{"id":690,"date":"2015-10-20T12:45:28","date_gmt":"2015-10-20T12:45:28","guid":{"rendered":"http:\/\/employee.clawsons.com\/?p=690"},"modified":"2020-04-30T11:23:25","modified_gmt":"2020-04-30T15:23:25","slug":"facebook-to-warn-you-of-targeted-attacks-check-this-security-setting-anyway","status":"publish","type":"post","link":"https:\/\/employee.clawsons.com\/index.php\/2015\/10\/20\/facebook-to-warn-you-of-targeted-attacks-check-this-security-setting-anyway\/","title":{"rendered":"Facebook to warn you of targeted attacks &#8211; check this security setting anyway"},"content":{"rendered":"<p>by John Zorabedian on October 20, 2015<\/p>\n<p><a href=\"https:\/\/nakedsecurity.sophos.com\/2015\/10\/20\/facebook-to-warn-you-of-targeted-attacks-check-this-security-setting-anyway\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/nakedsecurity.sophos.com\/2015\/10\/20\/facebook-to-warn-you-of-targeted-attacks-check-this-security-setting-anyway\/<\/a><\/p>\n<p>Facebook has announced that it will notify users it suspects are being targeted by nation states and urge them to take extra security precautions.<\/p>\n<p>Alex Stamos, Facebook&#8217;s chief security officer, explained the new notifications in a 16 October blog post, saying users will only receive the warnings if Facebook has strong evidence suggesting they are being targeted by\u00a0<a title=\"Facebook announcement on targeted attack notifications\" href=\"https:\/\/www.facebook.com\/notes\/facebook-security\/notifications-for-targeted-attacks\/10153092994615766?_rdr=p\" rel=\"nofollow\">nation-state sponsored attackers<\/a>.<\/p>\n<p>If the social network believes you are under attack from state-sponsored hackers, it will show a pop-up message in your feed explaining that you may have been targeted.<\/p>\n<p>The message asks, but does not require, those users to turn on an extra layer of protection for their account called Login Approvals.<\/p>\n<p>Stamos said Facebook &#8220;will have always taken steps to secure accounts that we believe to have been compromised,&#8221; but\u00a0will show the warning\u00a0to users because these attacks may\u00a0be &#8220;more advanced and dangerous&#8221; than others.<\/p>\n<p>This is how the message looks in the desktop version of Facebook:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-954 size-full aligncenter\" src=\"https:\/\/employee.clawsons.com\/wp-content\/uploads\/2015\/10\/facebook-warning.png\" alt=\"\" width=\"550\" height=\"186\" srcset=\"https:\/\/employee.clawsons.com\/wp-content\/uploads\/2015\/10\/facebook-warning.png 550w, https:\/\/employee.clawsons.com\/wp-content\/uploads\/2015\/10\/facebook-warning-300x101.png 300w, https:\/\/employee.clawsons.com\/wp-content\/uploads\/2015\/10\/facebook-warning-500x169.png 500w\" sizes=\"auto, (max-width: 550px) 100vw, 550px\" \/><\/p>\n<blockquote><p><tt>Jay, we believe your Facebook account and other online accounts may be the target of attacks from state-sponsored actors. Turning on Login Approvals will help keep others from logging into your Facebook account. Whenever your account is accessed from a new device or browser, we'll send a security code to your phone so that only you can log in. We recommend you also take steps to secure the accounts you use on other services.<\/tt><\/p><\/blockquote>\n<p>Because of the persistence of state-sponsored attackers, anyone whose Facebook account is\u00a0under attack by a nation state\u00a0is probably\u00a0also being targeted on other services, so Facebook encourages securing those accounts as well.<\/p>\n<p>Google began sending similar\u00a0<a href=\"https:\/\/nakedsecurity.sophos.com\/2012\/06\/06\/google-state-sponsored-attackers-may-be-attempting-to-compromise-your-account\/\">warnings to Gmail users<\/a>\u00a0back in 2012.<\/p>\n<p>Just like Google, Facebook says it can&#8217;t reveal how or why it suspects state-sponsored attacks, for fear of giving away useful information to attackers about security methods.<\/p>\n<p>Nation states may target individuals for political or national security reasons, but also attack individuals to\u00a0gain access to\u00a0their employers&#8217; intellectual property or customer data, for example.<\/p>\n<p>Countries like\u00a0<a title=\"Naked Security: Why was the US so sure North Korea hacked Sony? It had a front row seat\" href=\"https:\/\/nakedsecurity.sophos.com\/2015\/01\/19\/why-the-us-was-so-sure-north-korea-hacked-sony-it-had-a-front-row-seat\/\">North Korea<\/a>\u00a0and\u00a0<a title=\"Naked Security: China arrests hackers to appease US on cyberespionage\" href=\"https:\/\/nakedsecurity.sophos.com\/2015\/10\/13\/china-arrests-hackers-to-appease-us-on-cyberespionage\/\">China<\/a>\u00a0have been suspected of sponsoring attacks on private companies.<\/p>\n<p>Hackers affiliated with the\u00a0<a title=\"Naked Security: US charges Chinese military officers with cyberespionage\" href=\"https:\/\/nakedsecurity.sophos.com\/2014\/05\/20\/us-charges-chinese-military-officers-with-cyber-espionage\/\">Chinese military<\/a>\u00a0were indicted by the US two years ago for allegedly hacking into several US steel companies.<\/p>\n<p>The US claims the Chinese hackers used phishing emails and malware to gain access to email accounts of company officials, in order to steal information that would benefit Chinese state-run steel companies in trade disputes.<\/p>\n<h4>Targeted or not, extra security is always a good idea<\/h4>\n<p>Even if nation states aren&#8217;t likely to target you personally, it would be a shame to fall into the trap of thinking &#8220;no one&#8217;s interested in little old me.&#8221;<\/p>\n<p>As Naked Security expert Paul Ducklin pointed out in a post describing all the bad excuses we make for\u00a0<a href=\"https:\/\/nakedsecurity.sophos.com\/2014\/08\/20\/5-excuses-for-doing-nothing-about-computer-security\/\">neglecting our security<\/a>, we are\u00a0<em>all<\/em>\u00a0on cybercriminals&#8217; radars:<\/p>\n<blockquote><p><tt>We're all in the sights of cybercrooks somewhere, and we owe it to ourselves and to everyone else to do the best we can to thwart them.<\/tt><\/p><\/blockquote>\n<p>Today&#8217;s cybercriminals are typically in the business of making money, and to do that they want to compromise as many users and devices as possible.<\/p>\n<p>One method for attackers to gain access to your accounts is to implant malware on your computer that can steal passwords.<\/p>\n<p>Malware of this sort can get on your computer in various ways, such as through\u00a0<a title=\"Naked Security: Why Word macro malware is back and what you can do about it\" href=\"https:\/\/nakedsecurity.sophos.com\/2015\/09\/28\/why-word-macro-malware-is-back-and-what-you-can-do-about-it\/\">boobytrapped email attachments<\/a>, or by visiting a malicious website harboring malware that downloads automatically (called a\u00a0<a title=\"Sophos Blog: How malware works: Anatomy of a drive-by download web attack (Infographic)\" href=\"https:\/\/blogs.sophos.com\/2014\/03\/26\/how-malware-works-anatomy-of-a-drive-by-download-web-attack-infographic\/\">drive-by download<\/a>).<\/p>\n<p>Malware can also spread via Facebook.<\/p>\n<p>We recently learned of a hacker using a type of malware called a &#8220;Facebook Spreader&#8221; to compromise Facebook accounts via malicious links in Facebook chat messages.<\/p>\n<p>In August, a US-based hacker named Eric Crocker pleaded guilty to spreading\u00a0<a title=\"Naked Security: Hacker pleads guilty in Facebook malware and spam scheme\" href=\"https:\/\/nakedsecurity.sophos.com\/2015\/08\/19\/hacker-pleads-guilty-in-facebook-malware-and-spam-scheme\/\">Facebook malware<\/a>\u00a0to hijack thousands of accounts in order to send spam.<\/p>\n<p>Just like Facebook recommends, we think it&#8217;s a good idea to add extra layers of security to your accounts, such as\u00a0<a title=\"Naked Security: Snapchat steps up its security with login verification\" href=\"https:\/\/nakedsecurity.sophos.com\/2015\/06\/11\/snapchat-steps-up-its-security-with-login-verification\/\">login verification<\/a>\u00a0or\u00a0<a title=\"Naked Security: Two-factor authentication - understanding the options\" href=\"https:\/\/nakedsecurity.sophos.com\/2014\/11\/14\/understanding-the-options-2fa\/\">two-factor authentication<\/a>.<\/p>\n<p>Even if you&#8217;re not likely to be a target of a nation state, that&#8217;s no reason to become easy prey for common cybercriminals.<\/p>\n<h4>How to turn on Facebook Login\u00a0Approvals<\/h4>\n<p>When you turn on Facebook\u00a0<a title=\"Facebook help page on Login Approval\" href=\"https:\/\/www.facebook.com\/help\/148233965247823\" rel=\"nofollow\">Login Approvals<\/a>, you&#8217;ll need to enter a special one-time code whenever you log into Facebook from an unrecognized device or browser.<\/p>\n<p>You&#8217;ll receive the codes on your phone as a text message, so\u00a0Facebook needs your mobile phone number to send Login Notification alerts.<\/p>\n<p>Login Approvals are\u00a0similar but more secure than\u00a0<a title=\"Facebook help page on Login Notification\" href=\"https:\/\/www.facebook.com\/help\/162968940433354\" rel=\"nofollow\">Login Notification<\/a>, which alerts you when your account is accessed from a new device or browser, but without requiring a code.<\/p>\n<p>To turn on Login Approvals:<\/p>\n<ol>\n<li>Click the down arrow at the top right of any Facebook page<\/li>\n<li>Go to\u00a0Settings\u00a0&gt;\u00a0Security<\/li>\n<li>Click on\u00a0Login Approvals<\/li>\n<li>Check the box and click\u00a0Save Changes<\/li>\n<\/ol>\n<p>Finally, once you&#8217;ve set that up, make sure you\u00a0<a title=\"Change this Facebook setting so you can't be searched for by phone number\" href=\"https:\/\/nakedsecurity.sophos.com\/2015\/08\/11\/change-this-facebook-setting-so-you-cant-be-searched-for-by-phone-number\/\">change this setting so you can&#8217;t be searched for by phone number<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>by John Zorabedian on October 20, 2015 https:\/\/nakedsecurity.sophos.com\/2015\/10\/20\/facebook-to-warn-you-of-targeted-attacks-check-this-security-setting-anyway\/ Facebook has announced that it will notify users it suspects are being targeted by nation states and urge them to take extra security precautions. Alex Stamos, Facebook&#8217;s chief security officer, explained the &hellip; <a href=\"https:\/\/employee.clawsons.com\/index.php\/2015\/10\/20\/facebook-to-warn-you-of-targeted-attacks-check-this-security-setting-anyway\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a> <a href=\"https:\/\/employee.clawsons.com\/index.php\/2015\/10\/20\/facebook-to-warn-you-of-targeted-attacks-check-this-security-setting-anyway\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-690","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/employee.clawsons.com\/index.php\/wp-json\/wp\/v2\/posts\/690","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/employee.clawsons.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/employee.clawsons.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/employee.clawsons.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/employee.clawsons.com\/index.php\/wp-json\/wp\/v2\/comments?post=690"}],"version-history":[{"count":1,"href":"https:\/\/employee.clawsons.com\/index.php\/wp-json\/wp\/v2\/posts\/690\/revisions"}],"predecessor-version":[{"id":955,"href":"https:\/\/employee.clawsons.com\/index.php\/wp-json\/wp\/v2\/posts\/690\/revisions\/955"}],"wp:attachment":[{"href":"https:\/\/employee.clawsons.com\/index.php\/wp-json\/wp\/v2\/media?parent=690"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/employee.clawsons.com\/index.php\/wp-json\/wp\/v2\/categories?post=690"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/employee.clawsons.com\/index.php\/wp-json\/wp\/v2\/tags?post=690"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}