Showing posts with label Online Security. Show all posts
Showing posts with label Online Security. Show all posts

Monday, June 10, 2013

PRISM and Social Media Security


As the internet and social media have evolved, so has the etiquette that we should follow when using them. We have been taught not to post or send anything that we would not want to get out, for the sake of being professional online. However, we were not told to be careful of what we share in the event that the government would see it. 

Over the weekend, news broke that the National Security Agency and the FBI have been accessing information from the servers of nine top U.S. internet companies through a program code-named PRISM. The purpose of this program is to track foreign targets. So far information has been gathered from Microsoft, Yahoo, Google, Facebook, PalTalk, AOL, Skype, YouTube, and Apple; basically, every website that is used by millions of people on a daily basis. It has been reported that the NSA and FBI can request email, chat (both voice and video), video, photos, file transfers, and more. 

The most interesting thing about this revelation is that it is completely legal thanks to two pieces of legislation passed during the Bush Administration. The first, The Protect America Act of 2007 which allowed suspects to be monitored online without a warrant if they are “reasonably believed” to be foreign. The second, the FISA Amendments Act of 2008 which grants immunity to the internet companies that provide the information. Because of this, most, if not all, government statements thus far have been unapologetic and in support of continuing this program to ensure the safety of this country. 

Just yesterday, the PRISM whistleblower, Edward Snowden, decided to come forward. Why? He explains that when going up against such powerful agencies, you go in knowing that, “If they want you, they will get you in due time.” Snowden says that trying to keep your identity a secret does not prolong any consequences. He chose to blow the whistle on this project because he simply does not “want to live in a society that does these sort of things.”

This has sparked a huge debate among American citizens. Is PRISM an intrusion on our Constitutional rights or is it simply a new measure that our government has to take to keep our nation safe in this internet age?

Which side of the debate do you fall on? We want to know!

For more information on PRISM and the whistleblower, read these articles.

Saturday, March 2, 2013

Safeguarding your Social Media

Everyone has experienced seeing a stream of strange posts on a friend’s social media site with a tweet or status update later on saying “sorry my account was hacked!” But what if this friend was a social media manager for an organization, or what if this was a brand’s account you follow? 

It’s stressful to have an account hacked as an individual but when managing social media for an organization there are much higher stakes. A hacked Twitter or Facebook can do great damage to a company’s reputation. 

Burger King and Jeep are two examples of huge brands that have had their accounts hacked since the start of 2013. For Burger King, having their Twitter account hacked meant having a verified stamp next to the brand’s description which read, “Just got sold to McDonalds because the Whopper flopped.” 

There are simple tips we can remember when managing social media for a company to help us safeguard our brand’s reputation. 
  • Use a unique password for each site: It seems like an obvious answer but we all have the tendency to use the same password over and over for ease of use.  If a hacker obtains one password, at least you are able to deal with an isolated issue. 
  • Centralize a social media administrator: In a previous blog post, “Who Owns Social Media?” I discussed the trend toward collaborating between departments for social media. While you will want to do this for content, sharing the password between a large group is not secure. A solution could be for the administrator to use auto fill on other employees’ work computers to give access while on the job without sharing the password for use outside of work.
  • Randomly generated passwords: It’s a pain, but randomly generating passwords makes them nearly impossible to guess. Try Random.org's password generator and then backup your data with a cloud service that will store it in an encrypted form online. Some popular services include Lastpass, 1password and mSecure.
  • Make your mobile device secure: For most, a four digit password on the screen of an iPhone is fine. However, if you manage social media for a business and have passwords saved on your phone it’s a good idea to go into settings and turn the “simple passcode” feature off. This will unlock the option for you to use the full keyboard to make your password harder to crack.
This guest blog post was written by PRowl Public Relations staff member Kyra Mazurek.