• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
TheWayoftheWeb

TheWayoftheWeb

Content and Digital Marketing Specialists

  • Blog
  • The Cipher
  • About Us
    • Useful Resources For Businesses In Peterborough, UK
  • Contact Us
  • Show Search
Hide Search

security

The aftermath of Twitters biggest phishing scam

March 1, 2010 By Dan Thornton

Over the last week, many people have fallen foul of the latest phishing scam to do the rounds of Twitter. And an unusual number of high profile individuals have been included in the list of users affected, including the Press Complaints Commission, BBC correspondent Nick Higham, the Guardian’s Head of Audio Matt Wells, bank First Direct, and environment minister Ed Milliband.

Environment Minister Ed Milliband caught by phishing scam
Environment Minister Ed Milliband caught by phishing scam

Phishing scams have long been endured by most internet users – the traditional mechanism has been via email, but as social networks have becoming hugely popular, they’ve become the vector of choice. And Twitter is particularly attractive as the speed with which messages can spread is combined with the use of short urls, which help to mask the malevolence of the message.

While this is just another example of the huge amount of phishing attempts which exist, the higher profile of these attacks as they affect prominent politicians will hopefully lead to a better awareness and response by governments.

It’s probably a forlorn hope, but for example, here are some things which might change:

  • More education about phishing and spam to the ‘general public’ – how about a public awareness campaign?
  • More understanding about how normal users can have accounts compromised very easily – for instance, with ‘Three Strikes Rules’.
  • More people using offline backups of any content that is valuable or useful to them
  • More of a move towards data privacy, and Vendor Relationship Management, to allow users to only share the information they choose with any service provider under strict controls.
  • A rethink of the UK Identity Card scheme which includes private businesses taking fingerprint and photos.

Importantly, it should place the risks of Social Engineering alongside those of teenage cyberwarfare specialists taking down defence satellites from their bedroom. If a private company was, for example, storing fingerprint data, you wouldn’t need to target their infrastructure (Although I’m not sure most chemists have a particularly high level of internet security) – you’d use social engineering on their employees via Facebook, Twitter, or offline in person to gain information and access.

Of course, technology can play a part, and I’m sure Twitter will increase their response to phishers in future, particularly as a high profile attack via any platform is never good for PR. But any measures will always be part of a never-ending arms race, and only when every individual is educated enough will there be any noticeable difference…

Google Buzz proves problems with single online identities

February 24, 2010 By Dan Thornton

I’m assuming most people have been caught up in the huge amount of discussion around Google Buzz, the new social sharing and conversation tool from Google which surprised a lot of people by suddenly appearing as a full release within Gmail, and again by having some serious privacy problems at launch, which Google has had to work hard and fast to rectify.

But I think the launch of Google Buzz has simply highlighted the inherent problems with the move towards a single profile and identity for each internet user, whether that ends up being controlled by Google, Facebook, or an alternative service. Particularly as Google tested the system internally, where everyone had a Gmail account and several of the public problems just never arose.

1.  Security:  Almost everyone has encountered a scam or phishing attempt by email or a social network. There’s no way to eradicate these entirely, and a single identity which is then linked out to every other internet location would be a valuable prize for phishers. Seperate logins encourage you to use seperate passwords, so if one acocunt is compromised you’ll be able to alert people and still get on with most things – For example, my online email is backed up elsewhere, and contacts are replicated between Gmail and LinkedIn, so I could get the word out if problems occurred. Stalking also becomes a lot easier if everything is linked to one central location.

2. Embarrassing Content: This doesn’t have to just mean naughty pictures, although if you’re of legal age then I have no problem with you using the internet how you like. But it can also mean drunken photos and comments, or perhaps surprise presents or events being organised online which end up being discovered. The rule of thumb is to never publish anything online that you’d mind anyone seeing, even if it’s behind the thin veneer of a privacy setting, but we’d all still like to have some illusion of control over whether our boss discovers the pictures of our last night out, and we certainly wouldn’t want to ‘cross the streams’ and inadvertently shove it in front of him or her.

3. Different tools for different things, and added hassle: I’m a slight edge case here as I use several work accounts in addition to my own on a lot of networks, but even within my house, there is a shared computer which has at least two profiles used on the same site. Switching accounts suddenly becomes a real hassle – for instance, Youtube now automatically logs me in with my Google Profile, forcing me to log back out and then in again as Absolute Radio or OGS Labs.

4. Anonymity can be a good thing: Obviously this crosses over with the security and embarrassment issues, but not every anonymous person is a troll or 4Chan prankster. Take Wikileaks as an example of the positives that can come from anonymity.

5. Dependancy: Most people are combining email and social networks in varying amounts now, but if your email and social network ids are combined and potentially based in the cloud, any loss of access will leave you completely stuck. Or if your profile is removed for any reason, whether it’s a mistake or justified removal by whichever company controls all of your details…

But maybe there is a solution.

The people discussing Vendor Relationship Management hold the secret. Let me own some software – ideally Open Source, which is stored locally on my own devices, and then allows for the initial interaction with networks and service providers. And potentially have a mirror of certain elements of that software which is securely stored online somewhere that is also owned entirely by me. And that online element can then be differentiated into each of my personal and work profiles allowing me to quickly and easily switch between them, and not cross the identity streams. Companies would be able to access the particular information I wish to share with them, and use of that system would be a key part of digital education, which would implicitly educate people about privacy and sharing issues.

The only problem with this is who would store that info online – would you trust the Government of your country any more than Google, Facebook or Amazon?

Big money for hacked Twitter accounts

January 31, 2010 By Dan Thornton

Stolen Twitter accounts appear to be commanding a premium amongst hackers sharing details on forums.

Data stealing software is a risk to your details for any site, but according to Kaspersky researcher Dmitry Bestuzhev, he’s seen  a Twitter account with just 320 followers offered for as much as $1000. In this case, the three-letter username may have influenced the price.

That compares with Gmail accounts for $82, Rapidshare accounts for $5 per month, and other sites including Skype and Facebook. Bestuzhev also went on to say Kaspersky had detected 70,000 data stealing programmes in 2009, which is twice as many as in 2008.

Twitter is likely to be a preferred route to spread malware as links can spread in near real-time to hundreds or thousands of followers – each of whom can quickly and easily repeat a malware message to their own network.

Malware messages are also hidden by shortened urls, and with the amount of links spread via Twitter, there’s a good chance people are less suspicious than seeing the same links in an email or IM message.

It’s a reminder to make sure you use a unique password which is a mix of alphanumeric characters, and to change it regularly. Be careful of sharing it with third party sites and tools which aren’t using Twitter’s OAuth protocol, and be careful with links being posted by others – even including people you trust.

(Via Computerworld)

Stocktwits gets funding, Bit.ly get’s safer, Cli.gs gets bought

December 2, 2009 By Dan Thornton

The Twitter ecosystem is busy as always, so rather than try to write 20 posts to cover everything purely for SEO benefit, I thought I’d round up three things which stood out:

Stocktwits has gained $3 million in another round of financing for the social and microblogging network for the stock market. It’s interesting that the service has spun out of Twitter, building its own platform and Adobe Air desktop application which came into life in September. In addition Stocktwit.tv seems to be taking off.

Rather than building your own social network from scratch, perhaps a more realistic plan is to build community on the main Twitter site, before spinning off as Stocktwits have done – a technique that would work on any social network…

URL shortener Bit.ly (as set as the default shortener on Twitter, and heavily used by yours truly) has announced a partnership with security firms including Websense, Sophos and VeriSign to help address the problems of spam and malware-spreading shortened links which are otherwise difficult to spot (Bit.ly already offers a plugin to expand links before you click on them). That adds onto Twitter’s malware detection, and Bit.ly’s spam filtering.

For reference, Bit.ly shortens 35-40 million links a day, and apparently spam links make up less than 0.5% of that number…

And finally, fellow url shortener Cli.gs has been bought by social bookmarking site Mr Wong. That’s good news for users, and also for the White House, which uses Cli.gs. The reason for the sale is given as the time and effort needed on behalf of the founder – something which makes sense in the context of Bit.ly’s 40 million links a day!

Interesting responses to Twitter security worries

January 5, 2009 By Dan Thornton

Following my previous post on the implications for Twitter of the first large scale phishing attack, I’ve seen a few interesting responses:

First up, @benbarden responded to my concerns over short urls by suggesting that people could host their own, e.g. thewayoftheweb.net/link1 etc.

A pretty cool idea, and one that Ben is apparently running on a site already (I might have to beg him for a guide!). The only flaw is that a lot of people run hosted blogs, and will therefore still be at the mercy of shortening services. But for those of us paying hosting costs it’s worth considering.

Then the always friendly @mingyeow from MrTweet asked my opinions on a blog post ‘Addressing Privacy Concerns‘. Suffice to say it’s a very eloquent explanation of how and why the developers of one application are aiming to keep your accounts safe:

One of the points raised is that MrTweet will support OAuth as soon as it becomes available, although it won’t answer every security question, because, as they quite rightly say, securityand convenience are always a trade-off.

There’s some really interesting debate around the use of OAuth from both Jesse Stay on LouisGray.com, and Dave Winer.

  • « Go to Previous Page
  • Page 1
  • Page 2

Primary Sidebar

Join us…

  • Facebook
  • Instagram
  • LinkedIn
  • RSS
  • Twitter

We only exist to deliver results for your business. So you get fresh Content, expert SEO, engaging Social Media, or a new Website which is right for you – and your customers.

We help you build your brand, reach more customers and increase your revenue

Search

Categories

Creative Commons License
This work by TheWayoftheWeb is provided under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.

Start growing your business today Contact Us

TheWayoftheWeb

Copyright © 2026· TheWayoftheWeb Ltd. Company Number 08038527. ICO registration: ZB397650