# Security, or breach of security?

**URL:** <https://boards.straightdope.com/t/security-or-breach-of-security/671298>\
**Category:** In My Humble Opinion\
**Created:** [October 15, 2013, 12:24pm UTC](https://boards.straightdope.com/t/security-or-breach-of-security/671298 "2013-10-15T12:24:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Czarcasm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/czarcasm/32/4050_2.png) [@Czarcasm](https://boards.straightdope.com/u/Czarcasm)\
**Post date:** [October 15, 2013, 12:24pm UTC](https://boards.straightdope.com/t/security-or-breach-of-security/671298/1 "2013-10-15T12:24:35Z")

</div>

According to [this site,](http://www.the-gutters.com/) over 15, 000 people were able to sneak into the NY Comic Con last year through various means, including badge swapping. This year, they embedded a chip that had to be activated through the Con website through your Twitter account…which also allowed the convention to advertise through your Twitter account without your knowledge, making it look as if the message came from you… [More here.](http://mashable.com/2013/10/11/new-york-comic-con-promotional-tweets/) I don’t think that this is a good idea, and I would hate for this practice to spread to other venues. What say you?

---

<div class="post-metadata">

**Author:** ![MrDibble](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mrdibble/32/114_2.png) [@MrDibble](https://boards.straightdope.com/u/MrDibble)\
**Post date:** [October 15, 2013, 2:32pm UTC](https://boards.straightdope.com/t/security-or-breach-of-security/671298/2 "2013-10-15T14:32:28Z")

</div>

The ComicCon response indicates it was an opt-in service - was this just people not reading the TOS? If so, it’s just a bad idea on ComicCon’s part (I mean, hijacking Harry Knowles’ twitterfeed? That’s not going to go down well in AICN-land, I’m sure) but it can be countered in future by people watching what they click. If not, it probably crosses over into _way_ bad idea. And yes, I’d hate it if this happened at a con I attended (not that we have anything like that size of con here, damnit!)

---

<div class="post-metadata">

**Author:** ![Czarcasm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/czarcasm/32/4050_2.png) [@Czarcasm](https://boards.straightdope.com/u/Czarcasm)\
**Post date:** [October 15, 2013, 3:34pm UTC](https://boards.straightdope.com/t/security-or-breach-of-security/671298/3 "2013-10-15T15:34:14Z")

</div>

The "opt-in part was for the fans to tie in to the con, not for the con to take over their Twitter accounts. From [contactmusic.com](http://contactmusic.com):

> [@](#):
>
> NYCC did not ask for explicit permission from the users to post on Twitter on their behalf. However, after the start of the convention, plenty of attendees with connected twitter accounts were startled to discover statuses that they had not written. The tweets looked incongruous enough, ranging from “I \<3 NYCC” to “So much to see, so much to do! NYCC2013, I love you!” The added bit.ly links redirected to New York Comic Con’s Facebook page, and the tweets were all tagged with #NYCC. One Twitter user was outraged due to the poor quality of the tweets, writing: "@NY\_Comic\_Con Wrote 3 fake tweets on my account. And they weren’t funny, disgusting, or my me so I’m mad. "

---

<div class="post-metadata">

**Author:** ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)\
**Post date:** [October 15, 2013, 8:01pm UTC](https://boards.straightdope.com/t/security-or-breach-of-security/671298/4 "2013-10-15T20:01:31Z")

</div>

> [@Czarcasm](#):
>
> …which also allowed the convention to advertise through your Twitter account without your knowledge, making it look as if the message came from you… [More here.](http://mashable.com/2013/10/11/new-york-comic-con-promotional-tweets/) I don’t think that this is a good idea, and I would hate for this practice to spread to other venues. What say you?

LinkedIn is accused of doing this, or something similar. They badger users to give their e-mail addresses _and passwords_ :eek: then harvest all your contacts from your e-mail account. Then send invitations _in your name_ to all your contacts, to come and join LinkedIn. (I myself have received some of these.)

HuffPo article: [LinkedIn Sued For ‘Hacking’ Users’ Email Accounts To Spam Friends](http://www.huffingtonpost.com/2013/09/20/linkedin-sued-hacking-emails-spam_n_3963195.html)

Bloomberg article: [LinkedIn Customers Allege Company Hacked E-Mail Addresses](http://www.bloomberg.com/news/2013-09-20/linkedin-customers-say-company-hacked-their-e-mail-address-books.html)

The Independent article: [Stranger danger? LinkedIn denies ‘hack and spam’ attacks on members in marketing tussle](http://www.independent.co.uk/life-style/gadgets-and-tech/news/stranger-danger-linkedin-denies-hack-and-spam-attacks-on-members-in-marketing-tussle-8836995.html)

---

<div class="post-metadata">

**Author:** ![Boyo\_Jim](https://avatars.discourse-cdn.com/v4/letter/b/87869e/32.png) [@Boyo\_Jim](https://boards.straightdope.com/u/Boyo_Jim)\
**Post date:** [October 15, 2013, 8:37pm UTC](https://boards.straightdope.com/t/security-or-breach-of-security/671298/5 "2013-10-15T20:37:43Z")

</div>

> [@Senegoid](#):
>
> LinkedIn is accused of doing this, or something similar. They badger users to give their e-mail addresses _and passwords_ :eek: then harvest all your contacts from your e-mail account. Then send invitations _in your name_ to all your contacts, to come and join LinkedIn. (I myself have received some of these.)
> 
> HuffPo article: [LinkedIn Sued For ‘Hacking’ Users’ Email Accounts To Spam Friends](http://www.huffingtonpost.com/2013/09/20/linkedin-sued-hacking-emails-spam_n_3963195.html)
> 
> Bloomberg article: [LinkedIn Customers Allege Company Hacked E-Mail Addresses](http://www.bloomberg.com/news/2013-09-20/linkedin-customers-say-company-hacked-their-e-mail-address-books.html)
> 
> The Independent article: [Stranger danger? LinkedIn denies ‘hack and spam’ attacks on members in marketing tussle](http://www.independent.co.uk/life-style/gadgets-and-tech/news/stranger-danger-linkedin-denies-hack-and-spam-attacks-on-members-in-marketing-tussle-8836995.html)

This happened right here to one of the mods. and numbers of us got invites in the mod’s name. I’m still pretty pissed, because the mods wouldn’t take any action to prevent a recurrence, so it could happen again.
