« Understanding SQL Injection the Hard Way | Main | Zeus "Kneber" Botnet Cache Discovered »
Wednesday
Feb242010

Can't Login to Facebook...

ReadWriteWeb wrote a blog post titled "Facebook Wants to Be Your One True Login". Google indexed the page, so it quickly appeared at the top of search engine listings for "Facebook login". Amazingly, a rather large number of people landed on the blog from Google searches, didn't realize they weren't on the Facebook login page, and began leaving comments. Here's a sampling:


#
Ok If I have to I will comment,I love facebook so right now just want to log in if thats ok with you..lol Keep up the good work...
#
I just want to sign in............
#
I just want to log in to Facebook - what with the red color and all? #
#
I was just learning,why would you mess it up?
#
ok cool now can I get to facebook
#
wtf is this bullshttttttttttt all about. can i get n plzzzzzzzzz
#

Reading the comments, linguistically the majority of the "lost loggers" appear to be younger. This would be a generation that grew up with a "Popcorn" button on the microwave. And it begs the quite serious question, if the popcorn button failed, would they know how to pop it any other way? I don't mean using a stove, a pan, and some oil either - but simply the ability to program in the right amount of time?

I ask this because the thread, funny at times but mostly quite sad, indicates that a large number of Web surfers have no understanding of even the very basics of their Web browser. And because they are used to accessing sites via search engines, they aren't at all familiar with the address bar - much less how a URL is formed.

If users don't understand the basics of how a normal URL is formed, how can they ever recognize a malformed URL that points to a phishing site? Likewise, if these users cannot distinguish a valid search engine listing for Facebook from a listing for a blog discussing Facebook, how can they even begin to decipher spamdexing listings?

And if they can't do any of the above, how will those of us in the security industry ever be able to help them understand the sophisticated and highly criminal attacks that are taking place via the Web today? Because while it might be tempting to chuckle at these users' lack of basic understanding of how the Web works, the thing is that most of them probably have jobs. They could even be working in your own enterrpise. And it's your intellectual property that's at stake. And it's these very same users that might be the only thing standing between your sensitive data and those that would steal it.

It's not funny. It's downright scary.

Reader Comments (12)

Ok, this was great. Will you log me into facebook now, name is fbrocks4me and my password is iamsuchadolt

February 26, 2010 | Unregistered CommenterFBRules

Thanks for sharing the article - and have you noticed the new bold entry addressing "how to actually get to facebook" on the article's site? I was going to discuss this on my tech-related radio talk show, and while I would love to sit here and make fun of these inept users, you've forced me to be terrified of them instead.

March 2, 2010 | Unregistered CommenterPixie

I just want 2 log in 2 scansafe. Why u have no login box?

March 2, 2010 | Unregistered Commenterclueless user

Amm, what's with the above? I'm just trying to sign in... err I mean :-D Seriously though, this spells good tidings for us of the blackhat persuasion.

March 2, 2010 | Unregistered CommenterReow

Okay, this isn't funny. I'm trying to log into facebook and they've changed everything! What are these Create Post and Preview Post buttons for and why did facebook change its name to scansafe? Ughhh!

March 2, 2010 | Unregistered CommenterZach

What's with the new colors? All I want to do is log into Slashdot. Can I PLEASE log into Slashdot? Keep up the good work!!!

March 2, 2010 | Unregistered Commenterfunlover96

So, where's the login to enter Facebook?

March 2, 2010 | Unregistered CommenterBob

I wanted to get to ReadWriteWeb blog, where is it?

March 3, 2010 | Unregistered Commentermichael

Jesus Christ. Those comments are a maddening combination of hilarious and sickening. The more I read the more I want to scream at them.

March 3, 2010 | Unregistered CommenterLuke

Ok, I don¡t know what's this about I just want to log in to facebbok, where's the login buttons?

March 3, 2010 | Unregistered CommenterPopcorn Kid

This is all very nice, but how do I login to facebook now?

;-)

March 3, 2010 | Unregistered CommenterDave

Not Again! When will facebook stop making these drastic weekly UI updates? I can't find my wall for the past few days :( Though I must say that scan safe logo looks promising now. At least they're putting up some anti virus stuff on the website.

March 4, 2010 | Unregistered CommenterSmartass

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>