
The binding of different user accounts with each other leads to the fact that the marketing company becomes easier to compare profiles and create consumer dossiers; authoritarian authorities - identify an anonymous blogger; A malicious hacker - “hack” accounts. How does the binding arise? What can you do about it? Let's try to deal with the security expert Sergei Smirnov .
Nikita has two Google accounts, corporate and personal, and three postal services “in addition” to Google. Facebook, Instagram, Twitter, two online banks, cloudy storage (landfill of photographs, it is a pity to delete, there is no time to understand). In addition, public services, tax, Internet provider - replenish the balance, mobile operator. And also the reservation services of housing and tickets, a pair of torrents (TS-SC-S!), Several professional forums, a site for webinars, two dozen online stores, some entertainment resources. Most sites are interconnected "through Nikita."
“Well, good,” Nikita thinks. -Online Bank, of course, is needed. Google, Facebook, Instagram, cloud - no question. And here is the address on mail.ru? Yes, I have not been using it for a hundred years. There is nothing important there!
The same logins help to connect accounts with a specific face. If Nikita is registered on a musical flea market with the Highway_star account, sold the guitar there and added a phone number for communication, it seems that there is no problem. But if a kind of anonymous person leads an acute political blog and publishes its messages under the pseudonym Highway_star, its ill -wishers can compare the data of two virtual personalities, and - goodbye, anonymity. Binding of accounts through logins can simplify the collection of data about a particular person.
The same password leads to the fact that, having hacked one account, the attacker will receive at his disposal and another account with the same password. In February 2019, Google conducted a survey of three thousand US inhabitants and found out that 52% used one password for several accounts, and 13% for all its accounts. Do not do that.
In the settings of the Facebook account, which Nikita uses to administer the corporate page, the email address is indicated. Facebook invited Nikita to do this to protect the account and restore the forgotten password. Nikita indicated his address to Mail.ru. Years passed. Today, Nikita prefers Gmail, sometimes Proton Mail uses, and the old Mail.ru address has long abandoned. The password there remained some simple, Nikita has not changed it for five years. There is no two -factor authentication - in those days it was not yet popular.
More on the topic: Video lesson of the greenhouse: Protect your traffic using the HTTPS EVERYWERE plugin
In the described situation, the Mail.ru account is a weak link. The calculating attacker may direct his efforts there. Having made this account, the villain will be able to “restore the password” for Facebook, as well as to any other account, where the tuned address is indicated in the settings.
Have you ever tried to log in to the site without registration, and with the help of the “enter through Facebook” link? Owners of online services love such an option because it accelerates the registration procedure and helps to keep customers. Nikita also likes: quickly, comfortably, you do not need to remember another couple of login/password.
At the “entrance through Facebook”, the application is added to Nikita's Facebook account. Go to “Settings” - “Applications and Sites”. Take a look at how many applications are installed with you and which ones. Ticket reservation systems, discussion platforms, online tests ...
Nikita has twenty -eight applications. If the attacker receives access to Nikita Facebook, he will be able to enter any of these sites, see the profile settings and saved data, perhaps perform some actions from this account.
Each application has a set of permits for processing Nikitin data on Facebook. For example, name, photo, city of residence, email address. Some applications can go further and become interested, say, your list of friends. If you click the mouse on the application icon, you will see these permits.
The tool of the most large -scale scandal in the history of the scandal (2018) with the processing of the array of data from millions of Facebook users with subsequent processing for the needs of political campaigns was the application “Is Your Digital Life” ( Cambridge Analytica ). According to the head of Facebook, Mark Zuckerberg, the application installed 300 thousand people, but the total number of Facebook users affected was up to 50 million.
Most applications in Nikita’s account were related to sites that our hero visited a year or two ago, and he did not even recognize some sites.
Facebook is not the only resource that uses applications. You can enter some sites, for example, through Google, Twitter, VKontakte. In the accounts of these services there are sections with a list of connected applications.
Stay safe and do not forget: each person has his own values and threats. Maybe our tips are not quite suitable for you. But now you know what to pay attention to.