AP Twitter hack looks like a security tipping point
Two-step identity verification and analysis of user trends could prevent future attacks, experts say
IDG News Service - Getting hacked on Twitter is fast becoming a rite of passage for big corporations, but Tuesday's attack on the Associated Press could be a tipping point and shows that social networks must do more to keep their users safe, security experts said.
Wider use of two-factor authentication, which can involve an access code being sent to a user on a second device such as a smartphone, is one possible solution. Such a mechanism could be introduced selectively, some experts said, for high profile accounts such as celebrities and large corporations.
"Twitter needs to get on board and make two-factor authentication available ... as fast as possible," said Andrew Storms, director of security operations at nCircle Security.
The AP's Twitter account was hacked Tuesday morning, resulting in a bogus tweet reporting that there were "two explosions in the White House and Barack Obama is injured." A group calling itself the Syrian Electronic Army claimed responsibility, via their own Twitter account.
The tweet was only visible for a matter of minutes, but the Dow Jones industrial average took a nose dive immediately after it was posted before recovering several minutes later. Unlike some previous hacking incidents, "this one had a real-world impact on the markets," noted Steve Brunetto , director of product management at EdgeWave, a social media and email security company.
The AP joins a list of companies that have recently been hacked on Twitter. Three CBS brands -- 60 Minutes, 48 Hours and a Denver news affiliate -- were hijacked this past weekend. The New York Times, The Wall Street Journal and The Washington Post have also been hacked in recent months. In February, Twitter announced the site itself had been breached.
The Twitter accounts of Burger King and the Jeep car company have also been compromised. After those incidents, Twitter urged users to be smarter with their passwords and in how they use the site.
Twitter has remained largely quiet following Tuesday's AP attack. "We don't comment on individual accounts for privacy and security reasons," a spokesman said. But now may be the perfect time for the social network to employ stronger safeguards to prevent future account breaches, some experts said.
"Twitter needs to move faster in stepping up its cybersecurity efforts," EdgeWave's Brunetto said.
Mark Risher, CEO at Impermium, an Internet security firm based in Redwood City, California, said he thinks Twitter already takes security seriously, but Tuesday's attack does "elevate" concerns, he said.
One strategy would be for Twitter to implement a two-step authentication system. In one common implementation, when users log into the site from their laptop, Twitter would send them a passcode to a second device, such as their mobile phone. They would then need to enter that code as well as their login and password to access the site.
- Best iPhone, iPad Business Apps for 2014
- 14 Tech Conventions You Should Attend in 2014
- 10 Desktop Apps to Power Your Windows PC
- How to Add New Job Skills Without Going Back to School
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- The 12 PCI DSS 3.0 requirements addressed by Peer 1 Hosting This handy quick reference outlines the 12 PCI DSS 3.0 requirements, who needs to be compliant and how Alert Logic solutions address the...
- Defense Throughout the Vulnerability Life Cycle This whitepaper provides insight into how to leverage threat and log management technologies to protect your IT assets throughout their vulnerability life cycle.
- Mobile Policy Checklist Here's what to consider when putting together a mobile policy designed to support a highly productive workforce.
- Securing BYOD Mobile computing is becoming so ubiquitous that people no longer bat an eye seeing someone working two devices simultaneously. Individuals and organizations are...
- Live Webcast On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy...
- Live Webcast Endpoint Backup & Restore: Protect Everyone, Everywhere Arek Sokol from the bleeding-edge IT team at Genentech/Roche explains how he leverages cross-platform enterprise endpoint backup in the public cloud as part...
- Streamline Software Asset Management, Compose a software Management Symphony Keeping track of your organization's software is easy with effective software management solutions from CDW. View the videos in our software solutions channel
- Druva inSync: Endpoint Data Protection & Governance CLICK HERE to watch this video about protecting corporate data on laptops and mobile devices, sponsored by Druva. All Security White Papers | Webcasts