Proofpoint: Security, Compliance and the Cloud

January 13, 2010

Facebook Enables Commenting by Replying to Notification Emails: Will this be Exploited to Harvest Email Addresses?

Facebook has enabled replying to comments through email (see Facebook's blog post on "Replying to Comments through Email" at http://blog.facebook.com/blog.php?post=206480947130 ).

Overall, I would call this a good thing as it seems to me that it might reduce the number of users who click on links in Facebook notification emails to access their accounts (which is something I'm always advising people *not* to do, since so many phishing attacks work by putting malicious/fraudulent URLs into convincing-looking social media notification emails).

Haven't spent a ton of time thinking about the various security ramifications of this new feature, but one thing I predict:

I think it's only a matter of time before we see spoofed Facebook notification phish/spam that takes advantage of this feature to harvest email addresses. (e.g., the recipient replies to the fraudulent FB notice thinking it'll publish a comment, but all it does is confirm to the spam/phish sender that, indeed, there is a valid email recipient at that address.)

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Archives

Blog Search

Email Security Gateways, 2011

Magic Quadrant

Tweets

What people are saying right now about us.

©2012 Proofpoint, Inc.
threat protection: Proofpoint Enterprise Protection compliance: Proofpoint Enterprise Privacy governance: Proofpoint Enterprise Archive secure communication: Proofpoint Encryption