There’s a certain irony here – I work for an institution that teaches best practices for social media engagement, but does not have a social media policy for its employees and representatives. Many times, our academic offices and clubs are asked to engage in social media to promote events and reach out to potential students, but there is no policy in place that speaks to what type of media should be posted, and appropriate methods of engagement.
As a manager for the social media of the Marist Music
Program, I often get asked (sometimes by our campus social media managers), why
aren’t I posting examples of the students in action? Wouldn’t it be great to be able to show the
world all the great things that happen on the stage – wouldn’t it be a great
recruitment tool?
Unfortunately, it would be illegal to post such media-rich
engagements. Many institutions must pay
for the permission to video their performances …rights and royalties, etc. Even audio recordings which can be embedded
in social media and blog posts, require permission for recording if it is
outside of archival purpose. Certain
exemptions exist for media in public domain, but it leaves us limited in how we
can show the world our product. So we have to get a little creative with visual design...
![]() |
| Sample of Facebook Event Cover Photo (Facebook, 2016) |
If I were to make the mistake and post an item that violated
copyright law, the College could potentially be fined, fined a considerable
amount. If a set of best practices were
distributed to those charged with cultivating social media on our campus, that
included what can and cannot be posted by an agent of the College, much of the
liability that comes along with the creative process in creating posts with be
assuaged.
In terms of my own social media, I have always been a bit of
a nihilist – realizing worst case scenarios have always scared me (as with my
luck, they always seem to find me). Despite
meeting Twitter’s password security recommendations, I managed to have my
account compromised. It was very
subtle, and had I not have noticed the change to my profile description, I may
never have known about it.
![]() |
| Twitter Profile Description, @mikeynaps (Twitter, 2013) |
While it was true, I was in my 30s and from Poughkeepsie,
NY. The rest of the information was
false. I reported the issue to Twitter,
and they notified me that while my account was clearly compromised, the issue
was not with their security safeguards, but with one of the apps I had
connected to my account. Lesson learned
– as we are all charged with the convenience of integrating our social media
accounts, we must also be vigilant about the permissions we allow to access our
accounts.
I see those fun posts on Facebook all the time – quizzes and
game requests. After my experience with
Twitter, my stomach twists a little each time one show up on my timeline. Granted, I have still allowed permissions
for myself, so I might not be the best example – but I still review each request
or permission for access, and not blindly click accept. McAfee
said it pretty clearly, “Think twice about applications that request permission to
access your data. You would be allowing an unknown party to send you email,
post to your wall, and access your information at any time, regardless of whether
you’re using the application” (Siciliano, 2011).
Siciliano,
R. (2016, October 28). 15 Social Media Security Tips. Retrieved
February 22, 2017, from
https://securingtomorrow.mcafee.com/consumer/family-safety/15-social-media-security-tips/
Siciliano, R. (2011, July 13). 15 Social Media Security Tips.
Retrieved February 22, 2017, from
https://securingtomorrow.mcafee.com/consumer/family-safety/15-social-media-security-tips/


Hi Mike,
ReplyDeleteI like your take on Monica’s initial post! I know social media privacy/security issues happen frequently, but your personal hacking experience is interesting.
When I was researching privacy best practices, I also came across the recommendation to be careful what you click on your social media accounts and what add ons, apps, features and plug-ins you allow. It looks like Kerstin found this insight as well, noting “With all of the posts showing up on newsfeeds it is important to watch what you click on. It is important to note that “social networking sites don’t have spam filters”. Never click on any suspicious advertisements or links, even if it is from someone in a private direct message. Links that are engaged with may infect your accounts and even devices letting hackers gain access to your personal and “private” information (Marzullo, 2016).
Your situation got me thinking of if there are best practices companies should follow or respond with if they are hacked. I came across an article that I think does a great job at outlining some ideas: https://www.business.com/articles/how-to-recover-from-a-social-media-hack/
To recap quickly, they recommend:
•Respond immediately
•Assess the severity of the hack
•Determine what happened
•Plan to learn from the situation for next time
Does anyone have any thoughts on other things companies can do if they are hacked?
References
Evans, Z. (n.d.). How to Recover From a Social Media Hack. Retrieved February 22, 2017, from https://www.business.com/articles/how-to-recover-from-a-social-media-hack/
Marzullo, K. (1970, January 01). Kerstin's COMI 610 Blog. Retrieved February 22, 2017, from http://kmarzullo.blogspot.com/2017/02/how-to-prevent-social-media-hacking-in.html#comment-form
I think businesses not only need to assess social capital when they find their social media hacked, but also need to evaluate how secure their own tech infrastructure is. It may not be just deciphering encrypted passwords that causes an account to be hacked, but there may be a systemic problem with their IT.
DeleteI would agree with you Mike. Security is not just about updating passwords regularly, hardware upgrades need to happen consistently.
DeleteThe discussion of your work related social media reminded me of something a vlogger I follow said the other day, that if you don’t want someone filming a vlog in your business, just play loud music since they can’t get the copyright to re-broadcast it in their video. Do you have to worry about photo-release forms for students? At the museum, anyone who participates in an educational activity is asked to sign a photo release form allowing or denying the use of their photos in our social media or marketing. That’s how I ended up in several photos on their Facebook page today.
ReplyDeleteThe compromise of your Twitter account is worrying… it’s hard to know what creeps in through seemingly insignificant sources. Constant vigilance! At least there’s a song for that situation: “Turning Japanese” by the Vapors, ha ha.
Do you think your work-related social media accounts are more or less susceptible to hacking than personal accounts? I’ve reminded one client several times to be careful about who has access to edit their Facebook page, to set appropriate permissions (so the CSR responding to direct messages doesn’t have full admin rights), and to remove former employees promptly from access to the page.
Great question Victoria! I'm not sure whether they are more or less vulnerable, but if they don't follow suggestions such as yours, they are setting themselves up to be hacked!
DeleteVictoria -
DeleteTurning Japanese - amazing reference! In terms of the work-related social media accounts: yes, we should be getting releases from students that are used in the posts - are they generally strict in enforcement? Not really, most students are volunteering and creating their own post, then tagging our accounts - so the issue of consent really should really be addressed and clarified more across all of our social media channels at the College.
Our department's social media has yet to be hacked, I believe mainly due to the limitations and permissions we have on who can edit, who owns, and who can administer the media. When I see other departments do a "social media guest takeover" I get nervous - how do they maintain the integrity after a a "takeover"? How do they know that the posts that are going out are a good representation of the brand? I might worry too much, but I wonder how organizations balance the integrity of their posts over the benefits of heightened engagement.
I assume Twitter offers some sort of "guest host" protocol. I passively follow @sweden (I don't officially follow them, too many tweets overwhelmed my news feed). The country allows an individual to totally run their account for a week at a time, with essentially no censoring (Hay, 2014). Especially with the current #SwedenIncident, the account is getting a lot of traffic. 18 hours ago, this week's Swede, Max, references two-step verification as hackers tried to reset his personal account's password following a political rant. Sweden seems to have guidelines in place for this experiment though, http://curatorsofsweden.com/about. I think a guest takeover could work many places if there are protocols (and technical limitations) in place first.
DeleteHay, M. (2014, December 3). Looking back on the greatest Twitter experiment ever. Retrieved from https://www.good.is/articles/swedish-twitter-experiment
Mike, thanks for sharing your personal experience on Twitter. It made me pop over to take a look at my own Twitter account to be sure everything was okay. It was interesting to think of those games we play as possible threats. However, to protect yourself from third party apps you should at least pause and review, instead of clicking through with immediate permission. This simple action could save you from an attack.
ReplyDeleteYou also brought up some great examples about policies to protect the organization. Companies do need to be vigilant to protect their systems from hackers and that falls under the hardware and It department. From there it’s updating passwords regularly and educating your employees on the use of social media. I’m sure all of us have popped into Facebook or Twitter while at the office. It’s interesting to consider how personal social media use at work might not only affect productivity but possibly infect the work systems. However, employee use of social at media at work is not all bad and some encourage the use as well as use it as a company- wide communication tool.
I read that the top tools being utilized by corporations are:
1) Facebook Page-organization communication tool used by HR
2) Yammer- enterprise chat service
3) Twitter-person or private tweets to communicate quickly
4) LinkedIn – use LinkedIn groups as intranet
5) Company Blog – such as latest benefits
6) Remote Access- training
7) YouTube – archive video trainings (Taurasi, 2015)
You can read more at http://bit.ly/25KJapM
Does your company utilize social media tools for internal communication?
Reference
Taurasi, L. (2015, July 6). 7 Ways to Use Social Media for Employee Communications. Retrieved from http://workplace.care.com/7-ways-to-use-social-media-for-employee-communications
This comment has been removed by the author.
ReplyDeleteHi Mike,
ReplyDeleteFacebook has been taking many steps towards creating a more secure user experience. Users are able to turn on the "login approvals" feature where they enter a special code that is sent through text message each time they access Facebook from any device. They are also able to receive alerts whenever their account is logged into, view and manage recognized devices, view where they are currently logged in (provides you with application, last accessed, location and device type, etc. This can all be found through Facebook's security settings.
Recently, Facebook has introduced an additional layer of security, the Universal 2nd Factor (U2F) security key which allows users to log in through USB or NFC. Users can now "register a physical security key to your account so that the next time you log in after enabling login approvals, you'll simply tap a small hardware device that goes in the USB drive of your computer" (Facebook, 2017). What are the benefits?
Phishing protection, interoperable and fast login.
Reference
Facebook. (2017, January 26). Facebook. Retrieved February 24, 2017, from https://www.facebook.com/notes/facebook-security/security-key-for-safer-logins-with-a-touch/10154125089265766/