This story was first published on April 7, 2011
A rather breathless, ALL CAPS, warning message that is currently rocketing around Facebook, warns users to watch out for an alert with a padlock icon on their Facebook pages that informs them that their security is low. According to the message, answering questions asked by the security alert will give hacker’s access to your Facebook account. A later variant claims that attempting to click the “X” to delete the padlock will, in fact, launch a virus. The message asks recipients to repost the information as a warning to others.
However, the claims in the “warning” are nonsense and should not be taken seriously. Some Facebook users may have indeed noticed a “low security” alert on the right of Facebook pages. As shown in the screenshot on the right, the alert does include a padlock icon. However, this is a perfectly legitimate security feature that was introduced by Facebook in 2010. If you click on the “Increase protection” link in the alert, you will be taken to an “Update Your Security Information” page that allows you to choose options and answer questions intended to increase the security of your account.
Clicking the “Increase protection” link or answering the subsequent security questions certainly will not give hackers access to your account. Nor will it launch any kind of “virus”. In fact, the feature is intended to make it more difficult for criminals to hijack Facebook accounts.
When the security feature was first launched in late 2010, Sophos security expert Graham Cluley was critical of how it was implemented. In a December 2010 blog post, he raised concerns that the wording and method of promoting the feature could be misleading and cause unnecessary concern among users. He also questioned the effectiveness of the security measures suggested by the Facebook feature.
However, while Cluley’s concerns are certainly worth considering, they do not give any validity whatsoever to the bogus warning above. Even if Facebook’s implementation of the feature is somewhat flawed, using it certainly does not allow hackers (or viruses) to hijack your account.
Reposting such nonsense is entirely counterproductive. Sending on the warning may cause users to ignore a legitimate security enhancement thereby potentially increasing their vulnerability to attack. If you see this message, please do not repost it to others. And please let the poster know that the information in the warning is untrue.
Examples of the hoax messages:
HACKERS ALERT….. ATTENTION!!!!! IF ANY OF YOU GET A PADLOCK ON TOP RIGHT HAND CORNER OF FACEBOOK HOME PAGE SAYING YOUR SECURITY IS LOW.. IGNORE.. DO NOT, DO NOT, DO NOT ANSWER THE QUESTIONS.. IT IS SO HACKERS CAN ACCESS YOUR ACCOUNT. COPY & PASTE PLEASE DO NOT CLICK ON THE X TO DELETE, IT CAN BE PROGRAMED. PUSH ALT, CONTROL, DELETE, THEN END TASK…… IF YOU PUSH THE X IT CAN OPEN THE VIRUS…..
ATTENTION!!!!! IF ANY OF YOU GET A PADLOCK ON TOP RIGHT HAND CORNER OF FB HOME PAGE SAYING YOUR SECURITY IS LOW.. IGNORE.. DO NOT, DO NOT, DO NOT ANSWER THE QUESTIONS.. IT IS SO HACKERS CAN ACCESS YOUR ACCOUNT COPY & PASTE PLEASE!