{"id":14194,"date":"2018-12-27T10:00:11","date_gmt":"2018-12-27T18:00:11","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/12\/27\/news-7946\/"},"modified":"2018-12-27T10:00:11","modified_gmt":"2018-12-27T18:00:11","slug":"news-7946","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/12\/27\/news-7946\/","title":{"rendered":"Why it\u2019s Time to Switch from Facebook Login to a Password Manager"},"content":{"rendered":"<p><strong>Credit to Author: Trend Micro| Date: Thu, 27 Dec 2018 16:42:43 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"172\" src=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/12\/20180406024006282-383-aNET9uy-800-300x172.jpg\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/12\/20180406024006282-383-aNET9uy-800-300x172.jpg 300w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/12\/20180406024006282-383-aNET9uy-800-768x440.jpg 768w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/12\/20180406024006282-383-aNET9uy-800-640x366.jpg 640w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/12\/20180406024006282-383-aNET9uy-800-440x252.jpg 440w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/12\/20180406024006282-383-aNET9uy-800-380x218.jpg 380w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/12\/20180406024006282-383-aNET9uy-800.jpg 800w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>Social media sites are increasingly the focus of our digital lives. Not only do we share, interact and post on platforms like Facebook \u2014we also use these sites to quickly log into our favorite apps and websites. But what happens when these social media gatekeepers are hacked? Awhile back, Facebook suffered a major attack when hackers obtained the digital keys to access at least 30 million accounts (originally thought to be 50 million), exposing highly sensitive personal details.<\/p>\n<p>The attack not only gave the bad guys access to the Facebook accounts but raised the prospect of them also being able to access any linked apps or websites. The message is clear: it may be time to store log-ins for these third-party accounts in a password manager, rather than a frequently targeted social media company.<\/p>\n<p><strong>What happened, exactly?<\/strong><\/p>\n<p>As a Facebook user, you\u2019re probably well-aware of the ease-of-use benefit of logging-in to your third-party website and application accounts using your Facebook credentials. Known as Facebook Connect, this is what\u2019s called a \u201cSingle Sign-On\u201d feature: a fast, simple, and straightforward way to log in to your various accounts, so you don\u2019t have to remember multiple different passwords for different sites and apps.<\/p>\n<p>Convenient, eh? But here\u2019s the problem. At the end of September (in 2018), <a href=\"https:\/\/newsroom.fb.com\/news\/2018\/09\/security-update\/\">Facebook discovered<\/a> a major security issue: attackers managed to steal the crucial access tokens which act as \u201cdigital keys\u201d to keep you logged into the site without having to re-enter your password each time you use Facebook. These keys also provide access to all those third-party applications and websites you log-in to via Facebook: everything from Airbnb and Amazon to Tinder and your favorite news apps. Since there\u2019s a chance that the bad guys were also able to illegally access these, they may have been able to gather more of your sensitive info across these accounts to commit identity theft\u2014and thereby gain access to your credit cards as well.<\/p>\n<p>How did the hackers grab these all-important access tokens? By exploiting several bugs in Facebook\u2019s \u201cView As\u201d and video posting features. (View As is a feature that allows users to see what their own profile looks like to someone else). They ultimately <a href=\"https:\/\/newsroom.fb.com\/news\/2018\/10\/update-on-security-issue\/\">stole access tokens<\/a> for 30 million \u00a0users; accessed just name and contact details for 15 million; virtually <em>all<\/em> profile info including name, contact details, username, gender, language, relationship status, religion, etc. for 14 million; and no info at all for 1 million.<\/p>\n<p>Facebook has been quick <a href=\"https:\/\/newsroom.fb.com\/news\/2018\/10\/facebook-login-update\/https:\/newsroom.fb.com\/news\/2018\/10\/facebook-login-update\/\">to point out<\/a> that there are currently no signs the attackers did access any of third-party apps using Facebook SSO. However, that may change. It also doesn\u2019t alter the fact that a similar incident like this, or worse, could happen in the future. Social media and web providers like Facebook are a major target for attackers, while human error will inevitably lead to some security mistakes in the future. A bug in Google\u2019s code <a href=\"https:\/\/www.blog.google\/technology\/safety-security\/project-strobe\/\">recently exposed<\/a> the data of 500,000 users of its Google+ social platform, which has prompted their decision to shut down the consumer side of the site within the next 10 months (as of October 2018).<\/p>\n<p><strong>How can I stay safe?<\/strong><\/p>\n<p><strong>Post-hack<\/strong><\/p>\n<p>Facebook has fixed the bugs in question and reset the access tokens of those affected by this breach, which should help to stop future attacks. However, if your account was illegally accessed in the attack, there are a few steps you should take:<\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"20px\"><\/td>\n<td>\n<ul>\n<li><strong>Visit <a href=\"https:\/\/www.facebook.com\/help\/securitynotice?ref=sec\">this link<\/a> to get a yes or no answer <\/strong>on whether you were affected.<\/li>\n<li><strong>Be on the lookout for scams: <\/strong>Fraudsters may call, email or send you messages using the info they\u2019ve obtained from the breach.<\/li>\n<li><strong>Beware of phishing emails:<\/strong> scammers might try to capitalize on the notoriety of the incident to get you to part with sensitive info, by sending emails pretending to come from Facebook. <a href=\"https:\/\/www.facebook.com\/help\/www\/1956527391029758?helpref=faq_content\">Here\u2019s how to confirm<\/a> if they\u2019re real or not.<\/li>\n<li><strong>You may need to call your bank:<\/strong> if you were in the second group of 14m users, the hackers may have enough personal info on you to answer security questions to access your accounts. Consider adding further layers of security.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td height=\"10px\"><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Take preventative steps<\/strong><\/p>\n<p>After the above, consider the following options to keep all your accounts secure going forward:<\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"20px\"><\/td>\n<td>\n<ul>\n<li><strong>Disable Facebook SSO<\/strong>. Go to<a href=\"https:\/\/www.facebook.com\/settings?tab=applications\">your Facebook settings<\/a>\u00a0and remove all apps under <strong>Active Apps and Websites<\/strong>. Then under <strong>Apps, Websites and Games<\/strong> go to <strong>Preferences<\/strong> and click on<strong> Edit<\/strong> then <strong>Turn Off<\/strong>.<\/li>\n<li><strong>Switch on two-factor authentication: <\/strong>this will add an extra layer of security to your Facebook log-in. Visit Facebook\u2019s <strong>Settings<\/strong>&gt; <strong>Security and login<\/strong>&gt; <strong>Setting up extra security<\/strong>&gt; <strong>Use two-factor authentication<\/strong>.<\/li>\n<li><strong>Consider Facebook\u2019s app password generator:<\/strong> If you wish to maintain app and website connections, <a href=\"https:\/\/www.facebook.com\/help\/249378535085386?helpref=uf_permalink\">this function<\/a> lets you generate unique passwords for your linked apps and websites, instead of using the Facebook SSO password. However, these passwords can\u2019t be stored in a password manager, and if you log out of the app, you\u2019ll have to generate a fresh password.<\/li>\n<li><strong>Better yet, invest in a password manager<\/strong> to securely generate and store strong and unique passwords for each of your Facebook linked apps and websites.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td height=\"10px\"><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Will it affect my use of Facebook?<\/strong><\/p>\n<p>If you disable Facebook SSO there may be some loss of sharing functionality. For example, you might find that you can\u2019t post\/share articles from within news apps direct to Facebook, and instead have to cut and paste the link manually. It will depend, however, on the apps you\u2019re using. At the end of the day, you need to decide what\u2019s more important to you: tighter integration between apps\/websites and Facebook, or keeping your passwords in a separate, secure place away from the social media company.<\/p>\n<p><strong>How can Trend Micro help?<\/strong><\/p>\n<p><strong>Trend Micro Password Manager<\/strong> can help you to protect the privacy and security of your app and website account passwords across PCs and Macs, and Android and iOS mobile devices. Use it as a highly user-friendly but more-secure alternative to Facebook SSO. Trend Micro Password Manager<\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"20px\"><\/td>\n<td>\n<ul>\n<li>Generates highly secure, unique, and tough-to-hack passwords for each of your online accounts.<\/li>\n<li>Securely stores and replays these credentials for log-ins, so you don\u2019t have to remember them.<\/li>\n<li>Offers an easy way to change passwords, if any do end up being leaked or stolen.<\/li>\n<li>Makes it quick and easy to manage your passwords from any location, on any device and browser.<\/li>\n<li>Works across both apps and websites, with particular benefit for apps you use in conjunction with Facebook on your mobile devices.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td height=\"10px\"><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>For more information, or to purchase the product, go to our <a href=\"https:\/\/www.trendmicro.com\/en_us\/forHome\/products\/password-manager.html\">Trend Micro Password Manager<\/a> website. Note that Trend Micro Password Manager is automatically installed with <a href=\"https:\/\/www.trendmicro.com\/en_us\/forHome\/products\/maximum-security.html\">Trend Micro Maximum Security.<\/a><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\/why-its-time-to-switch-from-facebook-login-to-a-password-manager\/\">Why it\u2019s Time to Switch from Facebook Login to a Password Manager<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\"><\/a>.<\/p>\n<p><a href=\"https:\/\/blog.trendmicro.com\/why-its-time-to-switch-from-facebook-login-to-a-password-manager\/\" target=\"bwo\" >http:\/\/feeds.trendmicro.com\/TrendMicroSimplySecurity<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Trend Micro| Date: Thu, 27 Dec 2018 16:42:43 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"172\" src=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/12\/20180406024006282-383-aNET9uy-800-300x172.jpg\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/12\/20180406024006282-383-aNET9uy-800-300x172.jpg 300w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/12\/20180406024006282-383-aNET9uy-800-768x440.jpg 768w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/12\/20180406024006282-383-aNET9uy-800-640x366.jpg 640w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/12\/20180406024006282-383-aNET9uy-800-440x252.jpg 440w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/12\/20180406024006282-383-aNET9uy-800-380x218.jpg 380w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/12\/20180406024006282-383-aNET9uy-800.jpg 800w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>Social media sites are increasingly the focus of our digital lives. Not only do we share, interact and post on platforms like Facebook \u2014we also use these sites to quickly log into our favorite apps and websites. But what happens when these social media gatekeepers are hacked? Awhile back, Facebook suffered a major attack when&#8230;<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\/why-its-time-to-switch-from-facebook-login-to-a-password-manager\/\">Why it\u2019s Time to Switch from Facebook Login to a Password Manager<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\"><\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10413],"tags":[19627,11347,20544,20545,666],"class_list":["post-14194","post","type-post","status-publish","format-standard","hentry","category-security","category-trendmicro","tag-facebook-hack","tag-password-manager","tag-single-sign-on","tag-social-media-security","tag-uncategorized"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14194","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=14194"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14194\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=14194"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=14194"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=14194"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}