140Char

Microblogging news, tools and resources: Twitter, Google Buzz, Tumblr, Identi.ca, Yammer, Posterous
  • rss
  • Home
  • About
  • Microblogging tools
  • Monetise microblogging/Jobs
  • Business Use/Case Studies
  • Custom search

The aftermath of Twitters biggest phishing scam

Dan Thornton | March 1, 2010

Over the last week, many people have fallen foul of the latest phishing scam to do the rounds of Twitter. And an unusual number of high profile individuals have been included in the list of users affected, including the Press Complaints Commission, BBC correspondent Nick Higham, the Guardian’s Head of Audio Matt Wells, bank First Direct, and environment minister Ed Milliband.

Environment Minister Ed Milliband caught by phishing scam

Environment Minister Ed Milliband caught by phishing scam

Phishing scams have long been endured by most internet users – the traditional mechanism has been via email, but as social networks have becoming hugely popular, they’ve become the vector of choice. And Twitter is particularly attractive as the speed with which messages can spread is combined with the use of short urls, which help to mask the malevolence of the message.

While this is just another example of the huge amount of phishing attempts which exist, the higher profile of these attacks as they affect prominent politicians will hopefully lead to a better awareness and response by governments.

It’s probably a forlorn hope, but for example, here are some things which might change:

  • More education about phishing and spam to the ‘general public’ – how about a public awareness campaign?
  • More understanding about how normal users can have accounts compromised very easily – for instance, with ‘Three Strikes Rules’.
  • More people using offline backups of any content that is valuable or useful to them
  • More of a move towards data privacy, and Vendor Relationship Management, to allow users to only share the information they choose with any service provider under strict controls.
  • A rethink of the UK Identity Card scheme which includes private businesses taking fingerprint and photos.

Importantly, it should place the risks of Social Engineering alongside those of teenage cyberwarfare specialists taking down defence satellites from their bedroom. If a private company was, for example, storing fingerprint data, you wouldn’t need to target their infrastructure (Although I’m not sure most chemists have a particularly high level of internet security) – you’d use social engineering on their employees via Facebook, Twitter, or offline in person to gain information and access.

Of course, technology can play a part, and I’m sure Twitter will increase their response to phishers in future, particularly as a high profile attack via any platform is never good for PR. But any measures will always be part of a never-ending arms race, and only when every individual is educated enough will there be any noticeable difference…

Comments
Comments
Categories
Twitter
Tags
cures, ed milliband, first direct, hacking, phishing, scam, security, social networking, solutions, Twitter
Comments rss Comments rss
Trackback Trackback

Big money for hacked Twitter accounts

Dan Thornton | January 31, 2010

Stolen Twitter accounts appear to be commanding a premium amongst hackers sharing details on forums.

Data stealing software is a risk to your details for any site, but according to Kaspersky researcher Dmitry Bestuzhev, he’s seenĀ  a Twitter account with just 320 followers offered for as much as $1000. In this case, the three-letter username may have influenced the price.

That compares with Gmail accounts for $82, Rapidshare accounts for $5 per month, and other sites including Skype and Facebook. Bestuzhev also went on to say Kaspersky had detected 70,000 data stealing programmes in 2009, which is twice as many as in 2008.

Twitter is likely to be a preferred route to spread malware as links can spread in near real-time to hundreds or thousands of followers – each of whom can quickly and easily repeat a malware message to their own network.

Malware messages are also hidden by shortened urls, and with the amount of links spread via Twitter, there’s a good chance people are less suspicious than seeing the same links in an email or IM message.

It’s a reminder to make sure you use a unique password which is a mix of alphanumeric characters, and to change it regularly. Be careful of sharing it with third party sites and tools which aren’t using Twitter’s OAuth protocol, and be careful with links being posted by others – even including people you trust.

(Via Computerworld)

Comments
Comments
Categories
Twitter
Tags
hacking, kaspersky, passwords, security, stolen, Twitter
Comments rss Comments rss
Trackback Trackback

Interesting responses to Twitter security worries

Dan Thornton | January 5, 2009

Following my previous post on the implications for Twitter of the first large scale phishing attack, I’ve seen a few interesting responses:

First up, @benbarden responded to my concerns over short urls by suggesting that people could host their own, e.g. 140char.com/link1 etc.

A pretty cool idea, and one that Ben is apparently running on a site already (I might have to beg him for a guide!). The only flaw is that a lot of people run hosted blogs, and will therefore still be at the mercy of shortening services. But for those of us paying hosting costs it’s worth considering.

Then the always friendly @mingyeow from MrTweet asked my opinions on a blog post ‘Addressing Privacy Concerns‘. Suffice to say it’s a very eloquent explanation of how and why the developers of one application are aiming to keep your accounts safe:

One of the points raised is that MrTweet will support OAuth as soon as it becomes available, although it won’t answer every security question, because, as they quite rightly say, securityand convenience are always a trade-off.

There’s some really interesting debate around the use of OAuth from both Jesse Stay on LouisGray.com, and Dave Winer.

Comments
Comments
Categories
Twitter
Tags
@benbarden, addressing privacy concerns, dave winer, jesse stay, mingyeow, mrtweet, oauth, phishing, scams, security, short, Twitter, urls
Comments rss Comments rss
Trackback Trackback

140Char Sponsors

Public Relations Software

Subscribe

Subscribe to 140Char by Email

Tags

140char Advertising api application applications badgergravling business cash facebook followers Following friendfeed guide identica jaiku laura fitton links marketing microblog Microblogging mobile monetisation Monetising money news newspapers Plurk pownce revenue search Seesmic statistics tumblr tweet tweetdeck tweet of the week tweets twitpic Twitter twitter search UK updates users video viral

Monetize your Twitter account

Chirp, chirp!

Categories

  • 140char notices (15)
  • Advertising (4)
  • Audio Microblogging (1)
  • audioboo (1)
  • Case Studies (11)
  • events (3)
  • Google Buzz (1)
  • Interviews (4)
  • Lifestreaming (2)
  • Microblogging (60)
  • Microblogging Round-Up (5)
  • Mobile Phone Apps (2)
  • Monetising (20)
  • New launches (9)
  • Plurk (6)
  • posterous (3)
  • Seesmic (2)
  • Social Network Research (2)
  • Sponsorship (1)
  • statistics (4)
  • Tools (44)
  • tumblr (1)
  • Tweet of the Week (10)
  • Twitter (221)
  • Uncategorized (27)
  • Video Microblogging (6)

Rankings

Wikio - Top Blogs - Technology

badgergravling on Twitter

    Click for the 140Char Twitter Bookstore

    rss Comments rss valid xhtml 1.1 design by jide powered by Wordpress get firefox