Facebook’s Faceless Apps

By | November 22, 2011

image

We’re probably being too kind to Facebook, and, in particular, to the third party applications that plug into it. They’re abusing user trust and committing sins we castigate others for, so we should be consistent: Many Facebook applications are spam.

Take this one, for example, illustrated above. It’s called ATTACK! and upon accepting an invitation from someone the screenshot above (reduced for privacy reasons) is the first page you see. You’re encouraged to invite friends:

image

To make it easier for you, the first 10 friends on your alphabetical list have already been selected (what it must be like to be called something like Adam), and the only button available is the big blue one that says:

image

There are, as far as I can see, no alternative buttons. No options to just skip the inviting part, or to unselect the existing friends, meaning you’ve got to unselect the ten manually. If you do that and then click the blue button you get another message:

image

And the ten are selected again. Hang on a minute; wasn’t I invited by someone else to play this game? (Laying aside, for a moment, why I would be playing a game during work hours of dubious intellectual or work-related relevance.) Why can’t I just accept his invitation and start playing?

By now I’ve forgotten who invited me and the invitation has disappeared. So has my enthusiasm for playing the game. Or having anything to do with Facebook applications.

To be fair, quite a few friends seem to love these things. What troubles me is that if these applications are so cavalier with well-established norms of non-spamming etiquette, how cavalier are they with our personal data? Remember every third party application requires the user to select this box:

image

without ever going into detail about which information. All my information? Just a bit of information? Facebook has a lot of my information — not as much information as it used to, because I deleted a lot of it in a moment of panic (beware if you remove the fact that you’re married from your personal information, as you’ll get messages from people as they see in their status feed a broken heart icon and the words “Jeremy Wagstaff is no longer married” broadcast to all your friends. It is, however, a good way to find out what people really think of your marriage.)

So who is behind ATTACK!? Who are we giving that information to? Well, it seems to belong to a company called Presidio Media LLC. I say “seems” because there is no link to a company web page; the copyright sign includes that company’s name, which also seems to be responsible for games of Poker, Blackjack and Lotto. The company website, however, is empty, and I can’t find any registration information. There are three email addresses on the Facebook page, suggesting from their email addresses that they’re behind tribe.net, a social networking site.

Given Facebook has enjoyed huge popularity with what I would call social networking virgins — those who have not previously explored this online wonderworld of sharing information — I am, like some party pooper, troubled by the implications, even as we all frolic in this newfound social whirl.

But it’s probably just me. Anyway, whoever invited me to play ATTACK!: sorry. Let’s do it offline in the pub.

Technorati Tags: , ,

Software That Plays Tag

By | November 22, 2011

This week’s WSJ.com column (subscription only, I’m afraid) is about Jiglu, a sort of automatic tagging service you can see in action somewhere on this blog:

If you’re a writer, you hope your words will be etched in stone for eternity. If you’re a blogger, you’re happy if someone stumbles on your writings a few days after you posted them. Blogs, partly because they often consist mainly of commentary on things that have just happened, and partly because of the way they are structured (most recent postings first, making it easy to ignore everything you wrote before), are a transient medium. Rarely is a blog post treated as permanent. We write, then we forget.

The problem, I conclude, is that amidst all the writing, and despite the power of tagging

Blog posts, left to themselves, tend to have a short shelf life.

Briton Nigel Cannings thinks he has the solution to this: automatic tagging. He sees value in all those old blog posts of mine (he may be the only one) and reckons all that old content out there is a repository of wisdom that just needs to be sorted out better. Tagging it ourselves, he thinks, just isn’t enough because we don’t always see what we’ve written in a broader context. “Manual tagging is the first step” to sorting and storing blogs and other online content better, he says, “but it still relies upon people understanding themselves, whatever they’ve already written about, and how their content fits in with other people’s content.”

More at Loose Wire – WSJ.com.

Technorati Tags: , ,

FriendsReunited, At a Price

By | November 22, 2011

 image

Before Facebook, we had to find our friends on FriendsReunited, a very successful UK site that achieved critical mass but had one flaw: users had to pay to communicate with each other. It only struck me now that there’s something a little unethical about that.

Take, for example, what just happened to me: someone I haven’t seen or heard from in more than 35 years just got in touch via Friends Reunited (one advantage of the site is you can list the schools you attended right down to primary level).

Needless to say, it’s great to hear from him and I’d love to reply, but now I balk at the £7.50 ($15) I have to pay to do so. FriendsReunited lets you list your details there, but controls the communications between you, a little like LinkedIn.

But whereas with LinkedIn the communications are not controlled in a way that leaves the other person hanging; this old school chum now has no idea whether

  • I’ve received the message
  • I have any interest in communicating with him

unless I cough up the $15.

Of course, you could argue there’s no price on getting in touch with old friends. To which I would say, why should a company tell me what that price is? Now my old school chum is hanging there, uncertain whether I want to get back in touch.

Needless to say, I’ve tried to find out an email address or contact number through other channels, and maybe I’ll get lucky. So far nothing; FriendsReunited, like Facebook, both helped to extend the social networking model beyond the normal early adopter range, so not everyone on it has a big web footprint outside those walled gardens.

But if Facebook has changed nothing else, I suspect it’s altered our perception of community websites: from now on we expect to be able to find and connect with old friends on them, and if we have to pay to do that our interest wanes. Have to pay to contact a friend? Isn’t that a bit Web 1.0?

PS: Simon, if you’re out there, email me 🙂

FriendsReunited

Hi, I’m Sheila from Phishers ‘R’ Us

By | November 22, 2011

It amuses me that banks talk about security but rarely apply it in a consistent enough way to save people like you and me from getting scammed. Take what just happened to me this morning:

My bank rings me up (the number is a private number so doesn’t show up on my screen, but that doesn’t seem to be unusual anymore; nearly half of the people who call me seem to withhold their number these days. In any case, it’s not hard to fake a callerID.)

The woman on the phone tells me there’s been a problem with my last phonebanking transaction. Before she can tell me more, she asks me to key in my six-digit phonebanking ID, she says. I’m just about to do so, eager to sort out the problem, when I realize that I’ve not confirmed that she is who she says she is. So I ask her:

“Sorry, but I need to confirm who you are first.”

“Yes, I am Sheila and I work for the phonebanking division.”

“Yes, but how do I know you’re Sheila from the phonebanking division, and not Sheila from Phishers ‘R’ Us?”

Clearly Sheila hasn’t faced this kind of situation before.

“Er, well, if you key in your phonebanking ID, I can tell you details about your account, and that will confirm it.”

“Well, it may do, or else it would tell me you’d already succeeding in hacking into my account and were now just toying with me.”

A pause.

“Yes, but the PIN number goes straight into the computer,” says Sheila, a bit nonplussed now.

I try to explain that a) I’m not personally accusing her of being a scammer, only that I have no way of confirming whether she is a bank employee or a clever social engineering fraudster because she called me first and b) that technology makes it eminently possible that someone could capture my six digit PIN if I key into my phone. (A simple decoder attached to the phone will grab the DTMF signals (the beeps when you press a key) and figure out what digits they represent. I didn’t tell this to Sheila because she was already beginning to sense I was a ‘difficult customer.’)

In the end I tell Sheila I’m going to call her back, to which she politely agrees. When I later explain to her that the bank should think about plugging the hole in their security fence, she listens politely, thanks me for my feedback, and says:

“One last thing, Mr. Wagstaff. I don’t know if you’ve been told but we’re running a promotion at the moment that for every customer you’re able to bring in you get a $200 gift voucher for redemption at Takashimaya Department Store.”

A bank with its priorities right, it seems.

What amazes me about this is that banks don’t seem to have learned from past mistakes. A few months back I wrote about a scam in Hong Kong which uses exactly this tactic. Fraudsters stole wallets and handbags at a sporting event, removing only the ATM and business cards. The victims then got phone calls the next day pretending they’re from the bank informing them they’ve lost their card, and asking them to approve cancellation of the card by keying in their PIN number.  Voila. If Sheila was Sheila the Scammer, someone would be at least half way into my account by now.

I wish banks would be smarter about this. I wish in particular the banks I use would be smarter about this. Scammers are clever, particular about social engineering — the art of lulling people into a sense of false security. We ordinary people want to please, and we want to help solve a problem, especially if it’s connected to us, so we’re easy prey for someone at the end of the phone offering both.

The lesson is the same as the one I’m always trying to pass on: Don’t give anything to anyone just because they ask you to. Find out first whether they are who they say they are. A realtor asking for a deposit? Show me the documents that prove you are authorized by the landlord. Here to check the meter? Where’s your badge? Valet? How do I know you’re not just a guy in a red jacket and jaunty hat about to steal my car?

Authenticate, authenticate, authenticate. And if it’s someone like a banker, a real estate agent or an official, be hard on them if they seem impatient with your efforts. It’s your money, not theirs.