A friend recently had this experience. In a game on a popular social networking site, one of the goals is to obtain a progressively larger network of friends to move effectively play the game. In this case, I'm talking about Mafia Wars on FaceBook. A common practice is to randomly add people in groups dedicated to increasing group size and after linking up, "defriend" them. The game does not require you to remain friends for purposes of increasing your group size.
A spurned "friend" used the unfortunately visible personal information to engage in a simple identity theft. Where it gets ugly is Yahoo! They allow a person to recover their account by date of birth and postal code. If you are on FaceBook, look through your contacts and see how many have that information exposed. My friend recovered his account and changed the password but Yahoo!, in their infinite wisdom, allows you to recover your account forever once you know birthdate and postal code as those two items are immutable. Once your Yahoo! account is compromised by that vector, it's game over. There is no way to make the account safe again. The best you can do is shut it down and create a new account. That was their advice to my friend.
I've urged my friend to report the activity to FB as well as the Police Department of the assumed cracker's hometown. A wonderful double edged sword these social networking sites---the gentleman exposed enough information about himself to allow me to track down his age, city, high school (surprise) and his activities (6 mph runner) but as I have no desire to expose myself to legal issues, I won't join this troll in the gutters. I would like to call his parents though, that'd be delicious.
A blog about SQL Server, SSIS, C# and whatever else I happen to dealing with in my professional life.
Subscribe to:
Post Comments (Atom)
Blog Archive
-
►
2010
(53)
-
►
August
(9)
- Unclosed quotation mark after the character string...
- SQL Saturday 53 Birds of a Feather luncheon
- SQL Server 2005/2008 what's new, part 7
- SQL Server 2005/2008 what's new, part 6
- SQL Server 2005/2008 what's new, part 5
- SQL Server 2005/2008 what's new, part 4
- SQL Server 2005/2008 what's new, part 3
- SQL Server 2005/2008 what's new part 2
- SQL Server 2005/2008 what's new, part 1
-
►
August
(9)
Labels
#TSQL2sDay
(2)
.NET
(1)
ADO.NET provider
(1)
asp.net
(1)
benchmark
(1)
Bingo
(2)
Bot detector
(1)
build events
(1)
C#
(10)
CTE
(6)
cv
(1)
datawarehouse modeling
(1)
deadlock
(1)
Denali
(2)
dtutil
(2)
Engine of the Devil
(2)
EXECUTE AS
(1)
Execute SQL Task
(1)
EzAPI
(4)
F#
(3)
facebook
(1)
html
(1)
identity theft
(1)
itms
(1)
linked servers
(1)
Macbook Pro
(1)
Macros
(2)
meme monday
(4)
Merge Join
(1)
MS SQL Server
(33)
MySQL
(2)
n00b
(1)
Parameters
(1)
parsing
(1)
permissions
(2)
powershell
(4)
presentation
(1)
Profiler
(1)
Project Euler
(2)
python
(1)
Ranking
(1)
Resume
(1)
RSClientPrint
(2)
schema
(1)
shameless self promotion
(1)
SQL Lock In
(1)
SQL PASS
(1)
SQL Saturday
(2)
SQL Saturday 53
(8)
SQL Saturday 91
(1)
SQL Server 2005
(22)
SQL Server 2008
(13)
SSAS
(1)
SSIS
(29)
SSISUploader
(1)
SSISUploader SSIS
(3)
SSRS
(2)
standards
(1)
stupid
(1)
Summit 2009
(2)
Tofslie
(1)
troubleshooting
(1)
TSQL
(24)
Twitter
(2)
UAC
(1)
Visual Studio
(3)
Visual Studio 2010
(1)
Windows Server 2008 R2
(1)
XML
(1)
yahoo
(1)
0 comments:
Post a Comment