Obama Twitter Account Hacked – Update: Twitter Crack Culprit Discovered

As posted on Monday, Twitter has been suffering repeated security related challenges in the past few days. Now, news has surfaced of the compromise of President-Elect Obama’s campaign Twitter account (as well as other high profile celebrity accounts). The issue as we see it (beyond the scope of individual Twitter account compromises and the fallout to Twitter, is the impact this compromise may have on the micro-blogging/social networking sphere in general – viz. FriendFeed, Identi.ca, FaceBook, MySpace and others in the segment. After all, each new messaging vector brings new cybercrime vectors. Apparently, based on performance, due diligence, in regards to security, is not in the Twitter playbook. We hope this will change, and go beyond simple reactive actions by Twitter administrators, into some level of displayed competency in relation to securing the product (perhaps – here’s an idea, maybe…API level authentication!).
UPDATE:
News, late yesterday (in the Poorly Architected Web Security Dept.) of the true culprit to the Twitter security pains of late: A hacker /cracker with a history of ‘pranks’, has admitted an administrative account hijack /crack (through the utilization of a self-authored automated password-cracker). The culprit also posted the crack exploit on YouTube.
Advice for Twitter: Do Not Implement Weak Password-Driven Security Methodologies. Do Not Expose Administrative Accounts. Lock Accounts After A Five Failed Login Attempts. Learn About Strong, Complex Passwords. Better Yet, Use Secure Tunneling (SSH), Certificates And Two Factor Authentication for Administrative Activities...mxh
From the Wired.com ThreatLevel post: ” Official Twitter feeds belonging to Barack Obama’s campaign, Fox News and Britney Spears were hijacked to send out fake messages on Monday, two days after a password-stealing phishing attack targeted the microblogging service.
“A number of high-profile Twitter accounts were compromised this morning, and fake/spam updates were sent on their behalf,” the company acknowledged on its website Monday. “We have identified the cause and blocked it. We are working to restore compromised accounts.”
![Reblog this post [with Zemanta]](http://img.zemanta.com/reblog_b.png?x-id=d7ced045-8fb0-404d-947f-aa76a4c0b13a)






Sep 8th, 2009 at 13:37
Obama Twitter Account Hacked – Update Twitter Crack Culprit Discovered http://bit.ly/pP8Q4