How to Outsmart the Hackers
In today’s society social media is becoming an important tactic in the marketing field. Brands are creating social platforms to encourage consumer engagement and to create two-way conversations will strengthen loyalty and relationships. When creating new pages that represent a brand it is important to understand how to keep your profiles private.
Passwords
It is important to always create a strong, complex password that is unique to each account. These passwords should be a mix of numbers, letter (upper and lowercase) and characters and have no relation to any of your personal information such as your birthday, hometown, maiden name or answers similar to your account's security questions. The more characters in your password, the harder it is to hack, so try and keep your passwords to a minimum of 8 characters. “An eight-character password with numbers, symbols and mixed-case letters is harder to guess...it has 30,000 times as many possible combinations than an eight-character password with only lower case letters” (Google, n.d.).
Safety & Security
With all of the posts showing up on newsfeeds it is important to watch what you click on. It is important to note that “social networking sites don’t have spam filters” (Readability, 2013). Never click on any suspicious advertisements or links, even if it is from someone in a private direct message. Links that are engaged with may infect your accounts and even devices letting hackers gain access to your personal and “private” information.
Policies & Practices
Upon hiring a new employee or launching a new social platform brands should create a social networking policy or guideline. It should not only explain how employees should engage with consumers on their platforms but also how to maintain brand pricy and deal with any crisis issues that may arise.
They Were Hacked, You Can Be Too
In 2013, Jeep’s twitter account was hacked and had posted a tweet “WELCOME BACK CADILLAC #300,” claiming they were sold to Cadillac along with statuses stating that Jeep employees were taking part in illegal activities. Hackers were posting images, spam links and statuses that were damaging the brand image and changed their background imaged to a car painted with McDonald's colors and logo. Jeep reported their issue to Twitter right away and luckily regained access and control to their account soon after (Grandoni, 2013).
References
Google . (n.d.). Creating a strong password. Retrieved February 20, 2017, from https://support.google.com/accounts/answer/32040?hl=en
Grandoni, D. (2013, February 19). Jeep Twitter Account Hacked Day After Similar Attack On Burger King. Retrieved February 21, 2017, from http://www.huffingtonpost.com/2013/02/19/jeep-twitter-hack_n_2718653.html
Readability. (2013, January 27). Social Networking Security Information Security Guide. Retrieved February 20, 2017, from https://www.readability.com/articles/n9zxcx3x


Kerstin, thanks for bringing up the hack on Twitter. During the same time that Jeep was affected, other companies such as Facebook. As reported by Julia Boorstin for CNBC “Facebook revealed they were hacked but user data was not compromised” (Boostin, 2013).
ReplyDeleteHow did this happen?
“Facebook said that a handful of employees visited a compromised mobile developer website. That compromised website allowed malware to be installed on their laptops” (Boostin, 2013).
We are all at risk.
“Thwarting what experts call “advanced, persistent threats” from cyber intruders is now a reality for all CEOs and business owners. The key, experts say, is understanding how systems can be hacked, and the steps to take to prevent it from happening” (Abrams, 2012). So how does a company defend itself against a cyber-attack?
For companies some of the same defense procedures as the same as for individuals. “This means ensuring that all employees are using strong passwords, changing passwords regularly, ensuring antivirus software is automatically updated on all machines and ensuring the latest version of your operating system’s software is installed” (Abrams, 2012).
In addition to the hardware protocol, having a strict network user’s policy is one of the best defenses. This needs to be strictly followed by employees as well as any “out-sourced services to third parties” (Abrams, 2012).
“For more information on how to protect your intellectual property from cybertheft, please visit the following websites:
¥ Department of Homeland Security
¥ Cyber Security Technical Resources and Incident Reporting
¥ Federal Bureau of Investigation
¥ Cyber Crime Alerts and Reporting
¥ United States Computer Emergency Readiness Team
¥ Security Publications, Alerts, and Tips
¥ National Security Agency Central Security Service
Cyber Security Guide” (Abrams, 2012)
Reference
Abrams, M. (2012, July 8). How to Defend Against a Cyberattack. Retrieved from http://www.cnbc.com/id/48097849
Boorstin, J. (2013, February 15). Facebook Reveals Hack Attack, Says User Data Not Compromised. Retrieved from http://www.cnbc.com/id/100464999
Hi Monica,
DeleteI did some additional research on Facebook being hacked in 2013 and came across this CNN article, "Zuckerberg's Facebook page hacked to prove security flaw." It explains that a Palestinian security researcher, Khalil Shreateh, found a flaw in Facebook's security systems that allowed him to post to any user's profile page whether they were accepted friends or not. This one flaw would have been a "gold mine" for spammers and scan artists "seeking to take advantage of the site's roughly 1 billion users worldwide" if it weren't for Shreateh reporting it to Facebook (Gross, 2013).
During this article Gross also brought up the topic of language barriers when it comes to reporting spam, security and privacy issues on Facebook. "We get hundreds of reports every day. Many of our best reports come from people whose English isn't great -- though this can be challenging, it's something we work with just fine and we have paid out over $1 million to hundreds of reporters" (Gross, 2013).
I spoke about creating guidelines and policies and how brands should include a crisis communication plan. After reading Gross's article I would also include language barrier communication plans to the list.
Reference
Gross, D. (2013, September 20). Zuckerberg's Facebook page hacked to prove security flaw. Retrieved February 23, 2017, from http://www.cnn.com/2013/08/19/tech/social-media/zuckerberg-facebook-hack/
Hi Kerstin, that was an interesting article with a different twist that really highlights the fact that companies need a global view for risk and reward and with that comes the communication and language challenges.
DeleteI also wanted to address your crisis communication plan further. “Social media adds an overwhelming complexity to crisis communication. The multiple channels, user-level control of messaging, and real-time delivery make social media far more complex than press releases and conferences” (Dougherty, 2015). Even though during a crisis all of the communication basics such as honesty and empathy should be followed on social media, it’s important to be prepared prior to the crisis. Writing a plan that includes social media is an important aspect to not only help deal with the risks, but also how you will be available for media outreach. (Dougherty, 2015)
As Dougherty stated “social media for crisis communication isn’t intended to directly communicate with everyone you’re socially connected to. It is to provide resources and accessibility to the journalists and key influencers who amplify your message, and it is for stakeholders that need a place to find information” (Dougherty, 2015). He went on to note how important it was to use monitoring tools, particularly during a crisis. This becomes the best way to collect data and analyze what is taking place.
Reference
Dougherty, J. (2015, June 8). 6 Social Media "Musts" for Crisis Communication | Cision. Retrieved from http://www.cision.com/us/2015/06/6-social-media-musts-for-crisis-communication/
Hi Monica,
DeleteIt is definitely important to be prepared before a crisis on social media takes place. We live in a society where everyone is connected at all times and are receiving real time information upon opening social media applications. This makes it very easy for comments to quickly go viral. Creating a plan (which includes monitoring, responding and evaluating) prior to any situations ensures that a brand can respond quickly and resolve the issue before it gets out of hand and damages their image and reputation.
"People don’t often swing from anger back to neutral, but an angry customer can become a loyal fan if the problem is resolved quickly, empathetically and effectively" (Forbes Agency Council, 2016).
Reference
Forbes Agency Council. (2016, September 09). How To Use Social Media To Improve Crisis Communications. Retrieved February 24, 2017, from https://www.forbes.com/sites/forbesagencycouncil/2016/09/09/how-to-use-social-media-to-improve-crisis-communications/#9510977b910e
That XKCD comic is a great example of password security. Unfortunately, a combination of dictionary-based hacking software and people’s inability to choose two or more actually unrelated words usually makes the complex passwords a better choice.
ReplyDelete"To understand why passphrases failed to live up to their potential, the researchers extracted two-word phrases from sources including the British National Corpus and compared them to the phrases they had cracked from Amazon's PayPhrase system. They found most of the overlap involved common nominal modifier-noun phrases such as "bedtime story" or adverbial-modifier verb relations such as "never leave” (Goodwin, 2012).” MIT offers tips on how to tweak the passphrase formula to make very strong passwords (2016). The 1Password app (https://1password.com/) will generate pass phrases for you that are truly random… I did a test and it generated “epicycle fine vassar left” and
"fistful ends soap softly”. This app will generate pass phrases as long as ten words. It would take lifetimes for a hacker to figure out “moot baritone theatre mace cassava optimism reformer manure belabor pisces” to access your account.
This site has good information about the entropy [security] of a password and common password faults based on a study of leaked passwords... http://wpengine.com/unmasked/ I found seeing the passwords they were able to match to people at tech companies after the leak very insighful, especially since it shows the time it would take to crack each of those passwords (noticeably the IMB senior manager with "123456" which could be guessed in 0 seconds, or the Yahoo journalist with "abc123" with a crack time of 0.001 seconds). A GitHub developer who's complex password has a crack time of centuries if it wasn't for the data leak shows the benefit of changing passwords every few months.
Goodwin, D. (2012, March 14). Passphrases only marginally more secure than passwords because of poor choices. Retrieved from https://arstechnica.com/business/2012/03/passphrases-only-marginally-more-secure-than-passwords-because-of-poor-choices
MIT (2016, May 16). Strong passwords. Retrieved from http://kb.mit.edu/confluence/display/istcontrib/Strong+Passwords
Victoria, thanks for sharing that 1password app! It sounds like a great resources to use. I plan on being more secure after taking this class!
DeleteHi Victoria,
DeleteThanks for sharing those two resources. A brand that I used to freelance for would require us to change our passwords every 30 days. New passwords were generated through application and were a long combination of upper/lowercase letters, numbers and characters. Just as I would begin to memorize my password it was time for a new one. After this weeks topic on security I now realize how important it was for the brand to carry out this procedure, as inconvenient as it was for us to relearn passwords.
In addition, I found the topic of keyboard patterns to be very interesting. We "are addicted to patterns, and therefore certain assumptions can be made about most of [our] passwords" (Wpengine, n.d.). By avoiding keyboard patterns in a password such as qwerty, asdf, or bbbbbb (repetition of a letter), it becomes much stronger and more difficult to hack.
Reference
Wpengine. (n.d.). Unmasked. Retrieved February 24, 2017, from http://wpengine.com/unmasked/
I am interested to see your view on developing a social media policy for an organization and its employees. I believe that this is a multi-layered issue.
ReplyDeleteOne component should address the best practices for those that represent or will officially represent the brand on social media platforms - how to be consistent in messaging and imaging, language style and content delivery. I think that staying on message visually and through content delivery is key in building and maintaining a successful brand.
I also believe a separate set of expectations should be given to those that do not represent the organization, but are employed or affiliated with the organization. We haven't really spoken about it much, but organizations must be careful on any restrictions they place on their employees that might infringe on free speech or labor regulations. "Employers retain the right to prohibit sexual harassment, workplace violence and threats of violence, sabotage, and/or abusive and malicious activity. And employers also may limit employees’ use of social media at work, during working time, and/or on company equipment. Finally, even if employees are engaging in protected concerted activity, an employer can suggest that they should exercise good judgment and caution employees that if their conduct violates the rights of other employees or third parties, it may result in liability to these individuals" (National Law Review, 2012).
As an employer or social media manager, it may be very difficult to exact a policy that might be comprehensive yet still allow for open engagements through social media. The question arises, what's good for the brand - employees that engage the public frequently or those that are limited in the content and time they are permitted to engage?
When is Your Company's Social Media Policy an Unfair Labor Practice? Recent NLRB Decisions Offer Long-Awaited Guidance for Employers. (2012, December 3). Retrieved from http://www.natlawreview.com/article/when-your-company-s-social-media-policy-unfair-labor-practice-recent-nlrb-decisions-
Hi Michael,
DeleteWhen it comes to creating a social media policy for an organization and its employees I do agree with including best practices for representing a brand. Employees need to be on the same page when it comes to portraying a brands voice and image and maintain consistency across all of their platforms. In my opinion all employees should be trained if engaging with a brands social media platforms in addition to understanding the guideline file.
When it comes to social media policies regarding engagement during work and interaction on the pages, I believe policies need to cater to each brand. Such policies depend on the brands work environment but also have to take into consideration National Labor Relations Act. As the NYC Department of Education states they "provide recommended practices for employees to take advantage of this technology [social media] in a manner that encourages professionalism, responsibility, safety, and awareness...these guidelines provide recommended best practices for employees who use social media for personal communications" (NYC Department of Education, n.d.).
Reference
NYC Department of Education. (Spring 2013). Retrieved February 25, 2017, from http://schools.nyc.gov/NR/rdonlyres/BCF47CED-604B-4FDD-B752-DC2D81504478/0/DOESocialMediaGuidelines20120430.pdf