Re: Linked-in and its Phishing-like contacts option!
Jon Robinson <[email protected]> Wed, 1 May 2013 09:44:36 -0700
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <CADR-zoPXU+5cR3evia-6FW2vVJu-BB7s9cARHRHDxLJQgdG=Zg@mail.gmail.com> |
--===============1641492128== Content-Type: multipart/alternative; boundary=047d7b342d285085a304dbaad5da --047d7b342d285085a304dbaad5da Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable It's not free but Palo Alto Networks does this.You can search here to see which applications/sites they can control: http://apps.paloaltonetworks.com/applipedia/ Jon Robinson Digital Scepter desk (951) 461-7868 mobile (562) 682-0821 [email protected] On Tue, Apr 30, 2013 at 10:50 PM, Mathew Want <[email protected]> wrote: > Read only access to the sites. I like that idea a lot. > > Has anyone else come across this requirement or found a good way to do it > at a control point level? Perhaps at the IDS layer? > > M@ > > > On 1 May 2013 02:20, <[email protected]> wrote: > >> > I'm honestly not sure how we could block this stuff in a web-proxy, or >> be >> > alerted by an IDS rule short of just blocking the sites. >> > (Maybe this will start more discussion. How would one try this?) >> >> I have a lot of requests from customers to try to make the web read-only= . >> The main use cases are for social network, blogs/wikis, and commenting o= n >> posts. The fundamental ways to do this are to 1) have MITM SSL decryptio= n, >> and 2) block the POST method for specific sites. Most commercial proxies >> can do this and even squid does SSL MITM. >> >> By blocking POST to certain categories of sites and only allowing the >> POST for the */logon pages, users can view all the facebook/twitter/yout= ube >> they want, but can't write anything outbound to the site. It's pretty >> effective. >> >> e=C2=B2 >> _____________________________________ >> >> From: [email protected] [mailto: >> [email protected]] On Behalf Of Bruce Platt >> Sent: Friday, April 26, 2013 7:41 AM >> To: Firewall Wizards Security Mailing List >> Subject: Re: [fw-wiz] Linked-in and its Phishing-like contacts option! >> >> I have a love/hate relationship with these as well. I was only tempted >> down this perfidious path a few years ago when a set of my Grandchildren >> asked me to get a Facebook account so we could interact that way as they >> live on the other coast from me. I started disliking it within five >> minutes when a former employer sent me a request to "friend" him. Then = it >> became an issue of who can I not be "friends" with among my contemporari= es. >> >> Same with Linked-In, same with Twitter. >> >> Up to this point I'm just addressing the personal inconvenience aspect o= f >> it, which is why I chose Crispan's post to which to reply. >> >> But, the larger issue is really the risk of exposing all sorts of >> personal / corporate information in a variety of unwitting ways. This = is >> the part I hate. We've had many discussions about the risks of allowing >> people to use social media web sites from work. It's a losing battle. >> Entering one's email password is just one, and Linked-In is not the onl= y >> villain. I just made some flight reservations yesterday. The airline >> website offered to add the reservation to my Calendar. Not let me downl= oad >> a .cal file, but to directly insert it into my calendar. Uh, no. Not >> today. >> >> But, this now get's added to our list of worst practices and meet's >> Paul's criteria of being part of overall operational security. I'm >> honestly not sure how we could block this stuff in a web-proxy, or be >> alerted by an IDS rule short of just blocking the sites. (Maybe this wi= ll >> start more discussion. How would one try this?) >> >> Mix these with BYOD, and it makes a daunting task indeed. >> >> Cheers >> >> -- >> +------------------------------------+ >> Bruce B. Platt, Ph.D. >> V.P. Research >> ei3 Corporation >> 136 Summit Avenue >> Montvale, NJ 07645 >> Phone: +1-201-802-9080 ext. 404 >> Facsimile: +1-201-802-9099 >> >> On Fri, Apr 26, 2013 at 12:53 AM, Crispin Cowan <[email protected]= m> >> wrote: >> I boycott all social media. I=E2=80=99m not opposed to social networking= , but I >> am opposed to some dot.com monetizing my relationships; I do all my >> social networking via open protocols like e-mail, and having a beer with= a >> friend =F0=9F=98=8A >> >> I broke this rule once, joining LinkedIn 5 years ago, because I needed a >> job. LinkedIn was a total failure at getting a job, but attending ToorCo= n >> and having a beer with someone I met there worked. I deleted my LinkedIn >> account when I got tired of the =E2=80=9CFoo wants to connect with you= =E2=80=9D spam. I=E2=80=99m >> still getting LinkedIn spam. >> >> Screw social networking web sites. I don=E2=80=99t have a FaceBook page = or a >> Twitter account, and never will. >> >> Funny, I never envisioned myself as Clint Eastwood yelling at kids to ge= t >> off my lawn, but here I am =F0=9F=98=8A >> >> Sent from Windows Mail >> >> From: Gautier . Rich >> Sent: =E2=80=8EThursday=E2=80=8E, =E2=80=8EApril=E2=80=8E =E2=80=8E25=E2= =80=8E, =E2=80=8E2013 =E2=80=8E9=E2=80=8E:=E2=80=8E28=E2=80=8E =E2=80=8EPM >> To: Firewall Wizards Security Mailing List >> >> Thoughts? I=E2=80=99m wondering why User Operational Security falls unde= r the >> realm of Firewall Wizards.. Other than that, I=E2=80=99d say =E2=80=93 = They=E2=80=99re not alone >> by any stretch of the imagination, and plenty of users seem to be perfec= tly >> willing to accept the risk (or be unaware of it). However, not much you >> can do on the firewall side other than turning off webmail access... >> >> Richard Gautier, CISSP >> Enterprise Architect, Federal Group >> 650 Massachusetts Avenue NW >> Suite 510 >> Washington, DC 20001 >> Office: (571) 226-8828 | Cell: (703) 231-2156 >> [email protected] | www.drc.com >> >> From: [email protected] [mailto: >> [email protected]] On Behalf Of Mathew Want >> Sent: Monday, April 22, 2013 7:30 PM >> To: Firewall Wizards Security Mailing List >> Subject: [fw-wiz] Linked-in and its Phishing-like contacts option! >> >> Hiya all. >> >> Has anyone else noticed the option to see who else they know is connecte= d >> on Linked-in? Have you noticed that if you click on the outlook button i= t >> asks you for your WORK EMAIL PASSWORD!!!!! >> Bloody hell! It's not like the job of getting users to not submit this >> information to other sites isn't already hard enough without this!!! The >> "can't put brains in pumpkins " department must be having a field day ov= er >> this. >> Am I the only one that think this is a touch negligent on the part of >> Linked-in? Or should I just accept that it is corporate facebook, accept= s >> that they have the dame moral fibre and move on? >> Maybe I am expecting too much? Thoughts? >> -- >> Regards, >> M@ >> -- >> "Some things are eternal by nature, >> others by consequence" >> ________________________________________ >> This electronic message transmission and any attachments that accompany >> it contain information from DRC=C2=AE (Dynamics Research Corporation) or= its >> subsidiaries, or the intended recipient, which is privileged, proprietar= y, >> business confidential, or otherwise protected from disclosure and is the >> exclusive property of DRC and/or the intended recipient. The information= in >> this email is solely intended for the use of the individual or entity th= at >> is the intended recipient. If you are not the intended recipient, any us= e, >> dissemination, distribution, retention, or copying of this communication= , >> attachments, or substance is prohibited. If you have received this >> electronic transmission in error, please immediately reply to the author >> via email that you received the message by mistake and also promptly and >> permanently delete this message and all copies of this email and any >> attachments. We thank you for your assistance and apologize for any >> inconvenience. >> >> _______________________________________________ >> firewall-wizards mailing list >> [email protected] >> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards >> >> >> _______________________________________________ >> firewall-wizards mailing list >> [email protected] >> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards >> > > > > -- > "Some things are eternal by nature, > others by consequence" > > _______________________________________________ > firewall-wizards mailing list > [email protected] > https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards > > --047d7b342d285085a304dbaad5da Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">It's not free but Palo Alto Networks does this.You can= search here to see which applications/sites they can control:=C2=A0<a href= =3D"http://apps.paloaltonetworks.com/applipedia/">http://apps.paloaltonetwo= rks.com/applipedia/</a><div class=3D"gmail_extra"> <br clear=3D"all"><div><div dir=3D"ltr"><div><br></div><div>Jon Robinson</d= iv><div>Digital Scepter</div><div>desk (951) 461-7868</div><div>mobile (562= ) 682-0821</div><div><a href=3D"mailto:[email protected]" target=3D"_b= lank">[email protected]</a></div> <div><br></div></div></div> <br><br><div class=3D"gmail_quote">On Tue, Apr 30, 2013 at 10:50 PM, Mathew= Want <span dir=3D"ltr"><<a href=3D"mailto:[email protected]" target=3D"= _blank">[email protected]</a>></span> wrote:<br><blockquote class=3D"gma= il_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-lef= t:1ex"> <div dir=3D"ltr"><div>Read only access to the sites. I like that idea a lot= .<br><br>Has anyone else come across this requirement or found a good way t= o do it at a control point level? Perhaps at the IDS layer?<span class=3D"H= OEnZb"><font color=3D"#888888"><br> <br></font></span></div><span class=3D"HOEnZb"><font color=3D"#888888">M@ <= br> </font></span></div><div class=3D"HOEnZb"><div class=3D"h5"><div class=3D"g= mail_extra"><br><br><div class=3D"gmail_quote">On 1 May 2013 02:20, <span = dir=3D"ltr"><<a href=3D"mailto:[email protected]" target=3D"_bl= ank">[email protected]</a>></span> wrote:<br> <blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p= x #ccc solid;padding-left:1ex"> <div>> I'm honestly not sure how we could block this stuff in a web-= proxy, or be<br> > alerted by an IDS rule short of just blocking the sites.<br> > (Maybe this will start more discussion. =C2=A0How would one try this?)= <br> <br> </div>I have a lot of requests from customers to try to make the web read-o= nly. The main use cases are for social network, blogs/wikis, and commenting= on posts. The fundamental ways to do this are to 1) have MITM SSL decrypti= on, and 2) block the POST method for specific sites. Most commercial proxie= s can do this and even squid does SSL MITM.<br> <br> By blocking POST to certain categories of sites and only allowing the POST = for the */logon pages, users can view all the facebook/twitter/youtube they= want, but can't write anything outbound to the site. It's pretty e= ffective.<br> <br> e=C2=B2<br> _____________________________________<br> <br> From: <a href=3D"mailto:[email protected]" tar= get=3D"_blank">[email protected]</a> [mailto:<= a href=3D"mailto:[email protected]" target=3D"= _blank">[email protected]</a>] On Behalf Of Br= uce Platt<br> Sent: Friday, April 26, 2013 7:41 AM<br> <div>To: Firewall Wizards Security Mailing List<br> </div>Subject: Re: [fw-wiz] Linked-in and its Phishing-like contacts option= !<br> <div><div><br> I have a love/hate relationship with these as well. =C2=A0I was only tempte= d down this perfidious path a few years ago when a set of my Grandchildren = asked me to get a Facebook account so we could interact that way as they li= ve on the other coast from me. =C2=A0I started disliking it within five min= utes when a former employer sent me a request to "friend" him. = =C2=A0Then it became an issue of who can I not be "friends" with = among my contemporaries.<br> <br> Same with Linked-In, same with Twitter.<br> <br> Up to this point I'm just addressing the personal inconvenience aspect = of it, which is why I chose Crispan's post to which to reply.<br> <br> But, the larger issue is really the risk of exposing all sorts of personal = / =C2=A0corporate information in a variety of unwitting ways. =C2=A0This is= the part I hate. =C2=A0We've had many discussions about the risks of a= llowing people to use social media web sites from work. =C2=A0It's a lo= sing battle. =C2=A0Entering one's email password is just one, and Linke= d-In is not the only villain. =C2=A0I just made some flight reservations ye= sterday. =C2=A0The airline website offered to add the reservation to my Cal= endar. =C2=A0Not let me download a .cal file, but to directly insert it int= o my calendar. =C2=A0Uh, no. =C2=A0Not today.<br> <br> But, this now get's added to our list of worst practices and meet's= Paul's criteria of being part of overall operational security. =C2=A0I= 'm honestly not sure how we could block this stuff in a web-proxy, or b= e alerted by an IDS rule short of just blocking the sites. =C2=A0(Maybe thi= s will start more discussion. =C2=A0How would one try this?)<br> <br> Mix these with BYOD, and it makes a daunting task indeed.<br> <br> Cheers<br> <br> --<br> +------------------------------------+<br> Bruce B. Platt, Ph.D.<br> V.P. Research<br> ei3 Corporation<br> 136 Summit Avenue<br> Montvale, NJ 07645<br> Phone: <a href=3D"tel:%2B1-201-802-9080%20ext.%20404" value=3D"+12018029080= " target=3D"_blank">+1-201-802-9080 ext. 404</a><br> Facsimile: <a href=3D"tel:%2B1-201-802-9099" value=3D"+12018029099" target= =3D"_blank">+1-201-802-9099</a><br> <br> On Fri, Apr 26, 2013 at 12:53 AM, Crispin Cowan <<a href=3D"mailto:crisp= [email protected]" target=3D"_blank">[email protected]</a>> wro= te:<br> I boycott all social media. I=E2=80=99m not opposed to social networking, b= ut I am opposed to some <a href=3D"http://dot.com" target=3D"_blank">dot.co= m</a> monetizing my relationships; I do all my social networking via open p= rotocols like e-mail, and having a beer with a friend =F0=9F=98=8A<br> <br> I broke this rule once, joining LinkedIn 5 years ago, because I needed a jo= b. LinkedIn was a total failure at getting a job, but attending ToorCon and= having a beer with someone I met there worked. I deleted my LinkedIn accou= nt when I got tired of the =E2=80=9CFoo wants to connect with you=E2=80=9D = spam. I=E2=80=99m still getting LinkedIn spam.<br> <br> Screw social networking web sites. I don=E2=80=99t have a FaceBook page or = a Twitter account, and never will.<br> <br> Funny, I never envisioned myself as Clint Eastwood yelling at kids to get o= ff my lawn, but here I am =F0=9F=98=8A<br> <br> Sent from Windows Mail<br> <br> From: Gautier . Rich<br> Sent: =E2=80=8EThursday=E2=80=8E, =E2=80=8EApril=E2=80=8E =E2=80=8E25=E2=80= =8E, =E2=80=8E2013 =E2=80=8E9=E2=80=8E:=E2=80=8E28=E2=80=8E =E2=80=8EPM<br> To: Firewall Wizards Security Mailing List<br> <br> Thoughts? I=E2=80=99m wondering why User Operational Security falls under t= he realm of Firewall Wizards.. =C2=A0Other than that, I=E2=80=99d say =E2= =80=93 They=E2=80=99re not alone by any stretch of the imagination, and ple= nty of users seem to be perfectly willing to accept the risk (or be unaware= of it). =C2=A0However, not much you can do on the firewall side other than= turning off webmail access...<br> <br> Richard Gautier, CISSP<br> Enterprise Architect, Federal Group<br> </div></div><div>650 Massachusetts Avenue NW<br> Suite 510<br> Washington, DC 20001<br> Office: <a href=3D"tel:%28571%29%20226-8828" value=3D"+15712268828" target= =3D"_blank">(571) 226-8828</a> =C2=A0| =C2=A0Cell: <a href=3D"tel:%28703%29= %20231-2156" value=3D"+17032312156" target=3D"_blank">(703) 231-2156</a><br= > <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a> = =C2=A0| =C2=A0<a href=3D"http://www.drc.com" target=3D"_blank">www.drc.com<= /a><br> <br> From: <a href=3D"mailto:[email protected]" tar= get=3D"_blank">[email protected]</a> [mailto:<= a href=3D"mailto:[email protected]" target=3D"= _blank">[email protected]</a>] On Behalf Of Ma= thew Want<br> Sent: Monday, April 22, 2013 7:30 PM<br> To: Firewall Wizards Security Mailing List<br> Subject: [fw-wiz] Linked-in and its Phishing-like contacts option!<br> <br> Hiya all.<br> <br> Has anyone else noticed the option to see who else they know is connected o= n Linked-in? Have you noticed that if you click on the outlook button it as= ks you for your WORK EMAIL PASSWORD!!!!!<br> Bloody hell! It's not like the job of getting users to not submit this = information to other sites isn't already hard enough without this!!! Th= e "can't put brains in pumpkins " department must be having a= field day over this.<br> Am I the only one that think this is a touch negligent on the part of Linke= d-in? Or should I just accept that it is corporate facebook, accepts that t= hey have the dame moral fibre and move on?<br> Maybe I am expecting too much? Thoughts?<br> --<br> Regards,<br> M@<br> --<br> "Some things are eternal by nature,<br> others by consequence"<br> </div>________________________________________<br> <div><div>This electronic message transmission and any attachments that acc= ompany it contain information from DRC=C2=AE (Dynamics Research Corporation= ) or its subsidiaries, or the intended recipient, which is privileged, prop= rietary, business confidential, or otherwise protected from disclosure and = is the exclusive property of DRC and/or the intended recipient. The informa= tion in this email is solely intended for the use of the individual or enti= ty that is the intended recipient. If you are not the intended recipient, a= ny use, dissemination, distribution, retention, or copying of this communic= ation, attachments, or substance is prohibited. If you have received this e= lectronic transmission in error, please immediately reply to the author via= email that you received the message by mistake and also promptly and perma= nently delete this message and all copies of this email and any attachments= . We thank you for your assistance and apologize for any inconvenience.<br> <br> _______________________________________________<br> firewall-wizards mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank"= >[email protected]</a><br> <a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards"= target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/firewall-= wizards</a><br> <br> <br> _______________________________________________<br> firewall-wizards mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank"= >[email protected]</a><br> <a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards"= target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/firewall-= wizards</a><br> </div></div></blockquote></div><br><br clear=3D"all"><br>-- <br>"Some = things are eternal by nature,<br>others by consequence"<br> </div> </div></div><br>_______________________________________________<br> firewall-wizards mailing list<br> <a href=3D"mailto:[email protected]">firewall-wizards@= listserv.icsalabs.com</a><br> <a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards"= target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/firewall-= wizards</a><br> <br></blockquote></div><br></div></div> --047d7b342d285085a304dbaad5da-- --===============1641492128== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards --===============1641492128==--