The dangers of social spam.

Inside the Internet.
Sept. 23 2009 11:12 AM

Your Gullible Friend Has Sent You a Photo!

The dangers of social spam.

(Continued from Page 1)

The damage caused by ViddyHo, as with WeGame, appears limited to embarrassment. Hoan Ton-That, the site's San Francisco-based creator, told me in April that he didn't mean to auto-invite people's entire address books, though the fact that he has a new site with similar ambitions is not heartening. But there's nothing preventing the next ViddyHo from doing more damage, logging passwords and contacts for more sinister purposes.

Like any good scam, social spam exploits our trust—the belief that our friends wouldn't invite us to join a site with bad intentions. Versions of this trick have been around since the height of AOL Instant Messenger's dominance, when I would occasionally get IMs from friends with purported links to articles about Osama Bin Laden's capture. (I clicked on that one.) But the rise of social networking has made these scams even more convincing. I have a feeling most of the victims of the WeGame e-mails were more absent-minded than gullible. We decide we're going to register for some new site and then go into autopilot, typing in whatever we're asked for in the fields. After all, we've done it a thousand times before without incident. (One victim at Wesleyan claims to have been on the phone while absently clicking through the motions and ended up infecting her best friend's mother.)

It's easy to imagine how social spam could wreak real havoc. Imagine a site—vouched for in a friend's e-mail message, naturally—that asks users to provide their e-mail address as a login, then prompts them to set up a password. It would then be elementary for the wicked Web site to check whether this e-mail/password combo opens the user's Webmail account. Considering how often people use the same password for all of their Web transactions, I bet that simple scheme would work a lot of the time. Once the Webmail has been cracked, the wicked Web site could send invitations to everyone in the contact list—and plunder the inbox for valuable goodies like bank account information or Social Security numbers.


If WeGame and its ilk continue to proliferate, it may fall to the Webmail clients to place extra protections on how outside sites can mine contacts. "We don't approve of third-party sites handling their users' information in this way," a Google spokesperson told me, adding that "in some cases we may take more proactive measures to identify and block the spam."

WeGame doesn't actually send mail from users' Gmail accounts—it just sends all your contacts e-mail with your name in the subject line. On account of that, the best Google could have done immediately would have been to block e-mail that came from WeGame. In the meantime, a quick, finger-wagging PSA: The rise of social spam is yet another reason to practice safe surfing. Think twice whenever a site asks for your Webmail password. And for the millionth time, don't use the same password for everything.

Chris Wilson is a Slate contributor.



Forget Oculus Rift

This $25 cardboard box turns your phone into an incredibly fun virtual reality experience.

Stop Panicking. America Is Now in Very Good Shape to Respond to the Ebola Crisis.

The 2014 Kansas City Royals Show the Value of Building a Mediocre Baseball Team

The GOP Won’t Win Any Black Votes With Its New “Willie Horton” Ad

Sleater-Kinney Was Once America’s Best Rock Band

Can it be again?


Smash and Grab

Will competitive Senate contests in Kansas and South Dakota lead to more late-breaking races in future elections?

I Am 25. I Don’t Work at Facebook. My Doctors Want Me to Freeze My Eggs.

These Companies in Japan Are More Than 1,000 Years Old

  News & Politics
The World
Oct. 21 2014 11:40 AM The U.S. Has Spent $7 Billion Fighting the War on Drugs in Afghanistan. It Hasn’t Worked. 
Business Insider
Oct. 21 2014 11:27 AM There Is Now a Real-life Hoverboard You Can Preorder for $10,000
Oct. 21 2014 11:37 AM What Was It Like to Work at the Original Napster?
  Double X
The XX Factor
Oct. 20 2014 6:17 PM I Am 25. I Don’t Work at Facebook. My Doctors Want Me to Freeze My Eggs.
  Slate Plus
Tv Club
Oct. 20 2014 7:15 AM The Slate Doctor Who Podcast: Episode 9 A spoiler-filled discussion of "Flatline."
Oct. 21 2014 12:05 PM Same-Sex Couples at Home With Themselves in 1980s America
Oct. 21 2014 10:43 AM Social Networking Didn’t Start at Harvard It really began at a girls’ reform school.
  Health & Science
Climate Desk
Oct. 21 2014 11:53 AM Taking Research for Granted Texas Republican Lamar Smith continues his crusade against independence in science.
Sports Nut
Oct. 20 2014 5:09 PM Keepaway, on Three. Ready—Break! On his record-breaking touchdown pass, Peyton Manning couldn’t even leave the celebration to chance.