Twitter: A Growing Security Minefield
As it explodes in popularity, the micro-blogging site attracts the bad guys
PC World - In June, the world watched as tweets from the streets of Tehran flooded Twitter. Frequent Twitter users--and people who hadn't even heard of the microblogging service--were suddenly and simultaneously witnessing its potential.
At the same time, antivirus vendors were warning of new phishing attacks that spread via Twitter. Using Twitter accounts, phishers would follow users and then infect them via a link to a fake profile page laden with malware. Like instant messaging, MySpace, and Facebook before it, Twitter had come of age.
After three years of relatively quiet development and growth, the service's meteoric rise in 2009 has been rough. Aside from scaling issues due to the influx of new users, in January a Twitter hack compromised the accounts of 33 high-profile users, including President Barack Obama, CNN anchor Rick Sanchez, and entertainer Britney Spears.
In April, a Twitter worm known as "Mikeyy" or "StalkDaily" reared its head. Similar to the 2005 Samy worm on MySpace, the Mikeyy worm was authored by a 17-year-old who took advantage of a code quirk to gain notoriety for his Web site, StalkDaily.com. Twitter shut it down--plus a few follow-up viruses ("How TO remove new Mikeyy worm!")--fairly quickly. Following the worm attacks, cofounder Biz Stone wrote on the company blog, "Twitter takes security very seriously and we will be following up on all fronts."
Shortened-URL Dangers
Parallel to the growth of Twitter is the expansion of URL-shortening services. Fitting your thoughts into 140 characters takes practice; including full URLs is almost impossible. Usually URLs have to be truncated through services such as Bit.ly and TinyURL.com, which also mask the true destination URL and can present their own security problems as a result.
The first signs of shortened-URL trouble came with a pair of Twitter worms that promised to help users remove the Mikeyy worm. In June, a wave of hidden poisoned URLs swept Twitter, using Bit.ly links to low.cc and myworlds.mp domains where users were asked to download a file called free-stream-player-v_125.exe to view a video. The file held malware. Bit.ly and TinyURL have been responsive to reports of abuse; Bit.ly, for one, now blocks those low.cc and myworlds.mp domains.
At least one security product, ZoneAlarm, blocks access to TinyURL.com by default, listing it as a potentially malicious site (you can unblock it). You have other ways to protect yourself, too. TinyURL has a preview feature, and Firefox has a Bit.ly preview add-on. Some Twitter apps, such as TweetDeck and Tweetie, also preview the URL before you click.
Security researcher Aviv Raff designated July 2009 as "A Month of Twitter Bugs" during which researchers are to disclose a new Twitter vulnerability each day. Citing previous efforts focused on browsers and on Apple Mac OS vulnerabilities, Raff says his goal is not to break Twitter but to improve it and to address all social networking flaws: "I hope that Twitter and other Web 2.0 API providers will work closely with their API consumers to develop more secure products." The first disclosed Twitter bug concerned cross-site scripting flaws in Bit.ly. Within hours of the disclosure, Bit.ly corrected them.
Twitter Watch
- Twitter jumps on Do Not Track bandwagon
- With money in the bank, Twitter in no rush for IPO
- In 6 years, Twitter becomes major social, political player
- Twitter exec calls tweets the 'ultimate business intelligence tool'
- Twitter unveils redesign, touts ease-of-use
- Steve Jobs' death creates Twitter surge
- Twitter hits 100M active users, trumpets influence
- Twitter snags 'significant' funding, looks to expand reach
- Twitter gets down to business with promoted tweets
- In another shake-up, Twitter co-founder Stone steps away


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three...
- Driving Secure Enterprise File Sharing and Syncing in the Enterprise
- GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
- The Enterprise File Sharing Option
- Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
- Activities Streams Base An Integrated Social Layer
- The enterprise social software market is exploding thanks to converging trends of consumerization, cloud, and mobile. In this must-read report, "The Forrester Wave:...
- Converged Infrastructure for Dummies
- As you know, everything is mobile, connected, interactive, and immediate. This is exactly why organizations need a highly agile IT infrastructure in order... All Applications White Papers
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - BMC Control-M - Single Point of Control Demo
- With BMC Control-M, you schedule and manage everything - down to the very last platform and application - from one simple interface. It's...
- Operational Analytics - Changing the Competitive Dynamics of the Business
- Date/Time: June 5, 2012, 11:00 a.m., EDT, 4:00 p.m. BST / 3:00 p.m. UTC
Please join us for this webcast, as Dr. Barry... - Oracle Database Appliance Best Practices
- Business users increasingly demand 24x7 availability of their data while IT departments face the challenge of ensuring maximum availability while operating with limited... All Applications Webcasts