Welcome to the new Facebook

The Facebook Blog

Displaying all posts by Ryan McGeehan
We've often written about our commitment to keeping Facebook a safe place for you to interact and share information with your friends. We work hard to keep the site free of abuse, spam, and harassment. A recent place where we've been fighting the spam battle has been through sites that ask for a user's login information to use a contact importer, and then spam all of their friends. Our response seems to have confused some people as to why certain content can't be sent through our systems. For example, if you try to send a message that contains a link to a website with an importer, you might get a message like this:
[image]

This response is our way of trying to protect everyone's privacy. Right now, the sites that are asking for this information, and that we are blocking as a result, gain complete access and control over your account when you enter your login info—your photos, your private messages, and your friends. In order to protect sensitive data, we make it hard for spam to spread through Facebook.

We know that there are legitimate places where it would be useful to have your Facebook Friend List with you, which is why we've been working so hard on Facebook Connect. Our goal there is to allow you to bring any information you want over to any service you want, while still maintaining all of our privacy standards across the web. That way, you will have control over your information—not anyone else.

Ryan works on the site security team and continues to be a dodge ball ninja.
We take spam prevention seriously here at Facebook, but unfortunately, there is spam on the site. As an example, you may have seen Wall posts advertising free ringtones among other spam, as well as a more malicious form of spam called "Phishing". These two trends are related, and here's why:

Phishing is a method to trick Internet users into visiting fraudulent websites. Phishing websites are designed to look like the login page of popular websites. Because they look real, people log in, accidentally giving criminals access to user accounts. These can then send spam messages to perpetuate the phishing websites and promote services or products. When a phished account is used by a spammer, more Wall posts that are spam or links to phishing sites are sent out, and the cycle continues.

Wall posts that result from this will look out of place; they either advertise products or ask to log you in to Facebook from another site when clicked. If either case is true, keep in mind that it might be spam or a phishing attempt. We wanted to spend some time giving you tips to help you protect your own account, as well as your friends' accounts.
Remember, Facebook will never ask for your password in an email, Facebook message, or any medium that isn't the login page. Though you will need to re-enter your password when you set a security question, change your contact email, or send a virtual gift. Be extra aware of weird Wall posts. Don't click on any links—on a Wall or elsewhere—if you don't know where they go. Set a security question for yourself on your Account page. If somehow something malicious shuts you out of your account, you will need the answer to that question in order for our User Operations team to let you back in. (If you've already set your security question, you won't see a prompt for it on your Account page.) Be extra aware of what website you are using to log in to Facebook (and other websites). Phishing websites can be made to look like other websites (like the Facebook log in page), and might try to disguise their urls. Be smart: www.facebook.com.profile.a36h8su2m8.info/login starts out looking like a legitimate Facebook website, but that a36h8su2m8.info part means it's fraudulent. Set and use a browser bookmark to make sure you always log in from facebook.com If you see a Wall post that looks like spam on a friend's Wall, tell the author to delete it and reset their password immediately. Use a modern web browser to benefit from anti-phishing protection Check out opendns.com. This is another method for blocking specific domains that host phishing sites.

If you think you've been phished or find a phishing site,
Reset your password on your Account page. Report the issue to Facebook here. Submit phishing sites here and here.


Phishing is nothing new, so on our end, we're hard at work developing solutions to make Facebook more resilient to phishing. You may see more changes to Facebook designed to protect your privacy against phishing attacks in the future. If there's anything left unanswered, check out our Security Center.

Ryan works on the site security team and is a dodgeball ninja.


You are viewing a mobilized version of this site...
View original page here

Mobilized by Mowser Mowser