17 October 2007
Facebook bolsters security to protect children online Sophos welcomes move but calls for social networking site to change default privacy settings
IT security and control firm Sophos has welcomed news that Facebook has agreed to better promote its security settings and to take greater actions to protect children online, following a safety probe by the New York attorney general's office.
According to reports, investigators set up fake Facebook profiles posing as teenagers and received sexually suggestive messages from adults within days. The investigators then notified Facebook through its website, but these complaints went unanswered for weeks. Facebook has now agreed to post sterner and more obvious warnings about how users can control and set their security settings to reduce the dangers to children and others using its site. It has also pledged to deal with any complaints within 24 hours.

The office of the New York Attorney General investigated Facebook security.
Sophos experts note that, while Facebook's privacy and security features are far more sophisticated than competing social network sites, it is still almost impossible to police the site and check that users really are who they say they are. Furthermore, many users continue to unwittingly expose their personal details to millions of strangers online, potentially putting themselves at risk of online sexual abuse.
Indeed, recent research from Sophos revealed that 75 percent of users in the London network, the largest on Facebook with more than 1.2 million members, allowed their profile to be viewed by any other member. In light of this research and the findings of New York state, Sophos is urging Facebook to rethink its default privacy settings.
"With more than 70 million active users on Facebook - many of whom won't have thought to change their privacy settings and to limit which other members can access their personal information - it's no surprise that sexual predators are using these sites as a way to lure innocent victims," said Graham Cluley, senior technology consultant at Sophos. "Social networking sites provide these criminals with the anonymity they need to trick children and that's why it's so important that the companies themselves take steps to protect members and educate them about the dangers of joining networks and making friends with complete strangers. You wouldn't invite someone you don't know into your home and nor should you let them view your online profile."
- Read more about the privacy and productivity challenges associated with Facebook, and how to configure Facebook to better protect your online identity
- Download a podcast on Facebook and identity theft now
Simply click on the arrow above to stream the podcast through your browser. Alternatively you can download it to your MP3 player.
In August, Sophos published research showing that 41 percent of Facebook users were prepared to divulge personal information to a complete stranger (a small plastic frog called Freddi Staur - an anagram of 'ID Fraudster').

Freddi Staur, a plastic green frog, was able to access personal information about people on Facebook.
- SQL injection attacks are the biggest threat
- 90% of malware on legitimate sites
- Hackers exploit Web 2.0
About Sophos
Sophos enables enterprises all over the world to secure and control their IT infrastructure. Sophos's network access control, endpoint, web and email solutions simplify security to provide integrated defenses against malware, spyware, intrusions, unwanted applications, spam, policy abuse, data leakage and compliance drift. With over 20 years of experience, Sophos protects over 100 million users in nearly 150 countries with its reliably engineered security solutions and services. Recognized for its high level of customer satisfaction and powerful yet easy-to-use solutions, Sophos has received many industry awards, as well as positive reviews and certifications.
Sophos is headquartered in Boston, US and Oxford, UK. More information is available at www.sophos.com
See also:
- Sophos Facebook ID probe shows 41% of users happy to reveal all to potential identity thieves
- Facebook members bare all on networks, Sophos warns of new privacy concerns
- Facebook - the privacy and productivity challenge
- Best practice tips for privacy settings on Facebook
- 50% of employees blocked from accessing Facebook at work, Sophos survey reveals

