You've probably heard about this already, but yesterday the AP's Twitter feed was hacked, and used to send out a bulletin that the White House had been bombed and President Obama injured. Despite AP's quick reaction and suspension of its account, the hacker's message was retweeted thousands of times within the next few minutes to significant effect. There was panicked selling in stock markets, in one highly visible impact. Coming on the heels of last weekend's hacking of multiple CBS News Twitter accounts, it's renewed calls for better login security at Twitter.
The same group is claiming credit for both hacks, although the AP hack message mirrored AP style, while the CBS hack posts were more clearly political. A later AP story indicated that the intrusion was more the result of a phishing expedition aimed at AP corporate accounts. Phishing emails often use real graphics and look-alike account names to trick recipients to going to a faked login page and re-enter login names and passwords. Hackers then use the real account info to gain entry into the service.
Computer security experts are suggesting that Twitter add what's called two-factor authentication, where there is a second step when logins are attempted from a new device. In addition, they're suggesting that Twitter add a function that would allow for corrections to be attached to the original tweet - for now the only option for a hacked account is to suspend the account and create a new password, and hope that word of the false tweet gets the same exposure. While Twitter policy is to not comment on specific accounts or actions, Forbes reports that a scan of recent Twitter job listings suggests they're looking for people with the necessary skills to improve security.
Source - AP Hack Highlights Two Crucial Features Twitter Needs, Forbes
This blog is affiliated with a course at the School of Journalism & Electronic Media at the University of Tennessee, Knoxville. I'll try to use it to share relevant news and information with the class, and anyone else who's interested.
Showing posts with label hack. Show all posts
Showing posts with label hack. Show all posts
Wednesday, April 24, 2013
Monday, November 19, 2012
2013 Cyber Threats Forecast
Georgia Tech's Information Security Center, along with the GT Research Institute, has released its annual forecast of top Cyber Security threats. Here's some of the list:
- Cloud-based botnets - "One possible example is for attackers to use stolen credit card information to purchase cloud computing resources and create dangerous clusters of temporary virtual attack systems"
- Search History Poisoning - manipulating search engine results and other customer-targeted services
- Mobile Browser/ Mobile Wallet Vulnerabilities - just how safe are the apps?
- Malware Counteroffensive - continued efforts to hamper detection and bypass on mobile devices
"In 2013, we expect the continued movement of business and consumer data onto mobile devices and into the cloud will lure cyber criminals into attacking these relatively secure, but extremely tempting, technology platforms. Along with growing security vulnerabilities within our national supply chain and healthcare industry, the security community must remain proactive, and users must maintain vigilance, over the year ahead."The report can be downloaded by visiting http://www.gtsecuritysummit.com/report.html
Source - Georgia Tech Releases Cyber Threats Forecast for 2013, Dark Reading
Sunday, November 27, 2011
Photo Sharing with Color
Post contributed by Summer Johnson -
In March 2011, the first Color apps for smartphones debuted. Color is a new picture sharing app that connects multiple smartphones within a certain range to digitally share and sync photos in real time. The app then sorts pictures of individual events in a timeline and shares them with the nearby synced phones.
Although Color meant to revolutionize picture sharing and connect more people in an exclusive interactive way, some believe it gives users too little privacy. In an article for Forbes, Andy Greenberg, reports security researcher and Veracode chief technology officer Chris Wysopal had already hacked Color the night it debuted. By using an iPad hacked to allow third party applications in combination with another app, FakeLocation, Wysopal was able to change his own geographic location on Color to view all pictures in any geographic location he chose.
When Greenberg contacted Color’s spokesperson, John Kuch, about the hacking, Kuch explained that Color has never offered privacy, and said that it has always been public.
Although pictures create about 20% more interaction on social networking sites like Facebook (as stated by Buddy Media in Stan Bashmashnikov’s article, The Future of Photo Sharing), technology may be ahead of itself until applications like Color can offer more privacy to its users.
Sources - The Future of Photo Sharing, Social Media Week
Subscribe to:
Posts (Atom)