350 likes | 468 Views
Securing Your Facebook Identity. Nicholas A. Davis, CISA, CISSP UW-Madison Division of Information Technology. !!Advisory!!.
E N D
Securing Your Facebook Identity Nicholas A. Davis, CISA, CISSP UW-Madison Division of Information Technology UNIVERSITY OF WISCONSIN
!!Advisory!! The content of today’s presentation is designed to help people protect themselves on Facebook. This is NOT a session on Facebook hacking. If hacking Facebook is your motivation for attending today’s session, please leave now UNIVERSITY OF WISCONSIN
Overview Basic rules of Facebook security Unique situation on UW-Madison campus (academic research poses a unique Facebook chalenge) Why unauthenticated identity means “be careful” The dangers of Facebook photos Application settings and security preferences Facebook passwords Time and place concerns Roaming security Account cleanup and maintenance Tips and tricks Q&A session UNIVERSITY OF WISCONSIN
Basic Rules of Security Think before you post Customize your privacy settings Don’t accept friend requests from people you do not know Keep sensitive information private Remember, being on Facebook means that you are living like a rock star! (kind of) UNIVERSITY OF WISCONSIN
Research Lab Example UNIVERSITY OF WISCONSIN
Meet Flat Cow We will be using Flat Cow, known to his friends as FC, in a few slides UNIVERSITY OF WISCONSIN
Wait, Cows Can’t Be On FB!Unauthenticated Identity UNIVERSITY OF WISCONSIN
Organize Friends In Lists UNIVERSITY OF WISCONSIN
Photos Tell Stories(Not Always Safe Ones) UNIVERSITY OF WISCONSIN
Photos Tell Stories(Not Always Flattering Ones) UNIVERSITY OF WISCONSIN
Keep In Mind Don’t get yourself into a situation in which such pictures can be taken You have little to no control over who takes your picture in public Think about the stories your photos tell about you Exercise control over pictures of you tagged by others UNIVERSITY OF WISCONSIN
Automatic UpdatesTake Control! UNIVERSITY OF WISCONSIN
Don’t Advertise Yourself UNIVERSITY OF WISCONSIN
You Can’t Control Your FriendsBut You Can Control Their Applications UNIVERSITY OF WISCONSIN
Don’t Let Your App Excitement Obscure Your Judgement UNIVERSITY OF WISCONSIN
Keep The Stalkers At BayChange Search Visibility UNIVERSITY OF WISCONSIN
Get Your Facebook ProfileOut of Google UNIVERSITY OF WISCONSIN
Tips To Keep You Safe On Facebook Change your Facebook password often UNIVERSITY OF WISCONSIN
Facebook Is a Prime Target For Password Hackers Never use the same password for Facebook as you use for your bank access UNIVERSITY OF WISCONSIN
Examine Photos Before You Post Avoid posting photos with identifying information, such as addresses, license plates, etc. UNIVERSITY OF WISCONSIN
Don’t Advertise Your Absence Post vacation pictures AFTER you get home UNIVERSITY OF WISCONSIN
Browse Facebook Securely When at Starbucks (HTTPS) UNIVERSITY OF WISCONSIN
Remove Facebook Apps Which You Do Not Use UNIVERSITY OF WISCONSIN
Use Privacy Settings To Block People UNIVERSITY OF WISCONSIN
Check the Facebook URL Often UNIVERSITY OF WISCONSIN
Know The Difference Between Deactivating and Deleting Your Facebook Account Deactivating your account leaves all posts and pictures intact Deletion is supposed to remove everything Don’t login after you request deletion UNIVERSITY OF WISCONSIN
The Facebook Doppelganger Spy“But Flat Cow is already my friend” UNIVERSITY OF WISCONSIN
Three Strikes and You’re Out!Don’t Be a Friend Pig UNIVERSITY OF WISCONSIN
How Liking Things CouldTake Advantage of You UNIVERSITY OF WISCONSIN
Facebook SecurityBest Practices http://www.sophos.com/en-us/security-news-trends/best-practices/facebook.aspx UNIVERSITY OF WISCONSIN
Carnival Cruise ScamJust One Example Message purporting to be from "Carnival Cruise" claims that Facebook users can win an all-expenses-paid vacation package by liking and sharing a promotional image and clicking a link to apply for the free tickets. http://www.hoax-slayer.com/facebook-related.html UNIVERSITY OF WISCONSIN
Enable Login Notifications Login notifications are an extra security feature. When you turn on login notifications, we'll send you an alert each time someone logs into your account from a new place. UNIVERSITY OF WISCONSIN
A Note About UW NetID Your NetID is like your toothbrush, only you should use it UW-Madison will NEVER ask for your NetID and/or password via email Report any such requests to abuse@wisc.edu UNIVERSITY OF WISCONSIN
Q&A Session Nicholas Davis ndavis1@wisc.edu facebook.com/nicholas.a.davis UNIVERSITY OF WISCONSIN