• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
TheWayoftheWeb

TheWayoftheWeb

Content and Digital Marketing Specialists

  • Blog
  • The Cipher
  • About Us
    • Useful Resources For Businesses In Peterborough, UK
  • Contact Us
  • Show Search
Hide Search

developers

Twitter phishing attack – the implications

January 5, 2009 By Dan Thornton

Twitter has been hit by the first major effort to ‘phish‘ account details and spam users with links to a fake login page by Direct Messages from comprimised accounts.

The Twitter team has responded with a warning on the main web access page, and a warning on the Twitter blog. You can see the uproar it’s causing on Twitter via Twitter Search.

Currently the DMs are enticing people with:

  • Here’s a funny blog about you
  • Your picture is on this blog
  • You’ve won a free iphone

Luckily the phishers are at least sticking to the grand tradition of email spamming by either trying to entice you with a blatantly ‘too good to be true’ offer, or something personal with the link to a fake Twitter log-in page displayed in full, so hopefully the word has spread to most people.

However, this is likely to be just the start. As Pete Cashmore pointed out at Mashable, this is a sign Twitter has reached a big enough size to be a viable target for scams – a positive sign for Twitter’s growth perhaps, but also a sign that the scammers and spammers are coming, with pretty big implications for Twitter users.

Shortened urls:

For starters, we were all lucky in some ways that the bloggers obviously aren’t familiar with Twitter culture, and were displaying the full url of the fake website, meaning that even if the DM came from someone we absolutely trusted, we had a warning before clicking.

But given that the character limit of Twitter means that shortened urls are the norm, it will make it almost impossible to detect whether a link is likely to be fake before at least visiting it – meaning an urgent need for preview functionality of shortened urls at the bare minimum.

Warning systems:

A lot of Twitter users picked up on the scam emails via friends, and stayed up to date with information via the #phishing hash tag etc – Twitter responded promptly with a warning on the website and blog. But what about the many, many people using a client to access Twitter and their Direct Messages? And those using mobiles to access the service?

Will everyone get a warning via each client and application? Unlikely at the moment, unless there is a type of ’emergency signal’ which could be broadcast across all clients and apps.

Verified App Store:

Which brings me to the next possible implication – a few people have suggested that the fake log in page is in fact working as a Twitter application to utilise the stolen accounts and passwords.

It’s long been a matter of contention for users and app developers that any 3rd party application which requires a certain level of functionality has to ask for usernames and passwords – but now the 3rd party developers could be hit by a huge loss of trust from users.

So could this be an opportunity for a verified and approved Twitter application resource? Possibly monetised by charging a fee for consumers (unlikely), or for developers to have their application tested and approved (more likely)?

This could have implications for the speed and amount of Twitter applications and clients being produced, and also move such development away from bedroom coders depending on the fees for such services.

It certainly means that there could be a move for more users to utilise more than one Twitter account to allow them to test applications and clients etc without comprimising their main account.

So what other implications do you think the arrival of large scale phishing attacks could have on Twitter – and what suggestions do you have for other Tweeple – and Twitter itself, to try to minimise the damage of future attacks?

How much does it take to make a Twitter app?

January 2, 2009 By Dan Thornton

It’s a popular question today, after both Techcrunch and Mashable covered the launch of The New Platforms Fund, which will invest between $1000-$3000 in 10 ideas (plus human support), in exchange for a minor equity stake.

Techcrunch was pretty disparaging about the idea (headline: If you are really, really desperate for cash, these guys will give you $3k) Mashable’s take was a bit more open about the diea.

If you want to apply, the form is here.

But what is quite interesting is the debate in the TC comments around how much this could actually fund – obviously it’s not enough to pay for a team of developers for a year, but could it help 1 or 2-person start-ups just out of college to spend a month or two on one idea?

Or, given the current state of the economy and job market, could it be enough to make the mortgage payment for a month whilst you try something different? Or to get the services of a developer or designer for a week or two to make a simple concept into reality?

After all, Stocktwits got more funding after just two months.

But do you think $1-3k is enough to get something started? And is it worth giving up some equity in order to reach another round of funding?

Why make excuses?

June 6, 2007 By Dan Thornton

As much as I try to avoid the internet trap of constantly reciting buzzwords and cliches, I realised during my recent sabbatical that I’ve fallen into one of the most common habits of anyone working on the net…

Making excuses…

When I buy a new household gadget, like the vacuum cleaner and washing machine I recently purchased, I expect to just plug them in and go. And the vacuum cleaner, despite only costing £30, has actually been pretty enjoyable, and made cleaning up during my house move fun. It’s small, light, bagless, and has enough suction to pick up anything I need it to. Plus it makes a noise akin to a jet engine on take-off. Meanwhile the washing machine cleans clothes, and has a timer to let me know how long before it’s ended. They’re not the best, most expensive, or coolest gadgets, but they work.

Which is why it’s a shock to get back to explaining the reason a website doesn’t work properly is because of deadlines, or developer problems, or integrating technology, or the server caching, or one of the other 100 stock reasons why things don’t always run smoothly. Even the best sites experience niggles and occasional problems, and it seems to be accepted because ‘it’s the way the internet is’.

I’s probably a hang up from the days that installing even a game or small programme on your PC took days as everything conflicted, followed by the two hour wait for a page to download from a site in the glorious dial-up era. But every time an excuse is made, it makes it more acceptable for things to continue in the same way.

There’s no reason for a lot of problems. Adequate hosting and server space, proven software solutions, and good developers are all out there. You just have to use them, and not make excuses if things aren’t going so well.

On a brighter note, my Zen Broadband account has been transferred, and worked perfectly from the moment everything was plugged in again. That’s how it should be, even if the delay was double by BT not issuing a simultaneous move code which actually worked! I’ll have to check my speed tonight to see if moving to within 500 metres of the phone exchange (from 3.34km away!) has made a big difference.

  • « Go to Previous Page
  • Page 1
  • Page 2

Primary Sidebar

Join us…

  • Facebook
  • Instagram
  • LinkedIn
  • RSS
  • Twitter

We only exist to deliver results for your business. So you get fresh Content, expert SEO, engaging Social Media, or a new Website which is right for you – and your customers.

We help you build your brand, reach more customers and increase your revenue

Search

Categories

Creative Commons License
This work by TheWayoftheWeb is provided under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.

Start growing your business today Contact Us

Recent Comments

  • Don't wait for your ship to come in... - TheWayoftheWeb on Freelance & Consultancy

TheWayoftheWeb

Copyright © 2026· TheWayoftheWeb Ltd. Company Number 08038527. ICO registration: ZB397650