Click to Play

Traditional Media Vs. Digital Media
Although we consider ourselves on board and moving with the digital age, there are some areas that are taking longer to evolve. One such area is the transition...

Recent Articles

Stay On Top Of The Latest Twitter Apps
For day-to-day interacting with Twitter, you can't beat a good third-party app in my experience. As to which is the best one, that's largely a matter of subjective...

Thoughts To Consider When Building Your Social...
Starting a social media team? Here are some high level thoughts that you should consider before you get started. This is not a comprehensive list and there...

Vquence Offers Tracking And Analytics For Video Data
Social video technology and consulting company Vquence launched a new social video metrics product called VQmetrics with an event in Sydney last week. The online SaaS (Software as a Service) product is used...

Keep Track Of Different Metrics With StatCounter
Last week StatCounter launched a new service called GlobalStats which allows uers to take a look at 7 different metrics at an aggregate level across all StatCounter users. The different metrics include...

Making Web 2.0 Technologies Work For You
Here are several excerpts from an excellent article in The McKinsey Quarterly by Micheal Chui, Andy Miller and Robert P. Roberts of McKinsey & Company, Six...


05.06.09

Twitter Had Its Admin Infrastructure Cracked Causing Alarm For Social Networking

By Dan Morrill

Nothing says "going to have a bad day" than to have someone crack open the admin panel to one of the hottest social networking properties out there. But Twitter has had at least one of their admin accounts cracked, with pictures both on Mashable and Korben.

The bad part is that Twitter had its admin infrastructure cracked, but this should be ringing alarm bells across the social networking sphere. Information security is just as important in social networking as it is in any other online pursuit that people will engage in. The problem is further highlighted in that if I can download the few million e-mail addresses, websites, and other information that is often directly associated with people's data, then the ability to target people becomes so much easier. This just makes finding people and spear phishing that much easier, which is one of the bigger drawbacks when someone hacks a social networking system.


Ektron CMS400.NET Now With PageBuilder:
Instant Demo


It might be cool to look at, and the admin interface is indeed interesting, but from the viewpoint of people who will end up cleaning up the mess at twitter, the unknown number of people who have had their information downloaded, and the unknown amount of time this was available to the people who did this you could pretty much assume that the entire user base at twitter has been at the very least copied off somewhere, and is in hacker data exchange channels. Not a good day for twitter, or for the systems users.

Twitter has been hit with worms, and a whole host of other malware. You are seeing spammers and ethically challenged marketers using the system to push whatever product works (the lastest is swine flu medications) in the here and now. This is a detractor from the user experience, and something that anyone using a social networking system, or businesses that rely on these systems should be seriously putting in as part of their disaster recovery plans. Hacking systems are good enough that they could impersonate anyone, if you got an e-mail from a company, you might or might not click on it, but if you got a tweet from a company, you might just go follow the link.

User training is going to have to step up, even if they say you are their friend, it might not be healthy for your computer to click on links in twitter for a while.

Comments



About the Author:
Dan Morrill has been in the information security field for 18 years, both civilian and military, and is currently working on his Doctor of Management. Dan shares his insights on the important security issues of today through his blog, Managing Intellectual Property & IT Security, and is an active participant in the ITtoolbox blogging community.
CTOupdate is brought to you by:
SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
DatabaseProNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com ITmanagementNews.com


About CTOupdate
A collection of Articles an news designed to keep professionals in the tech industry informed about the latest developments in an ever changing landscape Tech News and Updates for Tech Professionals




-- CTOUpdate is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
© 2009 iEntry, Inc. All Rights Reserved Privacy Policy  Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article



Tech News and Updates for Tech Professionals CTOUpdate News Archives About Us Feedback CTOUpdate Home Page About Article Archive News Downloads WebProWorld Forums Jayde iEntry Advertise Contact