Facebook locked in 'arms race' with spammers
Within days of Facebook rolling out new security features designed to block spam, several new social-engineering attacks were spreading that managed to get by the company's antispam defences.
The spammers have modified their handiwork so it will get past Facebook's scam detection system, company spokesman Fred Wolens told ZDNet UK's sister site CNET News on Monday. "There are new methods they've picked up after we put out the protections on Thursday," he said. "It's an arms race. We put out new protections and they come up with new campaigns... When we announced the new security features, they were calibrated for all the self-XSS attacks we'd seen at the time."
The company began turning on a feature last week that displays warnings when it detects that users are about to be duped by cross-site scripting (XSS) and clickjacking attacks. In such attacks, people are tricked into clicking something or pasting some code into their browser web address bar.