::Trend Micro Threat Resource Center::

19 November 2010

Facebook Messaging System Opens New Security Concerns

The next big thing in social media has been revealed in Facebook's new Messages system, which combines email, texting, and instant messaging into one threaded experience. They want to let people talk to each other without having to worry about whether the recipient prefers email or SMS, etc. This also opens the way for new security challenges to be overcome as more and more people start using this new service.

Sophos, an internet security company that advertises a variety of email and encryption services, has released an article concerning the new Facebook Messages system which focuses on the new security issues that need to be considered for people who opt to use it. In it, senior technology consultant Graham Cluley discusses that the burden of security lies more with the user than with Facebook itself. He says, "Before signing up, users need to realize that these new features increase the attack surface on the Facebook platform, and make personal accounts all the more alluring for cybercriminals to break into. Facebook accounts will now be linked with many more people in the users' social circles - opening up new opportunities for identity fraudsters to launch attacks." Basically, spammers now have more of an incentive to hack into Facebook accounts using phishing attacks and exploiting weak passwords.

The other security issue that Cluley discussed was the fact that "users also need to be aware that Facebook will be storing a complete archive of all of their communications with one person - this raises concerns as to how this data could be misused if it fell into the wrong hands." Imagine every conversation you've ever had with anyone being recorded and stored on servers you have no control over. All that vital information in the wrong hands could most certainly spell trouble for anyone unfortunate enough to fall victim to such a situation. For more security-based information about the new Facebook Messages system, check out the Sophos FAQ about it.