Facebook Adds Malicious Link Protection
wiredmikey writes "As any IT security department knows, social networks pose a significant threat to users across the board as they blindly click links which often lead to spam or other malicious sites that could result in malware infection. In a move to further protect users of the world's largest social networking site, Facebook is adding a new feature to help protect users from links to these malicious sites. Starting today, when a Facebook user clicks on a link it will be checked against a database from Websense in an attempt to determine if the link is malicious. If the link is determined to be risky, the user will be given the choice to continue at their own risk, return to the previous screen, or get more information on why it was flagged as suspicious."
Sure, it might be used for blocking malicious links now.. but what about when competing social networks, like Diaspora, emerge? Looking at Facebook's history I'm sure they will use it to block users moving to Diaspora and reading about Diaspora. It will be used as an opinion suppression tool.
Does facebook.com come up as malicious?
Ignoring potential future abuses, wouldn't it make more sense to disallow the posting of likely-malicious links? The vast majority of users won't read the warning text and will just click through.
That is all.
help me fix this "Terrible" karma, please!
Correct URL: http://www.securityweek.com/facebook-adds-malicious-link-protection-powered-websense
I've yet to have a relative's computer contract a virus because of a Facebook link, but it seems that every other day they've got some Facebook app spamming everyone on their friends list because of the promise of free online poker or whatever. When does Facebook intend to do something about that? Ever?
No kidding!!! What do you say at this point?
Guys, come on!
In all seriousness, this'll be helpful for home users much more than it will in the office. I'm just surprised they've taken this long to do it; they've MITM'd every link for at least a year and a half.
Viable Slashdot alternatives: https://pipedot.org/ and http://soylentnews.org/
Let me guess... Google+ is listed as a malicious website.
"That's the way to do it" - Punch
Will they use the same list of domains as MSN do and block my entire website because someone has used my ddns provider to serve malware?
The more you protect users from their stupidity the stupider they get anyway. Not only that but the malware peddlers have to get cleverer and their techniques get more advanced so they catch the non-morons as well grr.
Facebook and their omnipresent Like buttons is the largest source of intrusive monitoring on the web. I highly recommend the antisocial subscription for adblock, it's not only reduced the amount of information leaking to google and facebook but it's also improved average page load times by about 40-50% (guestimation).
There are 4 boxes to use in the defense of liberty: soap, ballot, jury, ammo. Use in that order. Starting now.
you wouldn't want to accidentally click through to the wild internet, now would you. I wouldn't trust any page that didn't have a Like button to run FaceBook's protective scripts. It also would add a measure of security to know that if any page did anything really bad, FaceBook could pull the plug on them, by cutting off the user traffic it was sending their way via links. I like where the Internet is going...
You could put up 10 warning screens like that and people will still go "BUT I WANNA SEE THE CUTE THING MY FRIEND SAW"
As any IT security department knows
127.0.0.2 www.facebook.com
That should do it.
Am I the only one that think it is a little fishy that they are not checking the links when they are published, but only when user are clicking on them. So instead of doing one check per link they think it is better to do million checks... or this is just another excuse to track which user are clicking which links... but I guess that is just me being paranoid.
Is that protection from malicious links or protection of malicious links? With Facebook it is hard to tell.
I genuinely read it in the second sense the first time I saw the headline.
This has been occurring on the mobile version app for at least a week now, and it doesn't check.. every damn link you hit does the "this is an external site.. do you want to continue" crap. Its annoying. *IF* it only did it with suspect links like Google does with its search results or chrome does when it detects something, that'd be ok... but its done it for every damn link so far.
Not to mention I can't stand websenses listings (old employer used them and stuff was incorrectly classified all the time)
So Facebooks goal is to secretly collect data on you, then sell that data to whomever will pay the most, often criminals and totalitarian governments, and they are now offering protection against links that may lead to sites that do the very same thing? Thanks Facebook!
This sounds a lot like the 'Safe Browsing' feature already built into Chrome. It provides a warning screen on a suspicious page, and then allows the user to continue, or to go back.
As long as there is an opt-out setting, I really don't see what the big deal is. Am I missing something?
No man is an island, But if you take a bunch of dead guys and tie them together, they make a pretty good raft.
Why don't you just get DDNS through the same company through which you bought your domain?
Since social networking sites pose a significant security risk, facebook will of course block other social networking sites.
For your safety.
This is actually an issue they should have addressed a long time ago. Lots of people have their accounts hijacked and then they start sending out malicious links. And the bots are getting better at faking normal people.
I like saying "Boo Facebook" as much as anyone, but they need to do this. I don't believe this particular initiative is meant for political censorship. They already have those capabilities. I think the only thing they really gain from this partnering is the ability to block malicious links sent from hijacked accounts.
Democracy Now! - your daily, uncensored, corporate-free
This is in response to multiple CSRF vulnerabilities I posted to their white hate research group, took a month or two to implement, and guess what... I never saw or heard any whiff of my $500...
They
It is to add Malicous Link protection, which is the issue you are discussing.
Democracy Now! - your daily, uncensored, corporate-free
For decades now, via a custom HOSTS file here, that @ this point's 1,586,590++ entries strong here via a Python system (multiplatform which is why I switched to it from a Borland Delphi system mostly) which deduplicates, alphabetically sorts, & periodically refreshes + updates the MAIN hosts file from a temp. 'scratch copy', every 15 minutes vs. known malicious sites/servers, vs.:
1.) KNOWN malicious sites/servers/hosts-domain names
2.) Bogus adbanners
3.) Adbanners in general (which slow you down & rob you of bandwidth + speed YOU PAY FOR OUT-OF-POCKET)
4.) Botnet C&C servers
* & more... gaining you not only added "layered-security/defense-in-depth", but, also speed!
And, even more speed than above in blocking out adbanners alone, but also even MORE SPEED, by "hardcoding" your fav. sites into it, so they resolve LOCALLY off of harddisk read speeds (far faster than calling out to a DNS roundtrip = approx. 70ns or more) of sub-11ns typically (faster off SSD as I do it too no less, nearly no seek/access time is how/why)!
(Instead of via a potentially redirected or downed DNS server (plenty of problems there for years now that way etc.))....
For security? That's for host-domain driven malware (which most are, because they can "recycle" domain names they buy, & they do that)...
Firewalls' rules tables work for IP address based ones (and host-domain type too) for layered security.
APK
P.S.=> Because what you can't touch? Can't hurt you... period! Simplest principle in the world... &, as you can see plainly from this article?? Even the "big league" IT Pros & big shops are "into it" as well, albeit slightly diff. means, idea's the same...
... apk
This is likely in part to multiple CSRF vulnerabilities I submitted a month or two ago, and I never saw or heard anything about $500...
Should I acquire a lawyer or is there anyone willing to stick up for a little guy that they trampled on?
They are getting Security Consultants to work for FREE by saying vulnerabilities are worth $500, but obviously this is BS.
It's a free sub domain. And as such is entirely useless because once one person has used one to peddle malware everyone else is blacklisted forever after the provider has kicked the abusive users.
Yes I know, can't complain, get what you pay for etc. I'm still pissed off by it.
Just for a second I thought they were protecting the links not protecting the user from clicking on the link. I have to remember to always read though the article.
Paul: Father... father, the sleeper has awakened! - Dune
is the service they use for similar features for security online!
I supplement BOTH of those browsers "built-in features for security" (Opera also has a urlfilter.ini/filter.ini file for this locally also) with HOSTS files (vs. host-domain name based threats, which can & DO get "recycled" by malware makers), + firewall rules tables (for IP address based known online threats (these don't last that long usually & cannot be recycled/reused by malware makers as easily)).
* I do this, for BOTH better online "layered-security"/"defense-in-depth", but, also for more online speed (details in link below from another post I did here today)...
APK
P.S.=> It just works -> http://yro.slashdot.org/comments.pl?sid=2457274&cid=37589432 &, on the SIMPLEST PRINCIPLE OF ALL (i.e. of -> "You can't get burned if you don't go into the malware makers' kitchen", more-or-less)...
... apk
Of course this tells them which links you click on. And if Chrome does this, too, then google is not only aware of your searches but also the links you click on outside their domain.
Neat.
for five minutes. After that, the malware writers will identify the Facebook servers and show them a different page.
One of our competitors trademarked the term "hypothesis". From now on, we will call them "boneheaded ideas".
then you have much bigger problems than Facebook.
@ least, via its "TPL's" (tracking-protection-lists), here (free too):
http://ie.microsoft.com/testdrive/Browser/TrackingProtectionLists/
APK
YES! Mod this up to +5. I came here to say this very thing.
If merely visiting a link in your browser can do jack shit to infect your machine, your machine is DEFECTIVE and it should not be used to connect to the internet.
It is bewildering that no, in 2011-almost-2012, people STILL refuse to learn.
http://europe-v-facebook.org/EN/en.html
Hurry before Facebook blocks it.
Try sending yourself a piratebay link on Facebook messages....you'll find its blocked.
Oh Facebook
Mainly these 3 (which integrate into your IP stacks' settings & hardware router/firewalls too) - Each has a writeup on how/why/when/where they work too:
---
Norton DNS:
https://dns.norton.com/dnsweb/faq.do
OpenDNS:
https://store.opendns.com/get/basic
ScrubIT DNS:
http://www.scrubit.com/index.cfm?page=faq
---
* EACH does a heck of a job supplementing online security (in addition to my custom HOSTS file + Firewall rules tables I noted in my prior post I am replying to now)...
APK
P.S.=> It's ALL about "layered-security/defense-in-depth" first of all, but the nicest part? Well... THAT, is the added SPEED this layered security setup of mine yields (in addition to hardening the TCP/IP stack vs. attack, mostly via this -> http://msdn.microsoft.com/en-us/library/ff648853.aspx )...
... apk
DON'T USE FACEBOOK
Anons need not reply. Questions end with a question mark.
Quote from article: "Starting today, when a Facebook user clicks on a link it will be checked against the Websense database in an attempt to determine if the link is malicious."
So... Do the malicious links people post always end up in the WebSense malDB before anyone views them?
Or... Does the hosting provider of said malicious link take the "site" down first?
All I read is another FUD-calming act. Read: "Look what we've done to make our site better for you to belong to today!"
What responsible IT department even allows outbound connections to Facebook? Facebook's done. Put a fork in it already.
It's not so much the sites you KNOW are done well/as secured as can be in code/db engines etc. (plus OS + Serverware patch levels. et al), but... It's ALSO the possibilities, of this occurring:
---
Ad networks owned by Google, Microsoft serve malware:
http://www.theregister.co.uk/2010/12/13/doubleclick_msn_malware_attacks/
---
Attacks Targeting Classified Ad Sites Surge:
http://it.slashdot.org/story/11/02/02/1433210/Attacks-Targeting-Classified-Ad-Sites-Surge
---
Hackers Respond To Help Wanted Ads With Malware:
http://it.slashdot.org/story/11/01/20/0228258/Hackers-Respond-To-Help-Wanted-Ads-With-Malware
---
Hackers Use Banner Ads on Major Sites to Hijack Your PC:
http://www.wired.com/techbiz/media/news/2007/11/doubleclick
---
Ruskie gang hijacks Microsoft network to push penis pills:
http://www.theregister.co.uk/2010/10/12/microsoft_ips_hijacked/
---
Major ISPs Injecting Ads, Vulnerabilities Into Web:
http://it.slashdot.org/it/08/04/19/2148215.shtml
---
Two Major Ad Networks Found Serving Malware:
http://tech.slashdot.org/story/10/12/13/0128249/Two-Major-Ad-Networks-Found-Serving-Malware
---
THE NEXT AD YOU CLICK MAY BE A VIRUS:
http://it.slashdot.org/story/09/06/15/2056219/The-Next-Ad-You-Click-May-Be-a-Virus
---
NY TIMES INFECTED WITH MALWARE ADBANNER:
http://news.slashdot.org/article.pl?sid=09/09/13/2346229
---
MICROSOFT HIT BY MALWARES IN ADBANNERS:
http://apcmag.com/microsoft_apologises_for_serving_malware.htm
---
ISP's INJECTING ADS AND ERRORS INTO THE WEB: -> http://it.slashdot.org/it/08/04/19/2148215.shtml
---
ADOBE FLASH ADS INJECTING MALWARE INTO THE NET: http://it.slashdot.org/article.pl?sid=08/08/20/0029220&from=rss
---
London Stock Exchange Web Site Serving Malware:
http://www.securityweek.com/london-stock-exchange-web-site-serving-malware
---
Spotify splattered with malware-tainted ads:
http://www.theregister.co.uk/2011/03/25/spotify_malvertisement_attack/
---
* As my list "multiple evidences thereof" as to adbanners & viruses + the fact they slow you down & cost you more (from reputable & reliable sources no less)).
APK
P.S.=> Now, "top that off" with the possibility of "DNS-Poisoned" (redirected really) DNS Servers too? It goes up yet again, as to "absolutely trusting" sites you're actually seeing (& disabling javascript GLOBALLY but only using it where you absolutely NEED it (think 'e-commerce' type sites for example), & only enabling it for TRUSTED favs. & yes, there's way to check OS patch & WebServerWare OS patch levels online (or in Opera's dev
Don't use it. Facebook is under no obligation to allow their infrastructure to be used to promote competitors. Can't believe the amount of whining on this thread.. jesus..
So Facebook is going to block links to sites that are full of spam, or attempt to take all of your personal information in order to make money from it...
So, as best I can tell, Facebook has deemed Facebook.com to be a malicious link...
"As any IT security department knows, social networks pose a significant threat to users across the board as they blindly click links which often lead to spam or other malicious sites that could result in malware infection"
..
Correction: social networks pose a significant threat to Microsoft Windows users
I have met the enemy, and the enemy is APK. Alexander Peter "Petey" Kowalski.
For grins, visit the Onondaga County Dept. of Finance Office of Real Property Services, click "Click Here for Public Access", and search for Tax ID # "009.-13-12.0". Be sure to check "Owner/Sales" while you're there.
Nope, you just fail at following simple instructions. You can't even get that right. Or maybe you don't know the meaning of the word "prior".
Is that against the law?? I don't owe on it (paid in full), & taxes are paid up in full currently - we should ALL be such "enemies", lol... I mean, lol: IF THAT is being an "enemy" on my part, then, We all ought to be "the enemy" as you called me, lol, for Pete's sake! I mean - what exactly is YOUR idea of being "good"?? Not paying taxes???
* I wonder - can YOU say the same as I did above, in that you own your own place paid in full and taxes are up to date as well???
(For some reason, I doubt it... )
APK
P.S.=> Man, you are one hell of an online psycho-stalker freak, lol, looking into that to try to "discredit me", & all you ended up doing was making me look like what I am: An upright tax paying citizen... thanks!
... apk
I'll quote it for you again, so you can answer it (& PROVE IT too):
"* I wonder - can YOU say the same as I did above, in that you own your own place paid in full and taxes are up to date as well??? (For some reason, I doubt it... )" - by Anonymous Coward on Tuesday October 04, @01:55PM (#37601646)
Well? How about answering what I quoted above?? We KNOW the answer already (NO)... lol!
APK
P.S.=> Plus, in the end? You should thank the merciful Lord guys like me are around paying taxes, so you can get your welfare check @ least, lol...
... apk
I have a large penis.
Why's that -> http://yro.slashdot.org/comments.pl?sid=2457274&cid=37602672 ?? LMAO!
APK
P.S.=> Also, I must THANK YOU (again) for making me out to look good as per your off topic ac trolling usual, & in that YOU PROVE I AM A GOOD UPSTANDING TAX PAYING CITIZEN (which judging on how you avoid questions I put to you? Clearly I am QUITE unlike a welfare case like yourself, obviously)... apk
I admit I have a tiny penis and I made apk look good by proving apk pays taxes on time and owns properties. I am on welfare and I stalk apk online with anonymous coward posts on slashdot that really show I am a zero. That's why I troll and stalk apk and because he also has blown me away and humiliated me everytime I have tried it on technical issues in computing too. I just can't get over my obsession and geek angst. I have clear issues.
Hey guys, just want to let you know that the Link Protection is easily broken. So much for protection, eh?
Part # 1 of ? -> http://yro.slashdot.org/comments.pl?sid=2457274&cid=37610930 and we find it funny how you project your own weaknesses of being overweight onto others, as well as how you avoided simple questions (proving you're a penniless "ne'er-do-well" (do you like, stalk apk or something? You claim to "know him so well", & that is only possible if you stalk him as you are clearly doing now, illogical adhominem attacks & all). Too bad your puny plays always backfire on you eh, ac stalker-troll?
Mr. penniless "ne'er-do-well" -> http://yro.slashdot.org/comments.pl?sid=2457274&cid=37602672 ?
Don't we, here -> http://yro.slashdot.org/comments.pl?sid=2457274&cid=37602672 , By now all reading certainly do (answer = you don't own your own home and yet you have the nerve to attempt to give guff to those that do, and who keep their taxes paid, just so you can be on welfare, right?)
Typical APK... fat slob living on welfare in his $1 house talking about ME living on welfare. Projecting much? Just so happens that I don't. And not only do I pay property taxes on the house that I DO own (FULLY - I owe nothing on it), I also pay INCOME taxes. You know... the sort of taxes that people with actual JOBS pay.
So you pay your property tax... good for you, do you want a cookie? Whoops, better make that a sugar-free cookie, fatso.
Oh, and quit posting links to stuff that's been posted in this same thread. Some of us have attention spans better than your average brain-damaged fruit fly.
http://yro.slashdot.org/comments.pl?sid=2457274&cid=37602672
(We KNOW why, lol... you talk real big, but when it comes down to proof of your actual home ownership and it being paid in full along with its taxes too, you run away. Why's that?)
LMAO! It's because you have those things and proof of them, like you have this allegedly "million dollar insecurity" of yours you just spoke of (we don't have our microscopes ready for that, so, you're outta luck, lol...).
Has anybody had any experience on getting the alerts removed after a site has been cleaned of the malware?