WASHINGTON: Most folks who use it are aware that the Internet, especially social networking websites, can be hazardous due to hackers. The Indian Army issued a warning earlier this year stating, "All professional info must be taken off the internet immediately and defense personnel must be careful while posting pictures that may disclose their whereabouts, or any other professional info on public forums."
Now, on Monday, the US Marine Corps banned social networking sites including, Twitter, Facebook and MySpace, "effective immediately." The Marine Corps order noted that social networking sites "in general are a proven haven for malicious actors and content and are particularly high risk due to information exposure, user-generated content and targeting by adversaries."
The order also noted that social networking sites expose unnecessary information to adversaries and give them an easy conduit for information that puts operations security and communications security at an elevated risk of compromise.
"The very nature of SNS (social network sites) creates a larger attack and exploitation window, exposes unnecessary information to adversaries and provides an easy conduit for information leakage that puts OPSEC (operational security), COMSEC (communications security), (and) personnel at an elevated risk of compromise," said the USMC order.
The Marines' ban will last a year. It was drawn up in response to a late July warning from US Strategic Command, which told US military leaders that it was considering a Defense Department-wide ban on the Web 2.0 sites due to network security concerns. Scams, worms, and Trojans often spread unchecked throughout social media sites, passed along from one online friend to the next. So the Pentagon is now reviewing its social networking policy for the entire Department of Defense; the review should be completed by the end of September. This is important, as the policy for the entire military is somewhat fragmented: the US Army ordered military bases to allow access to social media sites in May.
So, just how much of a security threat are social networking sites? Experts at security vendor Sophos have noted that Facebook, MySpace, LinkedIn and Twitter have all experienced attacks during 2009 designed to compromise PCs or steal sensitive information.
About 63% of 709 system administrators polled by Sophos in February 2009 worried that employees were sharing too much personal information on their social networking profiles and, as a result, putting sensitive corporate data at risk. Criminals are also getting more sophisticated in using social media sites to spread malicious code, or malware. They use Twitter, for instance, to try to get people to click on bad links.
"If a user clicks on a link in Twitter and installs malware on an enterprise PC, that's bad," Patrik Runald, chief security advisor at F-Secure, a provider of online security services, told reporters. The fear is that the malicious code will then give hackers a back door to enter a corporate or military network. In fact, the Sophos survey revealed that 21 percent of respondents had been the victim of targeted malware or phishing attacks, designed to get victims to reveal sensitive information. Security experts say that once malicious code is installed on a corporate network, it can be difficult to spot. In some cases, it can run undetected for months.
The ban, authorized by Brig. Gen. G.J. Allen, the Corps' chief information officer, does allow for special waivers for access if usage of the sites is "mission critical." But now that the Pentagon is going through a general review of security threats on social networks, what is to be done with some of its senior brass, including Adm. Mike Mullen, Chairman of the Joint Chiefs of Staff, who uses the technology? Adm. Mullen has 4,364 followers on Twitter and, according to one of his recent tweets, he "recently finished reading 'The Bookseller of Kabul.'"



