Results 1 to 20 of 31
-
07-24-2010, 01:29 PM #1
ITT: I show you how to protect yourself on the net
So I was a bit drunk last night and was looking for something to do. My curiosity lead me to do some less-than-ethical activities, however, it showed me how FaceBook and lax security measures make us so vulnerable to identity theft and personal attacks, etc. First I'll tell you what I did, and then I'll tell you how to protect yourself against these sorts of things.
I logged into my FaceBook account, and went to my friends list, which contains a few hundred people. I started collecting email addresses that were listed on the profiles of people I'm friends with. Some profiles listed none, some one, and others a handful.
After getting a good amount of email addresses, I started looking in to how they help you if you've forgotten your password.
Student email accounts from different universities had a high level of security, requiring all of the following to reset a password: Full name, DoB, SSN, UID, and other things that weren't readily available.
Free accounts, however, are much more lenient account retrieval measures.
Gmail requires the account be idle (not logged into) for 24hrs, after which point it only asks a single security question which must be answered, at which point full access is given to the account, including the ability to change the password without know the old one.
Yahoo mail requires two security questions to be answered before access is given to the account, again, after which the password is changed with out the need to enter the old one.
First one I tried was a Gmail account. I clicked "can't access account", put in the gmail address, and it asked me the security question: "What is your favorite color?" I go back to the facebook account of the gmail account owner, and somewhere in the "about me" section was a single color among the other things about the person. So I type in that color, and it asks me to change the password, and then gives me full access to the gmail account.
bertstare.jpg
Second one I tried was a Yahoo account. First security question: "What is your middle name?" Didn't even have to look hard for that one. It WAS IN THE EMAIL ADDRESS ITSELF. Second security question: "What sorority are you in?" That took all of 10 seconds glancing at the persons FaceBook profile. Access granted, please change password, full access to account.
notsureifsrs.jpg
Third one I tried was also a Yahoo account. First security question: "What is the name of your oldest neice?" Browsing though some facebook photos of the person, one had the caption "Me and my neice [name]!! isn't she adorable!". So I put that name in, turns out she is the oldest. Second security question: "What was the make of your first car?" Look in the persons facebook albums, one is titled "My first car!", turned out to be a Mercedes. Typed that in, prompted me to change the password, and let me in.
isthisreallife?.jpg
You guys might be saying, "well whatever, I don't use my email for anything important, blah blah blah."
These questions are uncomfortably similar to security questions asked by banking and credit websites and other important online account. What would you do if one of those was compromised?
If you want to protect yourself, take a second look at all of the security questions across all of your online accounts. Most of the preloaded questions are bullshit, so if you have the chance to write your own question, DO IT! and ask something that ONLY YOU KNOW.
Next, take a look at your facebook profile. Best option? Deactivate/Delete it. However I know most people don't want to do that.
Just being "Friends only" isn't enough, as I've just shown, because that friend of that girl you talked with for 2 minutes at that party three years ago that you friend requested now has full view of your "friends only" account.
Ways to protect yourself on facebook:
Don't accept friend requests from people you haven't met in real life.
Become "facebook friends" with only actual friends.
Remove the following information from your profile:
-Date of birth (at the very least, the year)
-Hometown/Place of birth
-Links to Relatives (Important: if your mother is listed as your relative, and is divorced from your father, she is probably using her maiden name now, which is the most common security question for banking websites)
-All contact information (emails, phone, addresses, etc)
-Certain interests (If one of your security questions is "What is your favorite TV show", don't list that TV show anywhere in the "favorite tv shows" section of your profile, herp derp)
I hope you guys follow this advice because it's a scary world out there, and it's easier than ever to get information about anyone.Last edited by 86 IROC-Z; 07-24-2010 at 01:33 PM.
-
07-24-2010, 01:50 PM #2
I dont like your avatar......anymore
-
07-24-2010, 01:59 PM #3
good info
-
07-24-2010, 02:05 PM #4
Your definition of drunk:
My definition of drunk:
-
07-24-2010, 03:05 PM #5
- Join Date
- Apr 2008
- Location
- arizona
- Age
- 40
- Posts
- 178
- 2004,2008 triumph 675 SE
-
07-24-2010, 03:36 PM #6
-
07-24-2010, 05:47 PM #7
-
07-24-2010, 06:13 PM #8
I've had my avatar for a long time... I should change it...
(IROC's thread got derailed, hardcore)
-
07-24-2010, 06:22 PM #9
-
07-24-2010, 06:23 PM #10
-
07-24-2010, 06:46 PM #11
-
07-24-2010, 07:08 PM #12
I miss my old avatar
-
07-24-2010, 09:15 PM #13
I like to imagine my avatar reflects the expression on the faces of people who read my posts.
-
07-24-2010, 09:35 PM #14
I tried this with about 10 friends and couldn't get into one of them
Guess my friends are a little bit better secured then I thought
Granted I could ask the question to them and hit them up months later when the least expect it. Thanks tho IROC, I'll double check my shit
┌∩┐(◕_◕)┌∩┐
Man: The Mods you are fighting,
they are the biggest Men I have ever seen. I
wouldn't want to fight them!
Me: That is why no one will remember your name!
-
07-24-2010, 10:02 PM #15
-
07-24-2010, 10:08 PM #16
-
07-24-2010, 10:35 PM #17
Ok, maybe "skill" is'nt your thing. But it does require a thought process that most 12 year olds don't posess, they are too busy trolling around on 4chan and chatroulette. But a 40 year old "Dateline Perv" would definitely appreciate your well thought out blueprint of how to attain info on people
-
07-24-2010, 10:39 PM #18
Hey, I'm not 12...
You really think predators are going to bother snooping through peoples email? Their targets aren't intelligent, no need for extensive cyber forensics, just pick up a value-size bag of candy and wait at a bus stop.
Oops, I guess I shouldn't have said that, since I'm giving criminals instructions on how to perform their trade.
-
07-24-2010, 11:08 PM #19
Predators are freaks! They think up all sorts of ways to get at people. Speaking of chatroulette, ever notice how many fat hairy guys are jerking off? Who do you think they are?
-
07-24-2010, 11:21 PM #20
- Join Date
- Aug 2005
- Location
- Thornton, CO
- Posts
- 23,773
Red Tint Jewelcoat- 2008 Trailblazer SS
WTF is an avatar?
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
Moochelle: "Chip in $10 or more to protect Obamacare"
By wileyCoyote in forum Political / Debate ForumReplies: 4Last Post: 01-28-2014, 05:53 PM -
Customize and Protect With Armor All Custom Shield Coating
By Ed Blown Vert in forum Showcar and DetailingReplies: 5Last Post: 12-05-2013, 02:56 PM -
Mother shoots/kills home invader to protect baby
By BdAsBrd01 in forum Almost Anything GoesReplies: 47Last Post: 01-19-2012, 04:58 AM -
divorce advice! How to protect myself financially!
By RATCHETMASTER in forum Almost Anything GoesReplies: 65Last Post: 11-13-2008, 08:38 AM -
if you could only protect one which would it be?
By 0rion in forum Almost Anything GoesReplies: 26Last Post: 11-02-2008, 08:33 PM
Bookmarks