iEntry 10th Anniversary RSS Newsletter Advertising
Visit Twellow.com
Text: Decrease Font Size Increase Font Size | Print Print Article | Share: Delicious Digg StumbleUpon Post to Twitter Post to Facebook
7 commentsFriday, August 28, 2009

Update: Your Twitter Account is Still in Jeopardy

Huge Security Hole Uncovered

Update: There is now a video up on Dave Naylor's blog about the Twitter exploit, which I have embedded below. Meanwhile, Twitter has yet to respond to the issue via either the Official Twitter Blog or the Twitter Status Blog. They were kind enough to post a Ryan Seacrest video however.


Original Article: James Slater, writing on UK search marketer Dave Naylor's blog, uncovered a huge security issue with Twitter, and that issue has yet to be corrected. The skinny of it is if you tweet through Twitter.com, you may be putting your account in jeopardy.

James SlaterAccording to Slater (and the issue has been acknowledge by Twitter, just not fixed), anyone who simply sees your tweets from when you're logged into Twitter, can run some code inside your browser and take over your account, which can lead to malware spreading, impersonation, or whatever you can imagine.

That's not good.

Slater suggests the following steps for prevention:

 

- If you’re not logged in to Twitter, there’s no opportunity to steal your details or impersonate you, however malicious code could still send you to other websites or otherwise annoy you, so it doesn’t completely fix the problem.

- Unfollow anyone you don’t know or don’t trust that could be exploiting this. Who’s to say they’re not already stealing your details? If you don’t see their tweets they can’t harm you.

- If you use something other than the Twitter website to view your tweets, you should be fairly safe, though without looking at each one individually it’s hard to be sure. Still, you’re likely to be pretty safe this way.

Slater discovered the problem yesterday, and Twitter responded claiming to have fixed it, but Slater proved them wrong, and Twitter has yet to respond again. No posts yet on the Official Twitter blog about this issue, and not even on the Twitter Status blog. I would imagine that will change as this story is circulated more and more throughout the tech industry.

Hopefully they will have the problem fixed soon, before too many people take advantage of it. More of the technical details about what is happening can be found in Slater’s explanation.

About the author:
Chris Crum has been a part of the WebProNews team and the iEntry Network of B2B Publications since 2003. Twitter: @CCrum237

Twitter need better security

Yes as i commented in your (Chris) earlier post that Twitter need better security to maintain its trust in user otherwise it will become a platform for spammer and malicious people.Thanks James Slater and Chris .

I just wonder whether this

I just wonder whether this alarm can accelerate the process of acquistation of 'Twitter' by any company for the sake of improving security and funding?!

Publish A Comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
3 + 1 =
Solve this simple math problem and enter the result. E.g. for 1+3, enter 4.
SEARCH
Popular WPN Business Resources












Subscribe to WebProNews


Send me relevant info