Twitter now blocking bad URLs, but imperfectly
IDG News Service - Hoping to deal with a growing problem, Twitter has quietly introduced a feature to prevent users from posting links to malicious Web sites. But security experts say that it can be easily circumvented.
The feature was first noticed Monday by Mikko Hypponen, chief research officer with security company F-Secure. When someone tries to post a link to a malicious Web site, Twitter pops up a short notification saying "Oops! Your tweet contained a URL to a known malware site," and, after a few seconds, deletes the post.
Twitter is using Google Inc.'s Safe Browsing API to check for malicious links, a Google spokesman confirmed Monday.
F-Secure says it's recommended that Twitter start doing this because the site "is increasingly targeted by worms, spam and account hijacking," according to Hypponen's blog post. A month ago, technology entrepreneur Guy Kawasaki's account was misused to post a link to a malicious Web site. In recent weeks users have been hit with links to fake, and sometimes malicious, "rogue" security software.
Security experts said that while Twitter's filtering is a good first step, it still needs some work.
In tests, the feature blocked a URL that led to a phishing site, but it allowed the same link to post if it was shortened using services such as Tinyurl.com or Bit.ly. Because Twitter enforces a strict 140 character limit on each message, these URL shortening services are the most common way of posting links to Twitter.
The filter also permitted the phishing link when the "www" subdomain was stripped from the front of the URL.
Twitter did not return messages seeking comment.
"This is a common problem with this sort of filtering service," said Chris Boyd, director of malware research with FaceTime Security Labs.
However, even if Twitter isn't blocking malicious URLs when they've been shortened, users still get some protection. That's because some of these URL-shorteners use the Google's API themselves. Bit.ly, which is used to post more than half of all Twitter links, uses the API to block people from visiting malicious sites, for example.
Boyd said it will probably take Twitter a while to get its Web filtering up and running properly, "but even some protection is better than none."
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- IDC Security Infographic From the Era Before security to this current era of empowerment this infographic from Blue coat provides a timeline navigates the rise of...
- Key Drivers: Why CIOs Believe Empowered Users Set the Agenda for Enterprise Security Several years ago, a transformation in IT began to take place; a transformation from an IT-centric view of technology to a business-centric view...
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Business Assureance Technology Infographic IT Leaders See security as barrier to enabling employees. However with new Business assurance technology you are able to give Continuity, Agility, and...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts