Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts

Friday, March 23, 2012

Employee Passwords Are None of Your Business, Says Facebook

If the growing number of companies and law enforcement agencies asking job applicants for Facebook passwords was encouraging you to do the same, think again.
Facebook Friday issued a warning to employers that requesting passwords is an invasion of privacy that opens companies to legal liabilities.
The world's largest social network also is threatening legal action. Wrote Erin Egan, Facebook's chief privacy officer, in a lengthy post: "We'll take action to protect the privacy and security of our users, whether by engaging policymakers or, where appropriate, by initiating legal action, including by shutting down applications that abuse their privileges."
The company says it has seen a "distressing increase" of reports of employers attempting to access user accounts, Facebook's Egan wrote. "The most alarming of these practices is the reported incidences of employers asking prospective or actual employees to reveal their passwords," she said.
A user should never be forced to cough up private information just to get a job—"and as the friend of a user, you shouldn’t have to worry that your private information or communications will be revealed to someone you don’t know and didn’t intend to share with just because that user is looking for a job," Egan wrote.
The company has changed its Statement of Rights and Responsibilities, making requests to share or solicit a Facebook log-in a violation of the rules.
The American Civil Liberties Union this week used the reports to urge support for its "Demand your dotRights campaign."
ACLU attorney Catherine Crump called the password solicitation an "invasion of privacy."
"You’d be appalled if your employer insisted on opening up your postal mail to see if there was anything of interest inside," she said. "It’s equally out of bounds for an employer to go on a fishing expedition through a person’s private social media account."
The ACLU of Maryland currently is fighting for a social media privacy bill in the state, where the Department of Public Safety and Correctional Services asks applicants to "voluntarily" provide access to their social media accounts during interviews.

Thursday, February 23, 2012

YouPorn User Emails and Passwords Exposed

Thousands of user emails and passwords from pornographic site YouPorn were exposed in a security breach, the Associated Press reports.
The security breach was allegedly caused by a third-party chat service, which “failed to take the appropriate precautions in securing its user data,” according to Kate Miller, spokeswoman of YouPorn parent company Manwin Holding SARL. YouPorn has shut down the breached server and notified its users about the security breach.
To make matters worse, a list of user emails and accompanying passwords (in plain text) is already circulating online. The list contains some 6,400 passwords, and it’s already been widely publicized, looked over and analyzed – for example, a word cloud of the most popular passwords from the site has been created by researcher Ashkan Soltani.
YouPorn is one of top 100 visited websites on the internet according to Alexa, which makes this security breach a high profile one. It’s also highly embarassing for users, many of which probably do not want to be publicly associated with a pornography site.
The lesson to be learned from the incident is the usual one: do not use the same login credentials for multiple sites. Additionally, if you use services such as this one, choose an e-mail and/or login and password that cannot easily identify you.