Let’s talk about the risk of online reviews.
There’s the one we’ve been talking about for years, of course: fakes. A 4.8-star average backed by thousands of reviews can be enticing, but buyer beware. A British government report suggests between 11% and 15% of reviews are fake.
Tripadvisor and Trustpilot report figures suggesting that, on their platforms, the rate is probably somewhere between 7.4% and nine per cent.
Now a new study suggests there might be a legitimate risk in writing reviews in the first place. Even the 100% truthful kind.
Writing in the journal Information Systems Research, Yan Leng, an assistant professor of information, risk, and operations management at the McCombs School of Business at the University of Texas at Austin, says patterns in publicly available review activity can help reveal users’ social ties.
That information could make it easier for spear phishers to identify and impersonate people a potential victim knows.
Let’s make sure we define spear phishing. In short, it’s an attempt by a bad actor to get passwords or money by contacting a victim while impersonating someone that victim trusts.
The researchers used public Yelp data covering 4,299 reviewers in Louisiana and Pennsylvania in 2020. On Yelp, both the review texts and the users’ friendship lists were publicly accessible.
That allowed Leng and her colleagues to infer connections from review behaviour. Then they compared those presumed connections with the users’ disclosed Yelp friendships.
The connection to online reviews? According to Leng and her fellow researchers, patterns in people’s public reviews – especially patterns involving review length – made it possible to infer which Yelp users were connected, without using their friendship lists as an input.
The most revealing clue was review length.
Some connected users tended to write similarly long reviews. Other connected pairs showed complementary patterns, with one tending to write longer reviews and the other shorter ones.
Across thousands of users, those patterns enabled the model to begin reconstructing the social network.
Inferring connections between online reviewers from patterns in review length might sound a bit dubious, but Leng says her work shows there is a true signal hiding beneath the noise.
In fact, more identified connections mean more potential impersonation attempts – and the study’s model showed that an attacker could identify between 49% and 63% of Yelp reviewers’ social relationships from their activity.
The higher identification rate came with a higher level of false positives – wasted effort, from a scammer’s point of view – but the clear implication is that spear phishing is a numbers game.
For scammers, the return on investment scaled quickly: from 109% for 500 attempts to 1,098% for 10,000 attempts.
Interestingly, Leng’s recommendation isn’t for people like you and me to stop leaving reviews. Instead, it’s all on the platforms.
One of her suggestions: “small, carefully designed random changes to the data before it is released.”
An example would be for a platform to subtly vary a review’s displayed length without changing its meaning, thus blurring the linguistic fingerprint while preserving the usefulness of the underlying reviews.
Short version, in her words: “The platforms need to protect not only what users disclose, but also what others can infer.” – Inc./Tribune News Service
