<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:www.readwriteweb.com,2011:/1/tag:www.readwriteweb.com,2009://1.15510-</id>
  <updated>2011-08-16T17:04:09Z</updated>
  <title>Comments for Warn Users of Malware on Facebook - Get Banned?</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.35-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2009://1.15510</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=15510" title="Warn Users of Malware on Facebook - Get Banned?" />
    <published>2009-06-25T18:19:33Z</published>
    <updated>2009-06-26T12:11:50Z</updated>
    <title>Warn Users of Malware on Facebook - Get Banned?</title>
    <summary>Looking for a good conspiracy theory today? Well here&apos;s one: Chris Almond, the administrator of a Facebook group called the Rogue Facebook Apps Early Warning Group just got kicked off the social network. Why did this happen? Did Facebook not like how he was posting details about Facebook malware, hacks, and attacks? Attacks like this...</summary>
    <author>
      <name>Sarah Perez</name>
      
    </author>
    
    <category term="Facebook" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img src="http://www.readwriteweb.com/images/facebook_rogue_apps_group.jpg">Looking for a good conspiracy theory today? Well here's one: <a href="http://twitter.com/likeallstars">Chris Almond</a>, the administrator of a Facebook group called the <a href="http://www.facebook.com/group.php?gid=52631326657">Rogue Facebook Apps Early Warning Group</a> just got kicked off the social network. Why did this happen? Did Facebook not like how he was posting details about Facebook malware, hacks, and attacks? Attacks like <a href="http://theharmonyguy.com/2009/06/22/illustrating-facebook-privacy-problems/">this recent one</a> that exposed private Facebook profile information just by clicking on a link?</p>

<p>Or was Facebook simply following through on a TOS violation because Chris had accidentally sent out duplicate messages to group members, thereby getting flagged as a spammer and subsequently booted from the network? </p>

<em><strong><p>You decide. </p></strong></em>]]>
      <![CDATA[

<h2>First Rule of Facebook: Don't Talk about Hacks on Facebook!</h2>

<p>On Monday, the anonymous blogger over on Social Hacking <a href="http://theharmonyguy.com/2009/06/22/illustrating-facebook-privacy-problems/">posted a link</a> that demonstrated a gaping hole in Facebook which revealed private profile data upon clicking. The hack worked <em>(I tried it at the time)</em> although now the hole has been closed. He later revealed the <a href="http://theharmonyguy.com/2009/06/23/initial-details-on-facebook-attack/">technical</a> <a href="http://theharmonyguy.com/2009/06/24/facebook-attack-technical-details/">details</a> of this hack on his blog. </p>

<p>However, even before those technical explanations were posted, Chris Almond was spreading the word via the <a href="http://www.facebook.com/group.php?gid=52631326657">Rogue Facebook Apps Early Warning Group</a>, a group whose members like to stay informed about the latest and greatest threats happening on the social network. All he was doing was publicizing the information - he was not involved in the hack's creation in any way. </p>

<p>Shortly after sharing the information with the group, Chris found his account was disabled. </p>

<p>And because it was disabled, Chris's collection of links and articles he had posted since the group's creation in 2009 as well as all the discussions he had with other group members were gone, too. The group's archive was emptied out.</p>

<p>Does that sound suspicious to you? TheHarmonyGuy (aka Mr. Anonymous from <a href="http://theharmonyguy.com/">Social Hacking</a>) thinks so. <a href="http://theharmonyguy.com/2009/06/24/account-shutdown-seriously/">He writes</a>, "While I hope I'm wrong (and I very well could be), it appears that at least part of the reason for the account shutdown was that this user was spreading word about my Facebook attack. It saddens me that other people are having to suffer on my account..."</p>

<h2>Flip Side: Just a Simple TOS Violation?</h2>

<p>Of course, there are always two sides to any story and this story is no exception. In Facebook's defense, Chris Almond was guilty of a TOS (<a href="http://www.facebook.com/terms.php">Terms of Service</a>) violation. You see, Chris had decided to send out personal emails to group members with information about the hack and to invite them to a group event. Unfortunately, he accidentally sent out duplicate emails to some of the group's members. </p>

<p>This triggered Facebook's spam detection feature - most likely an automated system that detects such behavior on the part of group admins. Chris received the warning and realized his mistake. Though accidentally, he <em>had</em> in fact violated Facebook's TOS. He stopped sending any further messages after receiving the message.</p>

<p>But apparently, it was too late for contrition because Facebook soon thereafter disabled his account. </p>

<p>At the moment, Chris is busy pleading for reinstatement. He has sent Facebook the following emails to state his case:</p>

<p><strong><u>Email 1</u></strong></p>

<p><em>Hello</em></p>

<p><em>My Facebook account, registered with this email account [EMAIL ADDRESS REMOVED] has been disabled.</em></p>

<p><em>I'm not going to argue that I didn't violate terms of use, only that I did so unknowingly and in completely good faith.</em></p>

<p><em>Please allow me to explain my activity that led to the disabling. I am admin of a group called Rogue Facebook Apps Early Warning Group. I wished to send an invite to members to a group event I'd created in which information about facebook security issues was shared, containing links to a site that after personal contact with the author I am satisfied is legitimate and non-threatening.</em></p>

<p><em>Here is the link I shared: </em><a href="http://theharmonyguy.com/2009/06/22/illustrating-facebook-privacy-problems/"><em>http://theharmonyguy.com/2009/06/22/illustrating-facebook-privacy-problems/</em></a></p>

<p><em>Due to the size of the group, it was impossible to send a group invite, so I decided to personally message members of the group who had posted on the wall. My reasoning was that they were voluntary members of the group and so this was probably an acceptable course of action. Obviously I was wrong about that.</p>

<p>I have been corresponding recently with Ryan Merket of Facebook platform team about the group. Hopefully he will be able to vouch for my good intentions.</p>

<p>I assume that somebody to whom I sent a message has reported my activity as spam. I can certainly see, in light of what has happened, that it could be construed as such but my intention was to share information about Facebook security awareness, and absolutely not to trouble anyone at all.</em></p>

<p><em>Please reinstate my account. I run a small business, promoting music in my local area, and my business will suffer if I can't use facebook for that purpose.</em></p>

<p><em>Yours contritely</em></p>

<p><em>Chris Almond</em></p>

<p><strong><u>Email 2</u></strong></p>

<p><em>Hello</em></p>

<p><em>I wrote the other day about how I'd shared a link with members of the Facebook group I co-administrate, and how that action has led to the disabling of my Facebook account registered with [EMAIL ADDRESS REMOVED]</em></p>

<p><em>I don't know if the manner in which I distributed the message or its contents were the main transgressions in your opinion. I accept that by duplicating a message I triggered an automatic spam alert, and I sincerely regret that particular course of action. Please note, I stopped sending the messages as soon as the first warning appeared.</em></p>

<p><em>The link itself was to a hack, described here by its author </em><a href="http://theharmonyguy.com/2009/06/24/facebook-attack-technical-details/"><em>http://theharmonyguy.com/2009/06/24/facebook-attack-technical-details/</em></a></p>

<p><em>The purpose of the Facebook group I help to run, Rogue Facebook Apps Early Warning Group, is to spread awareness about the weaknesses in Facebook platform that allow unscrupulous Facebook app developers to access users' private information without their explicit authorisation. I am not a hacker, nor particularly technically informed in that area, but I am somebody who is concerned by the implications of such weaknesses. Neither am I, as my group co-admin erroneously stated in an email to you yesterday, working with theharmonyguy. I merely follow his work and believe that the kind of activism he engages in is an honorable, and practical way, of encouraging greater security on Facebook.</em></p>

<p><em>A hallmark of my personal experience of Facebook is the worrying amount of applications that find their way onto my account without my permission. Error Check System, the notorious app attack of February 2009 that led to the formation of our group, was merely one of the most aggressive, visible, and widely remarked-upon.</em></p>

<p><em>I don't publish sensitive personal info on my account, but many do, and I believe it is legitimate behavior to be proactive in spreading awareness of the issue.</em></p>

<p><em>Having accepted that the sending of duplicate messages is in contravention of the Facebook terms of use, I must say it is intolerable that I have been singled out for suppression when, over the course of my time using Facebook I have seen many groups containing material that by any reasonable assessment is racist, homophobic, or in some other regard hate-filled and offensive, and whose admins are allowed to continue their activities.</em></p>

<p><em>I am not a spammer. I have never, before this incident, done anything that could be viewed as spamming. I accept that I was naïve in the way I went about promoting the activities of my group. I do not think that what I did warrants permanent expulsion from the Facebook community, and I hope you will agree.</em></p>

<p><em>Yours sincerely</em></p>

<p><em>Chris Almond</em></p>

<h2>What Do You Think?</h2>

<p>So is this a clear-cut case of a Facebook TOS violation being acted upon? Or was Facebook just <em>looking </em>for an excuse to shut this group down? Surely they couldn't have liked the fact that Facebook users were using their very own platform to share news and links about ways to attack Facebook! Still, there wasn't anything Facebook could do about it...unless somebody crossed the line, of course. </p>

<p>Luckily for us, Facebook has not yet succeeded in completely destroying this group. The Rogue Apps Early Warning group itself lives on thanks to co-admin, Stuart Forbes, who is now in charge of the group's activities. Chris's account is currently still suspended.</p>

<p><strong>UPDATE:</strong>After this article was published, Facebook reactivated Chris's account. </p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.15510-comment:174397</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.15510" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php#c174397" />
    <title>Comment from Orlando on 2009-12-14</title>
    <author>
        <name>Orlando</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>They know that banning him was wrong. It just took a little light shined on the situation for them to do anything about it. Firefox did the same thing recently when a user on their boards was spreading the word about vulnerabilities in the browser. They claimed that he was encouraging <a href="http://www.sophos.com/products/malware-protection/" rel="nofollow">malware</a> and banned him from the boards...All he was doing was trying to get community input on closing the holes. These companies hsould maybe not make their software so vulnerable in the first place instead of taking out their rage on innocent users who are actually on their side! </p>]]>
    </content>
    <published>2009-12-14T15:43:43Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.15510-comment:155845</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.15510" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php#c155845" />
    <title>Comment from pcfixpoint on 2009-09-03</title>
    <author>
        <name>pcfixpoint</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>I think so but i am not sure.</p>]]>
    </content>
    <published>2009-09-03T22:23:40Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.15510-comment:145270</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.15510" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php#c145270" />
    <title>Comment from bedava film izle on 2009-07-03</title>
    <author>
        <name>bedava film izle</name>
        <uri>http://www.bedavafilmizlesene.org</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.bedavafilmizlesene.org">
        <![CDATA[<p>evet bakalım post atabilecezmi</p>

<p>Do you have sex with a creature that I think yahu crocodile öp bakalım elimi</p>]]>
    </content>
    <published>2009-07-03T20:06:25Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.15510-comment:145011</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.15510" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php#c145011" />
    <title>Comment from netlog on 2009-07-02</title>
    <author>
        <name>netlog</name>
        <uri>http://www.sevdaduragi.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.sevdaduragi.com">
        <![CDATA[<p>Do you have sex with a creature that I think yahu crocodile hadi bakalım kolay gelsin</p>]]>
    </content>
    <published>2009-07-02T12:23:22Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.15510-comment:145008</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.15510" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php#c145008" />
    <title>Comment from cet on 2009-07-02</title>
    <author>
        <name>cet</name>
        <uri>http://www.kerizimcet.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.kerizimcet.com">
        <![CDATA[<p>Do you have sex with a creature that I think yahu crocodile öp bakalım elimi</p>]]>
    </content>
    <published>2009-07-02T12:20:27Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.15510-comment:145007</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.15510" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php#c145007" />
    <title>Comment from hikayeler on 2009-07-02</title>
    <author>
        <name>hikayeler</name>
        <uri>http://www.sevdaduragi.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.sevdaduragi.com">
        <![CDATA[<p>Do you have sex with a creature that I think yahu crocodile taherr</p>]]>
    </content>
    <published>2009-07-02T12:18:53Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.15510-comment:144154</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.15510" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php#c144154" />
    <title>Comment from Youngistaan on 2009-06-26</title>
    <author>
        <name>Youngistaan</name>
        <uri>http://youngistaan.org</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://youngistaan.org">
        <![CDATA[<p>Thanks nice post.</p>]]>
    </content>
    <published>2009-06-26T12:01:08Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.15510-comment:144153</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.15510" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php#c144153" />
    <title>Comment from Pallab on 2009-06-26</title>
    <author>
        <name>Pallab</name>
        <uri>http://www.pallab.net</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.pallab.net">
        <![CDATA[<p>Yeah. You guys may want to upadte the story since he says that his FB account has been reinstated.</p>]]>
    </content>
    <published>2009-06-26T11:26:27Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.15510-comment:144121</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.15510" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php#c144121" />
    <title>Comment from Ricky on 2009-06-25</title>
    <author>
        <name>Ricky</name>
        <uri>http://www.iyogi.net</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.iyogi.net">
        <![CDATA[<p>Warn users of Malware on Facebook? Of course you get banned!!<br />
You ruined the whole element of surprise that the Facebook team worked so hard to get.</p>]]>
    </content>
    <published>2009-06-26T04:10:37Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.15510-comment:144114</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.15510" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php#c144114" />
    <title>Comment from theharmonyguy on 2009-06-25</title>
    <author>
        <name>theharmonyguy</name>
        <uri>http://theharmonyguy.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://theharmonyguy.com/">
        <![CDATA[<p>Chris has posted on his Twitter that his Facebook account has been reactivated; no word yet if Facebook gave any explanation of their actions to start with.</p>]]>
    </content>
    <published>2009-06-25T23:52:58Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.15510-comment:144113</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.15510" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php#c144113" />
    <title>Comment from &quot;her&quot; on 2009-06-25</title>
    <author>
        <name>&quot;her&quot;</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>TOS my ass.  plenty of blocked group leaders / owners still spamming the living daylights out of me on the daily, somehow doubt facebook "got lucky" and managed to "stumble upon" someone who was posting information they felt was inappropriate (exposing their already well-known weaknesses to users who are encouraged, by the website, to put as much personal information on their facebook profile as possible.)</p>

<p>for the record, i am one of the few people Mr. Almond sent an invitation to for this "event."  i did not receive duplicates of anything.  i've been receiving event invitations from Mr. Almond for the better part of the past five months, and never once has he duplicated any kind of invitation.  perhaps if this duplication of invitations is possible on facebook, facebook needs to address the internal technical issue at hand as opposed to slapping well meaning, registered users on the wrist.</p>]]>
    </content>
    <published>2009-06-25T23:45:56Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.15510-comment:144100</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.15510" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/warn_users_of_malware_on_facebook_-_get_banned.php#c144100" />
    <title>Comment from fiend.s2r.org on 2009-06-25</title>
    <author>
        <name>fiend.s2r.org</name>
        <uri>http://www.soundcult.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.soundcult.com/">
        <![CDATA[<p>hummm, well i think a guy running a group about spam/malware and such should know better (than a regular user) to abuse facebook TOS and system, sure its not the end of the world and the facebook people should bring back his account (cause everyone wants happiness), but if i was part of a group and i put on my privacy/personal settings that i don't want msg's from any group and then i get a msg from the group owner, for sure i'm gonna report it as well and hope that person gets banned too... ^_^ .oO( i think that the suggestion that the group subject has anything to do with him being banned is just "conspiracy" hehehe, if facebook people don't want a group they delete the group not go after the owners and users )</p>]]>
    </content>
    <published>2009-06-25T20:13:22Z</published>
  </entry>

</feed>
