Monday, March 5, 2012

Sunday, March 4, 2012

Linking Facebook and Match.com



This is a great example of cross-site inference. Mostly websites only think about their own privacy but the linking of innocuous data leaks might reveal powerful information!

Current Practices in Data Mining by Companies

While this post is not about online data and cybercasing, it gives you an example what is currenlty already done by companies:
http://www.forbes.com/sites/kashmirhill/2012/02/16/how-target-figured-out-a-teen-girl-was-pregnant-before-her-father-did/

Measures to keep your home safe

What measures should people be taking to keep their property and their family safe?
1. Don’t leave windows open
2. Don’t leave valuables in easy view of passers by
3. Don’t place your status and whereabouts on social media
4. Don’t hide keys in doorways
http://www.crimestoppers-uk.org/media-centre/news-releases/2011/4-out-of-5-ex-burglars-believe-thieves-are-targeting-your-home-using-social-media-522425

US bars friends over Twitter joke

As this is a highly political post, you might ask yourself, why is this on a cybercasing blog?
The reason for this is that I don't interpret the article as an example of the stupidity of Government but as a really nice example of "people don't think about the actual outreach of their post when they post". Again: Think before you post!
http://www.thesun.co.uk/sol/homepage/news/4095372/Twitter-news-US-bars-friends-over-Twitter-joke.html

Federal Contractor Monitored Social Network Sites

No surprise actually:
http://www.nytimes.com/2012/01/14/us/federal-security-program-monitored-public-opinion.html?_r=1

Hacked!

http://www.theatlantic.com/magazine/archive/2011/11/hacked/8673/

Online privacy could keep you and your home safe from robberies

http://news.medill.northwestern.edu/chicago/news.aspx?id=198289

Einstein said: "It's hard to predict, especially the future." Therefore, as researchers we are usually happy when we predicted somehow right. I am not in this case. 

Banks start to nose around on Social Media

Banks might also promote cybercasing in the future: http://www.betabeat.com/2011/12/13/as-banks-start-nosing-around-facebook-and-twitter-the-wrong-friends-might-just-sink-your-credit/?show=all

Cybercasing for Dummies

http://www.takethislollipop.com

Hitachi Develops World's Smallest RFID Chip

http://thefutureofthings.com/news/1032/hitachi-develops-worlds-smallest-rfid-chip.htmlhttp://thefutureofthings.com/news/1032/hitachi-develops-worlds-smallest-rfid-chip.html

Giving the F.B.I. What It Wants

http://www.nytimes.com/2011/10/30/opinion/sunday/giving-the-fbi-what-it-wants.html?_r=1

Airplane Hacking

You think you are sitting in the airplane anonymously to your fellow passengers? Not if you are using a Mac....
 
 

Infographic: 5 Ways You Can Lose a Job on Facebook

http://www.pcmag.com/article2/0,2817,2390620,00.asp

Undodgeable tracking...

http://www.wired.com/epicenter/2011/07/undeletable-cookie/

Cudos to my colleagues at ICSI.

"On the Internet, nobody knows you're a dog" revisited

There is no such thing as anonymous online tracking:
http://cyberlaw.stanford.edu/node/6701
 

The case for cybercasing: Uploading photos to Facebook and Twitter can make you a target for crime

http://news.medill.northwestern.edu/chicago/news.aspx?id=170325

Speaking about Oversharing....

It can't be more detailed:

Reverse Social Engineering

Reverse Social Engineering or how easy it is to make others request your friendship:
http://www.iseclab.org/people/

How advanced behaviour modelling is helping to identify online fraud

Well, it's easy to imagine how this can be abused:
http://www.physorg.com

SMS and Geo-Tagging

Two links to follows:

http://geosms.wordpress.com/
 

and

http://www.readwriteweb.com/archives/mapping_geolocation_and_the_future_of_scalable_disaster_response.php

How to easily delete your online accounts

Finally, somebody promises to do something about legacy accounts:
http://www.accountkiller.com/en/

Fake Faecbook ID

Post something in a group with the username of a "friend"? Facebook makes it possible: Invite the "friend" to a group (the "friend" cannot prevent being automatically added to this group), send an email from your emailclient with your "friends" email address - voila, the email appears as posted from your friend (Sorry, German again).
http://www.heise.de/newsticker/meldung/Mobbing-fuer-Fortgeschrittene-mit-Facebook-Gruppen-1264593.html

"Me on the Web" on Your Google Dashboard Lets you Manage Your Identity Online

For a change, here is a little more constructive post: http://glosslip.com/blogging/article/me-on-the-web-on-your/

Facebook Friday: Plan a party, good. Plan a murder, Bad | Lubbock Online | Lubbock Avalanche-Journal

We could call this one anti-cybercasing...
http://lubbockonline.com/interact/blog-post/bert-knabe/2011-06-17/facebook-friday-plan-party-good-plan-murder-bad

Don't announce your birthday party on Facebook:

http://www.youtube.com/watch?v=xxDTe-T__dQ
 (Apologies for the video being German)

Are you also exposing your private parts to strangers on Facebook?

A case of serious re-blogging :-)
http://blog.web.blogads.com/2011/06/08/are-you-also-exposing-your-private-parts-to-strangers-on-facebook/


Smartphone Stalking

Here are some instructions on how to turn off GPS on smartphones (not that it solves the problem, really):

http://myhighplains.com/fulltext?nxd_id=194647

Surprise! Your GPS Device (Probably) Isn’t Spying On You

http://www.credit.com/blog/2011/06/surprise-your-gps-device-probably-isnt-spying-on-you/

Cybercasing, original definition

What's this BLOG about?
Here is the original research paper we wrote:
http://www.icsi.berkeley.edu/cgi-bin/pubs/publication.pl?ID=002932

New Blog, yay!

Hi all,

This blog was originally started as a Facebook group. However, more and more people told me that a blog is a much better way of publishing about the topic I am publishing. So the first couple of entries in the blog will be copies of the original entries in the cybercasing Facebook group.

So what is cybercasing after all?
Cybercasing is: "Using online (location-based) data and services to mount real-world attacks that weren't otherwise possible".

The purpose of this blog is to inform people of the risks so that they can prevent being cybercased.

Have scary fun...

Gerald