a link in order to run a program that would rescue my machine, but I didn't do that; I know malware when I see it, and I don't allow scripts to run on my computer. The problem is that many of your 400 million users don't know very much about malware. And by allowing things like that pop-up window from your site, you are putting their computers at risk. And that's bad news for all of us, since the likely result will be even more botnets in the world.
This was the fifth time in a month that something like this happened to me on your site. Now, if it happened to me that often, how many millions of times did it happen to all those other Facebook users?
Why are Facebook users being exposed to risk this way? Because you allow advertisers on your site who provide malicious links. Worse, you seem to do nothing to prevent such "ads" from running programs when someone loads the page. A company with 400 million customers that's worth billions should be able to filter out these attacks. I know plenty of sites run by much smaller entities that do as much. And I don't know of any other major site that allows this sort of thing to happen.
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- The Threat Landscape Hardly a day goes by without the discovery of a new cyberthreat somewhere in the world! But how do you keep up with...
- Security for Virtualization In the rush to implement virtualization, security has become second. So while the business benefits are clear, the risks are less well documented...
- Is Your Big Data Solution Production-Ready? Read "Is Your Big Data Solution Production-Ready?" now, and discover best practices and actionable steps to implementing a production-ready big data solution.
- Pay-as-you-Grow Data Protection: IBM Tivoli's Full-featured Data Protection Suite for Small to Medium Businesses IBM Tivoli Storage Manager Suite for Unified Recovery gives small and medium businesses the opportunity to start out with only the individual solutions...
- Webinar: Building a Big Data solution that's production-ready Big data solutions are no longer just a nice-to-have.
- Meg Whitman presents Unlocking IT with Big Data During this Web Event you will hear Meg Whitman, President and CEO, HP discuss HAVEn - the #1 Big Data platform, as well... All Malware and Vulnerabilities White Papers | Webcasts