Bruce Schneier

 
 

Schneier on Security

A blog covering security and security technology.

« Cat Smuggler | Main | The Politics and Philosophy of National Security »

January 9, 2013

Denial-of-Service Attack Against Facebook

Just claim the person is dead. All you need to do is fake an online obituary.

Posted on January 9, 2013 at 6:44 AM12 Comments

To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter.

Comments

HaloJanuary 9, 2013 6:50 AM

Or find someone with an identical name to that on an actual obituary.


HugoJanuary 9, 2013 7:19 AM

Looks like you're probably still alive.

http://www.isxdead.com/person/15176/...


Jacson QuerubinJanuary 9, 2013 7:39 AM

I hope people discover that's all this "social" sites is just a waste of time... go live..
=)

they live?


brownJanuary 9, 2013 9:27 AM

@Hugo:

Your web site also thinks Gordon Brown is dead: http://www.isxdead.com/person/18016/...


cassielJanuary 9, 2013 10:49 AM

Another technique, reported a week or two ago, is to create a new Facebook group, add the intended target as administrator, and then post material which contravenes Facebook's terms and conditions. Voila: all administrative accounts for the group are disabled.


RustyJanuary 9, 2013 11:09 AM

All the experimental indications are that you only need an obit with a vaguely similar name. No need to fake, just google. Maybe they'll tighten it a bit now, but it appears this has been an open issue since at least 2009.


DaveJanuary 9, 2013 12:34 PM

There's a flip side too, a Facebook user who was a personal friend died (at a tragically young age) and the reminders from FB were upsetting to some. That issue was resolved, though. All-in-all there's a balance and I think social media are useful even if not ideal.
--
Dave


wiredogJanuary 9, 2013 12:57 PM

Given that Rusty hardly ever posts to his own website, it was probably easy to fake his death.


J.January 10, 2013 3:30 AM

I hope they have safeguards against repeated attacks.


Andre DeMarreJanuary 10, 2013 6:11 PM

This isn't new:
http://jeremiahgrossman.blogspot.com/2011/03/...

Two years ago internet security researcher Robert Hansen, aka RSnake, announced he would leave the web app sec research scene and stop blogging. His peers performed this same attack to "memorialize" his Facebook persona.


Post a comment




E-mail is optional and will not be displayed on the site.


Remember Me?


Allowed HTML: <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre>

Powered by Movable Type. Photo at top by Geoffrey Stone.

Schneier.com is a personal website. Opinions expressed are not necessarily those of BT.

 
Bruce Schneier