<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>techBLOGogy.net &#187; Internet Security</title>
	<atom:link href="http://techblogogy.net/index.php/tag/internet-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://techblogogy.net</link>
	<description>The Random Ramblings of a Technologist</description>
	<lastBuildDate>Tue, 06 Apr 2010 13:39:40 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9; </copyright>
		<managingEditor>dan@danandholly.com ()</managingEditor>
		<webMaster>dan@danandholly.com()</webMaster>
		<category>Technology</category>
		<ttl>1440</ttl>
		<itunes:keywords></itunes:keywords>
		<itunes:subtitle></itunes:subtitle>
		<itunes:summary>The Random Ramblings of a Technologist</itunes:summary>
		<itunes:author></itunes:author>
		<itunes:category text="Society &amp; Culture"/>
		<itunes:owner>
			<itunes:name></itunes:name>
			<itunes:email>dan@danandholly.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://techblogogy.net/wp-content/plugins/podpress/images/powered_by_podpress_large.jpg" />
		<image>
			<url>http://techblogogy.net/wp-content/plugins/podpress/images/powered_by_podpress.jpg</url>
			<title>techBLOGogy.net</title>
			<link>http://techblogogy.net</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>How-to: Securing your Social Networking Profiles</title>
		<link>http://techblogogy.net/index.php/2009/07/how-to-securing-your-social-networking-profiles/</link>
		<comments>http://techblogogy.net/index.php/2009/07/how-to-securing-your-social-networking-profiles/#comments</comments>
		<pubDate>Sun, 19 Jul 2009 21:08:09 +0000</pubDate>
		<dc:creator>Dan Thompson</dc:creator>
				<category><![CDATA[General Tech]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[Protecting Your Identity Online]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://techblogogy.net/index.php/2009/07/how-to-securing-your-social-networking-profiles/</guid>
		<description><![CDATA[Over the past couple months we’ve been doing a lot of talking about social networking / media sites and the potential security concerns they pose.  The one thing that’s been missing from all those discussions however is a “rubber meets the road” type of article actually showing how to make your online presence as tight as possible.  Well here it is...]]></description>
			<content:encoded><![CDATA[<p>&#160;&#160; Over the past couple months we’ve been talking a lot about social networking, social media, and their security concerns (click <a href="http://techblogogy.net/index.php/2009/06/managing-your-digital-id/"  target="_blank">here</a> for one such article).&#160; The thing that’s been missing this discussion is an article actually <em>showing</em> you how to make your online presence as tight as possible.&#160; Well, this is that article.</p>
<p><strong>To share or not to share… that is the question</strong></p>
<p>&#160;&#160; Let me just throw this out there: The safest and most secure social networking profile is the one that doesn’t exist.&#160; In a recent conversation I had with Martin Roesch, author of <a href="http://www.snort.org/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.snort.org');" target="_blank">Snort</a> and CTO of <a href="http://www.sourcefire.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.sourcefire.com');" target="_blank">Sourcefire</a>, he sad that “If you want to minimize your risks, then talking to anyone and sharing any information about yourself that has value is a bad idea but then, getting on a social network probably isn&#8217;t for you”.&#160; You’re probably reading this article because you’d like to continue enjoying social networking site, we’ll move right along.</p>
<p><strong>Passwords?&#160; NO, Pass<em>phrases!</em></strong></p>
<p><strong><em>&#160;&#160; </em></strong>I’ll spare you the greater passphrase lecture for later, but for now trust me that passphrases are more secure than passwords.&#160; Instead of something like “<strong>Br549!”</strong> as a password, use something like “<strong>I like my cat his name is Bill.</strong>”&#160; The idea is that by using a sentence the passphrase will inherently be longer, and thus harder to crack and harder to steal.&#160; It also makes it easier to remember, so you’ll be less likely to write it down.&#160; Here’s the problem though, only Facebook <em>really </em>supports them (good job guys).&#160; MySpace limits your password to a maximum of 10 characters (come on, really?) and Twitter won’t let you use spaces in your passphrase.&#160; So why have this conversation to begin with?&#160; Well, for now at least you can make your Facebook password REALLY secure.&#160; For the others, you’ll have to resort to good old fashioned complex passwords using upper and lower case letters, numbers, and special characters (Yeah, I know.. that’s a big giant fail whale).</p>
<p>To change your password in Facebook, hover over the <strong>Settings</strong> link in the upper right hand corner and choose <strong>Account Settings</strong>.&#160; From there click the <strong>Change</strong> link out from the <strong>Password</strong> heading</p>
<p><a href="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_13.png" ><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_thumb_13.png" width="366" height="68" /></a>Change your MySpace password by clicking the <strong>My Account</strong> button and choosing the <strong>Password </strong>link.&#160; You’ll need to enter your current password, the new password, and then type out the Captcha letters in the image it shows.</p>
<p>To change your password on Twitter, click the <strong>Settings</strong> link and choose the <strong>Password</strong> tab.&#160; You’ll again need to enter your current and new passwords. </p>
<p><strong>You’re how old again?</strong></p>
<p>&#160;&#160; In my mind, the next step to protecting your identity online is totally removing your birth date from your profiles.&#160; Publishing this information seems like a good idea because it lets your friends and family track your birthday better and it further identifies you to your friends. The problem is <em>it further identifies you to your friends</em>!&#160; If we think about it, our birthday is used quite frequently as a means to authenticate us.&#160; The last time you visited your doctor’s office they undoubtedly asked you your name and date of birth as soon as you walked through the door.&#160; In addition to this, researchers at Carnegie-Mellon University recently discovered that they could guess your social security number simply by knowing the town you were born in (another common piece of information we share about ourselves) and the date you were born (click <a href="http://redtape.msnbc.com/2009/07/theres-a-new-reason-to-worry-about-the-security-of-your-social-security-number-turns-out-theyre-easy-to-guess--a-gro.html#posts" onclick="javascript:pageTracker._trackPageview('/outbound/article/redtape.msnbc.com');" target="_blank">here</a> for the full article).&#160; You really don’t need further reasoning than that.&#160; Just get rid of it.&#160; </p>
<p>On Facebook, your birthday can be listed two different places.&#160; One is the information panel on the side</p>
<p><a href="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image.png" ><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_thumb.png" width="303" height="287" /></a>…and the other is on the info page of your profile, under <strong>Basic Information</strong>&#160;</p>
<p><a href="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_3.png" ><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_thumb_3.png" width="455" height="229" /></a>You can actually make it disappear from both places simply by clicking the <strong>Edit Information</strong> button on the <strong>Info</strong> page and then choosing <strong>Don’t show my birthday in my profile</strong> from the dropdown listing.</p>
<p><a href="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_4.png" ><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_thumb_4.png" width="418" height="222" /></a>While you’re at it, go ahead and change the birthday listed to something other than your real birthday.&#160; This may seem like a bit of overkill, however a recent Facebook hack which allowed people who weren’t your friends to view your personal info (click <a href="http://www.fbhive.com/private-facebook-info-accessible-with-a-simple-hack/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.fbhive.com');" target="_blank">here</a> for the full article) reminds us that it’s best just to not have that information listed at all (yes, you may be surprised to find out that I wasn’t really born on Independence Day).</p>
<p>On MySpace this same operation is done by clicking the triangle next to the profile listing and then choosing <strong>Edit Profile</strong>.</p>
<p><a href="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_5.png" ><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_thumb_5.png" width="240" height="244" /></a> </p>
<p>Once there, click the <strong>Basic Info</strong> and edit away (this is done the same way regardless of if you’re using the original profile tool or the new <em>Profile 2.0</em> setup).</p>
<p><a href="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_6.png" ><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_thumb_6.png" width="385" height="261" /></a></p>
<p>Both Facebook and MySpace require that you’re at least 13 years of age for your profiles to be publically searchable (parents take note; it’s a common practice for children to say they’re older than they really are so it’s easier for their friends to find them online… it also makes it easier for “you know who” to find them as well) so keep that in mind when you’re making up a new birthday.</p>
<p>Twitter doesn’t even ask you to provide this information.</p>
<p><strong>Yo Momma!</strong></p>
<p>&#160;&#160; Another feature of Facebook is the ability to list your family members.&#160; This is can be done by either using the <strong>Family Members</strong> section of your <strong>Basic Info</strong> page or through add-on apps like the <strong>Family Tree App</strong> (more on these apps in a second).</p>
<p><a href="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_7.png" ><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_thumb_7.png" width="368" height="65" /></a>As harmless as this may seem, it is a common practice for women to list their maiden name in their profiles.&#160; By associating your children with yourself and listing your maiden name, we’ve given away a critical security question answer commonly used by credit card companies and home security companies.&#160; You’ll note that more established online family tree websites, like <a href="http://www.ancestry.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.ancestry.com');" target="_blank">ancestry.com</a>, will hide all pertinent information about your relatives that are still living for this very reason.&#160; Again, just get rid of it!&#160; This is done by again editing your <strong>Info</strong> page and clicking “<strong>cancel relationship”</strong>.</p>
<p><a href="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_8.png" ><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_thumb_8.png" width="244" height="50" /></a>Even if your children are not old enough to own credit cards yet, I’d still recommend doing this.&#160; At this point it’s really hard to tell how long this information could possibly hang around (potentially forever), and at the end of the day it’s just not necessary for the social networking experience.&#160;&#160; </p>
<p><strong>Ummm… I’m sorry sir, but you’re not on the list.</strong></p>
<p>&#160;&#160; The next recommendation I’d make is that you consider making your profiles private.&#160; This is somewhat of a site culture thing, so I won’t harp on this one too much.&#160; The culture on Facebook is to have your profiles limited to only your friends.&#160; MySpace is kind of in the middle with some people protecting their profiles and some people not, and your age really almost defines which of those camps you fall into.&#160; Twitter on the other hand is arguably useless if you lock your profiles down, although I’ll add that with the influx of spam accounts people are slowly migrating in that direction.&#160; With this in mind I would offer that if you choose to leave your profiles open for public viewing, remember that <em><strong>your profile is open for public viewing!</strong> </em>Stating that you’re going to be out of town for the next two weeks probably isn’t the best idea (click <a href="http://www.abc15.com/content/news/southeastvalley/mesa/story/Home-burglarized-after-owner-twittered-he-was/Jq5LLx3ra0exDfw_pwFwOg.cspx" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.abc15.com');" target="_blank">here</a> for an article on man who found this out the hard way).&#160; It’s easy enough to use sites like <a href="http://www.anywho.com" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.anywho.com');" target="_blank">anywho.com</a> to combine your name and current city to come up with your street address.&#160; Oh, and saying that you hate your boss is probably not a good idea either.&#160; Employers are watching (click <a href="http://montanasnewsstation.com/Global/story.asp?S=10551414&amp;nav=menu227_3" onclick="javascript:pageTracker._trackPageview('/outbound/article/montanasnewsstation.com');" target="_blank">here</a> for the full article).&#160; </p>
<p>&#160;&#160; If your profile is currently public and you’d like to make it private, here’s how it’s done.&#160; In Facebook, hover over the <strong>Settings</strong> link in the upper right-hand corner and choose <strong>Privacy Settings</strong>.</p>
<p><a href="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_9.png" ><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_thumb_9.png" width="244" height="107" /></a>On the next page, click the <strong>Profile</strong> link and you’ll be taken to a page that allows you to edit who can see your <strong>Basic </strong>and<strong> Contact Information</strong>.&#160; On both of those pages, ensure that all are set to <strong>Only Friends</strong>.</p>
<p><a href="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_10.png" ><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_thumb_10.png" width="383" height="346" /></a></p>
<p>Facebook has recently announced that it will be adding more granularity to its security settings in the near future.&#160; This translates to potentially more confusion on how to keep your updates and posts private.&#160; Check back to this site for updated information as soon as the changes are made.</p>
<p>&#160;&#160; On MySpace this is accomplished by clicking the <strong>My Account </strong>button in the upper right hand corner and then clicking the <strong>Privacy </strong>link.&#160; If you’re using the original profile type you’ll select <strong>Only My Friends Can View My Profile</strong>, however if you’re using the new Profile 2.0, you’ll need to select that for each category listed.</p>
<p><a href="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_11.png" ><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_thumb_11.png" width="382" height="343" /></a>&#160;</p>
<p>&#160;&#160; On Twitter, click the <strong>Settings</strong> link in the upper right hand corner.&#160; Scroll to the bottom of the <strong>Account</strong> tab and you’ll notice a check box that says <strong>Protect My Updates</strong>.&#160; This will make your updates viewable only to those people who are following you, and will ask you to approve any new followers.</p>
<p><a href="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_12.png" ><img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_thumb_12.png" width="349" height="139" /></a> In addition to the note given about the fact that some of your previous updates could still be searchable, also take note that you’ll need to go through your current followers and block those that you don’t want to see your posts.&#160; </p>
<p><strong>It’s all about the apps man!</strong></p>
<p>&#160;&#160; The last thing I’ll mention is concerning Facebook apps.&#160; I can’t tell you how many times I’ve been invited to join Mafia Wars on Facebook, and quite simply I’m just not interested.&#160; What does this have to do with security?&#160; We just don’t know who wrote these applications, and they all want direct access to your personal information.&#160; To my knowledge nothing catastrophic has happened because of installed apps yet, but it seems to like an accident waiting to happen.&#160; My advice: ignore the requests and don’t install add-ons.&#160; If you’ve got a burning desire to install them, at the very least stick to the more widely known ones that have been around for a while.&#160; For good measure, look at your current list of installed applications and see if there are some you can get rid of.&#160; To accomplish this, click the <strong>Applications </strong>button in the bottom left hand corner of your Facebook page and choose <strong>Edit Applications</strong>.</p>
<p><a href="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_14.png" ><img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="image" border="0" alt="image" src="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_thumb_14.png" width="244" height="117" /></a>From the <strong>Show</strong> dropdown box, choose <strong>Authorized</strong></p>
<p><a href="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_15.png" ><img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="image" border="0" alt="image" src="http://techblogogy.net/wp-content/uploads/HowtoSecuringyourSocialNetworkingProfile_F0DC/image_thumb_15.png" width="267" height="148" /></a> This will now present you with a page that lists all the applications that are authorized in your profile.&#160; You may be surprised what you find.&#160; To remove an application from your profile, click the <strong>X </strong>out from the application.&#160; It will prompt you with a message asking if you’re sure, click <strong>Remove.</strong></p>
<p>&#160;&#160; So there you have it… at the very least a good start to protecting your identity while using social networking sites.&#160; The ultimate goal is that you at least <em>consider</em> what it is you’re sharing with the greater internet community… and hopefully think twice before telling the world <strong><em>everything</em></strong>.</p>
<p>Be careful out there guys! =)</p>
<p>&#8211; Dan Thompson</p>
]]></content:encoded>
			<wfw:commentRss>http://techblogogy.net/index.php/2009/07/how-to-securing-your-social-networking-profiles/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
