Cyber Security Tip & Tricks
Showing posts with label HTTPS. Show all posts
Showing posts with label HTTPS. Show all posts

Friday, May 3, 2013

Securing Your Facebook Account


Facebook has emerged as the world’s most popular and largest social networking site with more than one billion users. Facebook has successfully marked its presence among teens as well as young and older adults. It’s a way to connect with your family or friends, a means of interaction with strangers.

Limit your connections

Most key privacy settings are accessible by clicking the arrow in the upper right-hand corner of your profile screen (next to your name and the Home button). From here, select Privacy Settings in the drop-down menu.  Click on Edit Settings next to the How You Connect option to begin your profile lockdown. This section contains five privacy settings.
Facebook privacy: connections
Limit who can find you, contact you and post to your timeline.

Facebook offers many features to its users for a safe and secure online experience. Facebook has recently announced and added the full HTTPS support for the site to keep you protected from security threats like viruses, malware and hackers. But, if you are using HTTPS support, encrypted pages take longer to load and your account will be slower. The best part of Facebook, however, is that you can customize your account’s settings and privacy to suit your needs.

Profile -> Settings
Go to: settings -> privacy 
Here you can customize visibility of your basic details such as profile information, status updates, friends, your wall, photos or videos you are tagged in etc. In short, you can adjust your privacy on all of the above elements.

Profile -> Settings
Go to: settings -> general accounts setting
In this section, you can customize your contact details such as your phone number, user name, password and e-mail address. You also can hide your contact details from strangers.

Profile -> Settings
Go to: settings -> timeline and tagging settings
In this section, you can adjust your settings for tagging of photos, who can see your timeline and who can add items to your timeline.

Profile -> Settings
Go to: settings -> blocking
Facebook also offers a unique “block” feature. You can use this feature to block those who are sending you weird messages, posting spam links or are annoying you in any way.

Other security measures
  • Do not click on suspicious links.
  • Use a unique password for accessing your Facebook account and never disclose it to anyone else.
  • Avoid logging into your Facebook account on untrusted networks.
  • Just because a link is on Facebook doesn’t mean it is safe avoid clicking on Facebook ads.
  • Avoid using third party applications like online data transfer, information exchange, games etc.
  • Never forget to logout.
  • Share your posts, updates, pictures within your friend circle rather than making it public.

How-To Video: Securing Facebook

Tuesday, September 18, 2007

The net is an insecure place - US CERT Reminder

If you use Gmail, eBay, MySpace, or any one of dozens of other web-based services, the United States Computer Emergency Readiness Team wants you to know you're vulnerable to a simple attack that could give an attacker complete control over your account.

US CERT warned that Google, eBay, MySpace, Yahoo, and Microsoft were vulnerable, but that list is nowhere near exhaustive. It said the world's biggest websites have yet to fix the gaping security bug, which can bite even careful users who only log in using the secure sockets layer protocol, which is denoted by an HTTPS in the beginning of browser address window. Just about any banking website, online social network or other electronic forum that transmits certain types of security cookies is also susceptible.

The vulnerability stems from websites' use of authentication cookies, which work much the way an ink-based hand stamp does at your favorite night club. Like the stamp, the cookie acts as assurance to sensitive web servers that the user has already been vetted by security and is authorized to tread beyond the velvet rope.

The thing is just about every website transmits these digital hand stamps in the clear, which leaves them wide open to snoops monitoring public Wi-Fi traffic or some other type of network. Once attackers have the cookie, they gain complete access to the victim's account, and depending on the way many cookies are crafted, those privileges may continue in perpetuity - even if the victim changes the account password.

Indeed, awareness of this man-in-the-middle vulnerability is by no means new. For more than a decade people have known that authentication cookies could be manipulated, but somehow it took the folks at Errata Security to make a presentation at Black Hat to remind the world that the risks continue.

If you're waiting for a fix, we recommend you pack a very large lunch. And beyond that, where possible you might switch to Google, which has already gone a long way to closing the hole.

As the only web-based email service we know of that offers a start-to-finish SSL session, the service is among the most resilient to cookie hijacking. Unfortunately, Gmail doesn't enable persistent SSL by default, and has done little to educate its users about its benefits.

The company also offers SSL for its calendar, search history, documents and reader services, and a Google spokesman said security engineers "are actively working to expand capacity to enable HTTPS encryption for all users."

In the meantime, a Firefox extension called CustomizeGoogle provides a simple way to ensure that all sessions with the above-mentioned Google services are automatically protected by SSL.

Recent Comments

Popular Posts