Risk
6/24/2010
10:09 PM
50%
50%

Twitter, Feds Settle Security Charges

Twitter must establish and maintain a "comprehensive information security program" and allow third-party review of the program biannually for the 10 years.

Twitter has settled Federal Trade Commission charges that the social network put users' personal information at risk, while deceiving them about safeguards to protect data.

The settlement, announced Thursday, closed the FTC's first action against a social networking site for faulty security. Twitter's failings led to two well-publicized attacks, one of which resulted in a hacker gaining access to several high-profile accounts, including that of then President-elect Barack Obama.

The settlement requires Twitter to take a number of security steps to protect user data, steps the site said it has already taken. "Even before the agreement, we'd implemented many of the FTC's suggestions and the agreement formalizes our commitment to those security practices," Twitter said in response to the FTC's settlement announcement.

Nevertheless, the FTC said Twitter failed to provide the security it promised users.

"When a company promises consumers that their personal information is secure, it must live up to that promise," David Vladeck, director of the FTC's Bureau of Consumer Protection, said in a statement. "Likewise, a company that allows consumers to designate their information as private must use reasonable security to uphold such designations."

The first security breach occurred in January 2009 when a hacker used an automated password-generation tool to continuously try to log in to a person's account. In some cases, the hacker made thousands of attempts before striking pay dirt. Twitter's culpability was in failing to implement password rules that would have led to stronger passwords, the FTC said. In addition, Twitter should have had technology in place to lock out the hacker after several failed attempts.

The hacker accessed the accounts of 45 Twitter users, including Facebook, Fox News, The Huffington Post, Obama, Britney Spears and CNN host Rick Sanchez. In some cases, the hacker sent phony tweets under the accounts. Tweets are the short messages of 140 characters or less people broadcast to followers on the site.

A bogus tweet sent from Obama's account offered his more than 150,000 followers a chance to win $500 in free gasoline, according to the FTC.

The second breach occurred in April 2009 when a hacker broke into a Twitter employee's administrative account by first accessing the employee's Yahoo e-mail account, where the password was stored in plain text.

In gaining access to the administrative account, the hacker could access private information from any Twitter user, according to the FTC. The hacker did post more than a dozen screenshots of Twitter's administrative console on several Web sites.

To help prevent the second breach, Twitter should have prohibited employees from storing passwords within personal e-mail accounts, enforced periodic changes of administrative passwords, restricted access to administrative controls to employees whose jobs required it and imposed other reasonable restrictions on administrative access, the FTC said.

Under the terms of the settlement. Twitter is barred for 20 years from misleading users about the extent to which it protects their privacy and personal information. The company also must establish and maintain a "comprehensive information security program," the FTC said. A third party has to assess the program every other year for 10 years.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5426
Published: 2014-11-27
MatrikonOPC OPC Server for DNP3 1.2.3 and earlier allows remote attackers to cause a denial of service (unhandled exception and DNP3 process crash) via a crafted message.

CVE-2014-2037
Published: 2014-11-26
Openswan 2.6.40 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads. NOTE: this vulnerability exists because of an incomplete fix for CVE 2013-6466.

CVE-2014-6609
Published: 2014-11-26
The res_pjsip_pubsub module in Asterisk Open Source 12.x before 12.5.1 allows remote authenticated users to cause a denial of service (crash) via crafted headers in a SIP SUBSCRIBE request for an event package.

CVE-2014-6610
Published: 2014-11-26
Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated users to cause a denial of service (crash) via an out of call message, which is not properly handled in the ReceiveFax dia...

CVE-2014-7141
Published: 2014-11-26
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?