Facebook In Warning Users of State-Sponsored Attacks: A Simple Notification At Its Best

Facebook logo - padlockWhen concerning privacy on the internet, people think that there are always more and more things tech companies can do to protect them. When some people have difficulties in securing their online data, some others are running away with it. Facebook is one of the tech companies that continues to demonstrate its willingness to add more security to its users.

No matter who you are or what you do, there are a lot of state-sponsored malware and potential attacks floating around the web. With the many surveillance programs lurking to find the next victim, Facebook wants to warn its users for any of those attacks.

Facebook has one of largest user base if compared to other internet services. So there is no imagining how attractive it has become to people that wants to steal information from its users.

Back in the year 2012, the search giant Google started notifying its users if it believes that users were at risk of a state-sponsored attacks. In the year 2015 is Facebook's turn.

Facebook's Chief Security Officer Alex Stamos announced the protection in his blog post on October 17th, 2015.

"While we have always taken steps to secure accounts that we believe to have been compromised, we decided to show this additional warning if we have a strong suspicion that an attack could be government-sponsored," he wrote. "We do this because these types of attacks tend to be more advanced and dangerous than others, and we strongly encourage affected people to take the actions necessary to secure all of their online accounts."

Stamos clarified that Facebook will only use this warning "where the evidence strongly supports" a state-sponsored attack. The company uses this system because attacks from state-sponsored organizations "tend to be more advanced and dangerous than others," explained Stamos.

While Facebook won't detail how it will distinguish security breaches from hackers or from the government, with Stamos citing the need "to protect the integrity of our methods and processes", but users will see the following message upon login if Facebook believes the user is a target.

FB Login Approvals

The user is then prompted to turn on Facebook's Login Approvals which is Facebook's two-factor authentication. The feature can also be accessed through the user's Settings page under the Security option.

Turning on this feature in the first place should avoid users from being compromised before anything actually happened. The two-factor authorization which was first introduced by Andrew Song on May 12th, 2011, texts a login code to the user's mobile device whenever they, or anyone else for that matter, tries to access the account from an unrecognizable device.

FB Login Approvals

Despite being years behind Google in implementing such feature, Facebook is the only major tech company to offer such security. The move is also seen as Facebook's major step to ensure privacy and security for users that are trying to avoid surveillance. Back in June, the social network giant offered the option to share public encryption keys in order to keep email notification encrypted. The company has also launched its own deep web version of Facebook for TOR users.

Ideally, protecting privacy on the internet is not Facebook or Google's total responsibility as they're not complied to do everything for their users no matter how much they wanted to. But for companies as big and influential like Google and Facebook, the least they can do is to let their users know if they're being attacked.

"We strongly encourage affected people to take the actions necessary to secure all of their online accounts," said Stamos. "Ideally, people who see this message should take care to rebuild or replace these systems if possible."

The feature serves as a simple reminder, no more and nothing less. Hopefully people won't ever get this Facebook message. But at any case, it's always better to be ready.