Risk
6/24/2010
10:09 PM
50%
50%

Twitter, Feds Settle Security Charges

Twitter must establish and maintain a "comprehensive information security program" and allow third-party review of the program biannually for the 10 years.

Twitter has settled Federal Trade Commission charges that the social network put users' personal information at risk, while deceiving them about safeguards to protect data.

The settlement, announced Thursday, closed the FTC's first action against a social networking site for faulty security. Twitter's failings led to two well-publicized attacks, one of which resulted in a hacker gaining access to several high-profile accounts, including that of then President-elect Barack Obama.

The settlement requires Twitter to take a number of security steps to protect user data, steps the site said it has already taken. "Even before the agreement, we'd implemented many of the FTC's suggestions and the agreement formalizes our commitment to those security practices," Twitter said in response to the FTC's settlement announcement.

Nevertheless, the FTC said Twitter failed to provide the security it promised users.

"When a company promises consumers that their personal information is secure, it must live up to that promise," David Vladeck, director of the FTC's Bureau of Consumer Protection, said in a statement. "Likewise, a company that allows consumers to designate their information as private must use reasonable security to uphold such designations."

The first security breach occurred in January 2009 when a hacker used an automated password-generation tool to continuously try to log in to a person's account. In some cases, the hacker made thousands of attempts before striking pay dirt. Twitter's culpability was in failing to implement password rules that would have led to stronger passwords, the FTC said. In addition, Twitter should have had technology in place to lock out the hacker after several failed attempts.

The hacker accessed the accounts of 45 Twitter users, including Facebook, Fox News, The Huffington Post, Obama, Britney Spears and CNN host Rick Sanchez. In some cases, the hacker sent phony tweets under the accounts. Tweets are the short messages of 140 characters or less people broadcast to followers on the site.

A bogus tweet sent from Obama's account offered his more than 150,000 followers a chance to win $500 in free gasoline, according to the FTC.

The second breach occurred in April 2009 when a hacker broke into a Twitter employee's administrative account by first accessing the employee's Yahoo e-mail account, where the password was stored in plain text.

In gaining access to the administrative account, the hacker could access private information from any Twitter user, according to the FTC. The hacker did post more than a dozen screenshots of Twitter's administrative console on several Web sites.

To help prevent the second breach, Twitter should have prohibited employees from storing passwords within personal e-mail accounts, enforced periodic changes of administrative passwords, restricted access to administrative controls to employees whose jobs required it and imposed other reasonable restrictions on administrative access, the FTC said.

Under the terms of the settlement. Twitter is barred for 20 years from misleading users about the extent to which it protects their privacy and personal information. The company also must establish and maintain a "comprehensive information security program," the FTC said. A third party has to assess the program every other year for 10 years.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5211
Published: 2015-01-27
Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response.

CVE-2014-8154
Published: 2015-01-27
The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which trigger a heap-based buffer overf...

CVE-2014-9197
Published: 2015-01-27
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

CVE-2014-9198
Published: 2015-01-27
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

CVE-2014-9646
Published: 2015-01-27
Unquoted Windows search path vulnerability in the GoogleChromeDistribution::DoPostUninstallOperations function in installer/util/google_chrome_distribution.cc in the uninstall-survey feature in Google Chrome before 40.0.2214.91 allows local users to gain privileges via a Trojan horse program in the ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.