Showing posts with label Twitter. Show all posts
Showing posts with label Twitter. Show all posts

Thursday, July 16, 2009

Twitter's Password is...Password?

TechCrunch reports that the Twitter search product interface was accessible with username "Jack" and password "password". Their take is that this is part of a culture of lax security at Twitter. For screenshots and more detail, click through to the article.

The best part? The screenshot with Twitter's own interface noting that the password is obvious.

Tuesday, January 6, 2009

Twitter Hack Targets High Profile Users

The BBC and other news outlets are reporting a hack of Twitter accounts via an email change utility. The hacked accounts, including those belonging to Britney Spears and Barack Obama were used to post various false Twitters.

The Huffington Post has screenshots and further details, including the post made to the Fox News Twitter feed.

Twitter hacks present an interesting attack vector, as many Twitter users use TinyURL to post links, thereby potentially obscuring the location. In addition, most Twitter users believe that they know the person posting, leading to a higher default level of trust. A hacked Twitter account from a trusted source such as a news agency or a well known individual would be an excellent attack vector for future attacks.

Creative Commons image courtesy of carrotcreative.