On CHOW: Are five meats enough for pizza?
BNET Business Network:
BNET
TechRepublic
ZDNet

July 15th, 2009

The Twitter hack: Let's not start blaming Google or the cloud

Posted by Sam Diaz @ 11:49 am

Categories: Cloud computing, Google, Twitter

Tags: Google Inc., Document, Password, Twitter, Security, Sam Diaz

updated below:

Have you been following this controversy surrounding some confidential documents swiped from Twitter and sent to the folks at TechCrunch? The site’s editors have been engaging in a discussion over ethics, specifically whether or not to post these “stolen” documents.

For what it’s worth, this is a discussion that mainstream news outlets have been having for generations. If I were part of those discussions, I’d skip anything in those documents that has no value - such as a document that does nothing more than embarrass someone. But I would definitely consider posting information about business strategies, revenue projections and so on - after confirming their authenticity.

It’s unfortunate that a hacker was able get his hands on these documents and pass them along. But as a journalist, I’m less interested in how these documents were obtained and more interested in their validity. Anonymous sources regularly feed information to news agencies - anyone who reads the Wall Street Journal knows that.

With all of that said, my reason for chiming in here is not about the documents, but rather the blame game. In particular, I take exception with the idea that Google - which was storing the documents on the cloud - is somehow responsible for this hack. In the comments section of his original post on this subject, TechCrunch editor Michael Arrington writes:

the original security hole seems to be Google, via Google Apps for your Domain. Some passwords were guessed and things started to fall apart from there. Most (or all) of these documents were downloaded from Google’s servers.

Then, in a subsequent post, where he tries to justify why he is considering posting some of the documents, he writes:

It’s not our fault that Google has a ridiculously easy way to get access to accounts via their password recovery question. It’s not our fault that Twitter stored all of these documents and sensitive information in the cloud and had easy-to-guess passwords and recovery questions…

hopefully this situation will encourage Google and Google users to consider more robust data security policies in the future.

Hogwash.

Sure, maybe Google could come up with a better password-recovery system - but this isn’t Google’s fault. Bottom line: Twitter used an easy-to-guess password and recovery question. That’s how the hacker was able to get in - not because Google has some sort of security hole.

On my personal accounts, I use a password that’s not only easy for me to remember but, more importantly, pretty much impossible for anyone to guess - unless, of course, you have some sort of inside knowledge into details of my childhood that even my own mother probably wouldn’t guess. Even with my work accounts, I regularly have to change passwords and follow their rules on the use of numbers, letters, symbols and so on as a means of keeping the network secure. From what I can tell, that process - albeit somewhat inconvenient at time - is effective.

So, let’s just leave Google and the cloud out of this debate. The finger of blame points in one direction and one direction only: Twitter.

updated: In a blog post, Twitter co-founder Biz Stone addresses the hack and offers users an explanation as to how this happened. It’s worth noting one specific line in his post: “This attack had nothing to do with any vulnerability in Google Apps which we continue to use.”

Thanks for the update, Biz. I’m glad you included a line in your post about Google. It was the right thing to do.

Sam Diaz

Sam Diaz is a senior editor at ZDNet. See his full profile and disclosure of his industry affiliations.

Email Sam Diaz

Subscribe to Between the Lines via Email alerts or RSS.

  • Talkback
  • Most Recent of 11 Talkback(s)
RE: The Twitter hack: Let's not start blaming Google or the cloud
amazing how ones ego can cloud ones response or judgment. There are two factors here.
1. Poor password and hint created by the user - this is still the #1 cause behind any security breach.
2. Th... (Read the rest)
Posted by: justinco Posted on: 07/17/09 You are currently: a Guest | | Terms of Use
Of course not. You would not want  GuidingLight | 07/15/09
Will you be this generous with Microsoft?  Fark | 07/15/09
Not Google issue...  SamDiazZDNet Moderator | 07/15/09
Is Karl Rove coaching ZDNet posters now?  storm14k | 07/15/09
To each their own, I imagine  GuidingLight | 07/15/09
Agreed! Same when Mac falls off the rails. /eom  Arapey | 07/15/09
Twitter has the same security hole/weakness as MS Passport did!  kd5auq | 07/15/09
Consider the non Google Apps scenario:  ZDnet Reader 43 | 07/15/09
Bingo!  kd5auq | 07/16/09
It's just ONE layer of password protection  jirving@... | 07/16/09
RE: The Twitter hack: Let's not start blaming Google or the cloud  justinco | 07/17/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here