Social Media Security: What a Communication Professional Needs to Know

07/06/2013
|

To mark the celebration of the 1st Brand Care Congress on Reputation, Security, and Digital Legality for Communication and Digital Marketing Professionals next Thursday, July 4, 2013, thanks to onbranding, La Salle Engineering University, and Microsoft, among other collaborating companies, we want to offer you an explanatory post on some important aspects of Reputation, Security, and Legality, present in our daily domestic and professional lives.

What should a communication and digital marketing professional know about cybercrimes and cyberattacks?

  1. Opening accounts in someone else’s name by impersonating them
  2. Taking my partner’s phone
  3. Accessing their Facebook account, email
  4. Changing passwords for someone else’s email, network, computer
  5. Unlocking a phone
  6. Sniffing WhatsApp
  7. Stealing a neighbor’s Wi-Fi
  8. Monitoring conversations, calls, messages… of a person who has not authorized us
  9. My boss controlling and monitoring my devices without my express consent
  10. Buying Facebook fans or Twitter followers

Are these actions punishable? Do they have consequences? We cannot get away with all these situations unscathed. Beware! We’ll tell you why.

MOST COMMON CYBERCRIMES or CYBERATTACKS (real cases)

  • Unauthorized access
  • Manipulation of computer systems
  • Disclosure of secrets through access and interception of devices and communications
  • Forgery
  • Crimes against the physical and moral personality of individuals (insults, slander, defamation*)

*Insult: Anyone who, outside the cases provided for in the preceding article, offends in any way, with words, writings, or actions, the honor, rectitude, or decorum of a person, shall be punished with a penalty of three to eighteen months imprisonment or a fine of 60 U.R. (sixty readjustable units). Be careful because compensation can also be claimed for damages caused to service providers, i.e., forum webmasters, search engines, bloggers, and website owners.

*Defamation: Anyone who, before several people gathered or separated, but in such a way that the version can be disseminated, attributes a specific act to a person, which if true, could lead to criminal or disciplinary proceedings against them, or expose them to public hatred or contempt, shall be punished with a penalty of four months imprisonment to three years penitentiary, or a fine of 80 U.R. (eighty readjustable units).

(Aggravating circumstances): The preceding crimes shall be punished with an increase of one-sixth to one-third of the penalty when committed in public documents, or with writings, drawings, or paintings publicly disseminated or exposed to the public.

In cases of offense against a social, political, or administrative corporation, proceedings shall only be initiated with the authorization of the offended corporation or its hierarchical superior when it concerns an authority not collegially organized.

WHAT WE SHOULD DO

Our communication strategy must assess whether or not it is worth reacting to a situation (making noise is sometimes counterproductive, and sometimes silence is already an answer).

Once the seriousness of the situation has been analyzed, we must file a lawsuit requesting that the illegitimate interference with the right to honor be declared, as well as claiming compensation for possible damages caused by defamation.

These actions can also be “resolved” through criminal proceedings.

For example, by requesting compensation in terms of civil liability, the Court could also be asked, if applicable, for a custodial sentence or a financial fine for the perpetrator of the defamatory act.

Criminal liabilities (fine and/or imprisonment)

  • Slander: 6 months to 2 years imprisonment or a fine of 24 months
  • Insults: fine of 6 to 14 months

WHAT PREVENTIVE MEASURES SHOULD WE TAKE TO AVOID THESE CRIMES? HOW SHOULD WE PROTECT OURSELVES?

Basic connection measures such as:

  • Strengthen WiFi network configuration
  • Change the SSID: The SSID is the network name
  • Change the default password
  • Hide the SSID: By hiding your network’s SSID, your WiFi access point does not broadcast beacon frames with the network name.
  • Periodically change the SSID and password.
  • Filter by MAC addresses for connection
  • Turn off WiFi when not in use.

CYBER INVESTIGATION = private investigation related to the Internet?

As the compound word itself suggests, we are talking about investigation in the online realm, but this is NOT just monitoring and seeing what appears about a company or someone online; it goes much further. It’s about going beyond the visible and the non-apparent.

APPLIED TO COMMUNICATION, SOCIAL MEDIA, AND DIGITAL MARKETING PROFESSIONALS

In the field of online communication and social media, we also provide Social Media Intelligence services, meaning all the valuable information we can extract from social media data, interactions, data flows between users… or on a specific topic, which we convert into intelligence necessary for the company.

SOCIAL MEDIA INTELLIGENCE

What is it for? For the launch of new products by identifying and creating a mapping of communities and audiences, as well as influencers on the network for the topics that may be of most interest to us. To know what people are saying online about them, where they are saying it, who and how they talk about a topic, person, product, brand…

WHAT SHOULD WE CONSIDER WHEN TALKING ABOUT CYBERSECURITY?

Regarding cyber investigation, it is important to understand that the information we leave on the internet is not only what search engines show us with a simple search (not just Google, but also Bing, Yahoo…), but there is also non-apparent information, geolocations via meta data, images related to us even if we are not tagged…

There are many open-source software programs that trace our entire life with a single click (personal data, geolocation data, social media data, pages we visit, portals where we have spoken, even IP voice conversations like “Skype, WhatsApp…”)

ARE THERE SITUATIONS WHERE A PERSON’S OR COMPANY’S REPUTATION CAN BE AFFECTED BY A LACK OF KNOWLEDGE IN DIGITAL SECURITY AND LEGALITY? WHAT COULD THESE SITUATIONS BE?

There are many, but to give you an idea, from the moment we don’t truly know what we share, where we share it, or with whom, we are no longer deciding what image we want to project.

And we might say, I don’t care, I have nothing to hide… well, let’s put that in quotes; we all have a private, public, social, and a secret or intimate life that doesn’t have to be known.

For example:

Basically, understand that Internet Presence can primarily be of 3 types:

  • Active Presence (I choose what I say, where I am, and how I am, and I have active online channels)
  • Passive Presence (I have a presence but don’t control what I share, with whom, for how long… I had a conversation in a forum where I ranted about something, someone… and I didn’t remember)
  • Passive Presence and in the hands of third parties (public bodies, media, directories, friends, acquaintances, bosses, colleagues, but in third-party spaces that I don’t control…)

Dating social networks, images synchronized on our devices, pages we visit, people we interact with (it is very easy to trace a person’s personal and professional profile and unravel their relationships, not just personal ones).

Presence in the BOE (Official State Gazette), in business directories, in forums… We can de-index content from many places by making the relevant requests, but for example, in the BOE, we will not disappear from the publication, only from Google’s cache.

WHAT TYPE OF ADVICE AND KNOWLEDGE ARE NECESSARY TO PREVENT THESE SITUATIONS?

onbranding uses the PAS method (prevent, advise, and assist). First: Prevent, identify our objectives; for this, we will have to scan the network, investigate, and understand what we are facing. Then Advise (talk to the relevant platforms and take the necessary legal or non-legal actions), Assist (establish the strategy, asset and participation plan, as well as online spokesmanship for each company, person)..

IS THE ONLINE WORLD STILL AN UNREGULATED SECTOR? ARE THERE MANY GAPS?

We have a chapter of the penal code regarding telematics crimes that are typified, therefore criminal behaviors are subsumable within the precepts of that chapter. The only problem is that our legal system often operates based on events, “crimes” (imputable and proven), so we are always behind in the typification of crimes (many networks, many new forms of communication…).

MOST COMMON TELEMATIC CRIMES

  1. Cybercrime (white-collar, hacker, anonymous)
  2. Types of crimes
    1. Crimes against intellectual property
      1. Unlawful use of computer programs
      2. Distribution of copyrighted content
    2. Manipulation of computer systems
      1. Program manipulation
      2. SQL injection
      3. Manipulation of data contained in the system
      4. Manipulation of output data
    3. Forgeries
      1. Document forgery
      2. Credit card cloning
    4. Damage to computer systems
      1. Sabotage
      2. Virus
      3. Worm
      4. Logic bomb
      5. Defacement
    5. Unauthorized access
      1. Unauthorized access to systems or services
      2. Data theft
      3. Data interception
        1. *** Disclosure of secrets,

Organic Law 10/1995, of November 23, of the Penal Code: Crimes against privacy, the right to one’s own image, and the inviolability of the home.

“Catching” my partner’s WhatsApp, accessing someone else’s account (partner, family member…) without prior permission from the affected person IS a Crime, a Crime against privacy, the right to one’s own image, and the inviolability of the home, CHAPTER ONE, On the discovery and disclosure of secrets

Anyone who, to discover the secrets or violate the privacy of another, without their consent, seizes any documents or intercepts their telecommunications or uses technical devices for listening, transmitting, recording, or reproducing sound or image, or any other communication signal, shall be punished with penalties of imprisonment from 1 to 4 years and a fine of 12 to 24 months.

The same penalties shall be imposed on anyone who, without authorization, seizes, uses, or modifies, to the detriment of a third party, reserved personal or family data of another that are registered in computer files or supports, electronic or telematic, or in any other type of public or private archive or registry. The same penalties shall be imposed on anyone who, without authorization, accesses them by any means and on anyone who alters or uses them to the detriment of the data owner or a third party.

Anyone who, by any means or procedure and violating the security measures established to prevent it, accesses without authorization data or computer programs contained in a computer system or part thereof or remains within it against the will of the person legitimately entitled to exclude them, shall be punished with a prison sentence of six months to two years.

The penalty of imprisonment from two to five years shall be imposed if the discovered data or facts or the captured images referred to in the preceding paragraphs are disseminated, revealed, or transferred to third parties. Anyone who, with knowledge of their illicit origin and without having participated in their discovery, carries out the conduct described in the preceding paragraph shall be punished with prison sentences of one to three years and a fine of twelve to twenty-four months.Paragraph 4 of Article 197 renumbered by the fifty-third paragraph of the sole article of Organic Law 5/2010, of June 22, which modifies Organic Law 10/1995, of November 23, of the Penal Code (“B.O.E.” June 23). Its literal content corresponds to that of the previous paragraph 3 of the same article. Effective: December 23, 2010

If the acts described in paragraphs 1 and 2 of this article are carried out by the persons in charge or responsible for the files, computer, electronic or telematic supports, archives or records, the penalty of imprisonment from three to five years shall be imposed, and if the reserved data are disseminated, transferred or revealed,
the penalty shall be imposed in its upper half. Paragraph 5 of Article 197 renumbered by the fifty-third paragraph of the sole article of Organic Law 5/2010, of June 22, which modifies Organic Law 10/1995, of November 23, of the Penal Code (“B.O.E.” June 23). Its literal content corresponds to that of the previous paragraph 4 of the same article. Effective: December 23, 2010

Likewise, when the acts described in the preceding paragraphs affect personal data revealing ideology, religion, beliefs, health, racial origin, or sexual life, or the victim is a minor or an incapacitated person, the penalties provided for shall be imposed in their upper half. Paragraph 6 of Article 197 renumbered by the fifty-third paragraph of the sole article of Organic Law 5/2010, of June 22, which modifies Organic Law 10/1995, of November 23, of the Penal Code (“B.O.E.” June 23). Its literal content corresponds to that of the previous paragraph 5 of the same article. Effective: December 23, 2010

If the acts are carried out for profit, the penalties respectively provided for in paragraphs 1 to 4 of this article shall be imposed in their upper half. If they also affect data mentioned in the preceding paragraph, the penalty to be imposed shall be imprisonment from four to seven years. Paragraph 7 of Article 197 modified as established by number 2 of the second final provision of Organic Law 3/2011, of January 28, which modifies Organic Law 5/1985, of June 19, of the General Electoral Regime (“B.O.E.” January 29), which corrects certain articles and paragraphs of Organic Law 10/1995, of November 23, of the Penal Code, in the wording given by Organic Law 5/2010, of June 22. Effective: January 30, 2011. Paragraph 7 of Article 197 renumbered by the fifty-third paragraph of the sole article of Organic Law 5/2010, of June 22, which modifies Organic Law 10/1995, of November 23, of the Penal Code (“B.O.E.” June 23). Its literal content corresponds to that of the previous paragraph 6 of the same article. Effective: December 23, 2010

  1. Unlawful use of computer systems
    1. Spam Abuse of Internet use in companies
      1. Fake job offers
      2. Supposed gifts and prizes
      3. Psychics and similar
      4. Free websites with diverse content
      5. Order confirmation
      6. Investment abroad
      7. Phishing
      8. Email validation
    2. Apology for terrorism
    3. Incitement to racial hatred
    4. Child pornography
    5. Gambling
    6. Money laundering
    7. DNS changer virus
    8. Cyber warfare
  1. Social networks
  1. REAL EXAMPLES
    1. François Cousteix, the 23-year-old hacker who was prosecuted by the FBI after “taking over” Obama’s Twitter account, was pardoned by the court… repercussions and dissemination, comscore 93 million users (25-year-old hacker, Twitter access keys with access…, Barack Obama, Britney Spears)
  2. Facebook
  3. Gmail
    1. Email changes (social engineering) deduction by dictionary
    2. Everyday passwords
    3. The same everywhere
    4. Birth dates, events, city and year…
  4. In France, a young cybercriminal accessed Twitter with administrator privileges over the entire network and published important internal documents such as benchmarks on Facebook. The FBI alerted the French Police. He was caught because he published several posts on his blog (ego problems). Sentence: 2 years in prison, 5 months in correctional facility, €1,000
  • Breach of contract
  • Crimes against intellectual property
    1. Software plagiarism
    2. Database plagiarism

We look forward to seeing you at Brand Care (Tickets for the congress)

Register for the event//

Digital Identity

Methods for analyzing and
assessing online
reputation damage