On CNET: Tech gifts for every budget
BNET Business Network:
BNET
TechRepublic
ZDNet

April 12th, 2009

Lesser of two security evils: Twitter Web or third-party clients?

Posted by Jennifer Leggio @ 12:33 pm

Categories: Microblogging, Security, Social Media and Security, Social Networks, Twitter

Tags: Web, Worm, Twitter, Cyberthreats, Security, Viruses And Worms, Jennifer Leggio

Twitter Web might not be safe anymore and users may want to consider only tweeting and surfing through third-party applications for the time being. Yes, I know, there are all kinds of issues with using a third-party anything. And while I use and love TweetDeck and many are raving about Seesmic Desktop, you still need to give your Twitter user credentials away in order to use them. However, after the appearance of two worms on Twitter this weekend, users are faced with a choice between two evils — taking a chance on third party apps and using the Twitter Web Interface.

There were two Twitter worms reported over the weekend:

  • On Saturday, if a user happened to land on an infected Twitter profile page from Twitter Web, that user’s profile became infected as well. The worm would take over a user’s account and use it to spam out promotions for StalkDaily.com. A 17-year-old New Yorker named Mikeyy Mooney allegedly claimed responsibility for this worm.
  • Today, it was reported by Mashable that a second worm actually named “Mikeyy” was hitting Twitter. According to the report the “Mikeyy” worm posted messages to Twitter streams using the same technique as StalkDaily. One of the messages even mocks Twitter for it’s security flaws: “Twitter should really fix this…”

These only impacted Twitter users surfing profiles via Twitter Web. While both of these worms were only used for a sort of Twitter “adware” there’s a much bigger issue at hand. It doesn’t matter that these worms weren’t malicious. What matters is that there’s a door open that Twitter seems incapable of closing. The microblogging service reported on Saturday evening that it had fixed the issue. Clearly, given the prevalence of today’s worm, that was either untrue or they are in over their heads.

“Somebody is apparently bent on egging the Twitter property on a repeated basis,” said Damon Cortesi of Alchemy Security. “It would seem Twitter has fallen prey to focusing on features and doesn’t have a reliable and repeatable security process in place to help prevent security bugs.”

Cortesi concurs that these attacks are more nuisances than anything, but also states that given the flimsy nature of Twitter’s security a motivated criminal could take advantage of a similar attack to do more damage.

“Security is an ongoing piece of maintenance in software development and needs to be continually addressed as new attack vectors and issues are discovered. As projects get more complex, so do the potential attacks,”  Cortesi said. “Strong software development process that includes continual security review and testing is necessary to protect from current and future attacks.”

Next: Why does this keep happening? –>

Pages: 1 2

Jennifer LeggioJennifer Leggio, aka "Mediaphyter," writes about the "social business" side of social media - including enterprise, security and reputation issues. See her full profile and disclosure of her industry affiliations.


Email Jennifer Leggio

For daily updates on Jennifer's activities, follow her on Twitter.

Subscribe to Social Business via Email alerts or RSS.

  • Talkback
  • Most Recent of 4 Talkback(s)
RE: Lesser of two security evils: Twitter Web or third-party clients?
Twitter 2.0 Add-on for fring Available for WinMo and Symbian
Read more:
http://techunits.com/content/list_all/87/twitter... (Read the rest)
Posted by: lilykudrow Posted on: 04/14/09 You are currently: a Guest | | Terms of Use
You act so surprised  wolf_z | 04/13/09
RE: Lesser of two security evils: Twitter Web or third-party clients?  RTTECH82 | 04/13/09
RE: Lesser of two security evils: Twitter Web or third-party clients?  LiLac22281 | 04/13/09
RE: Lesser of two security evils: Twitter Web or third-party clients?  lilykudrow | 04/14/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline