RSA11: User-generated content threat to Twitter users

Powered by SC Magazine
 

Be careful what you tweet.

The reality of how much malicious content is on Twitter was demonstrated at the RSA Conference in San Francisco.

Barracuda Networks' research scientist Daniel Peck and chief research officer and vice president of cloud services Paul Judge said that with any website with user-generated content there is a gap in trust among users, some of who are genuine and others who use them as a means to attack other users' accounts.

“Twitter is so open that it allows attackers to make use of it," Judge said.

"With account hijacking, what risk model is there? There are security flaws and malware in the content and you can see hijacking or simply spam.”

He pointed to incidents such as where compromises forced users to follow another user, the 'onmouseover' cross-site scripting attack where users tweeted a phrase by simply clicking on a piece of code in a tweet and various account hijacking incidents.

Peck said that millions of users accounts are created every day and for every 100 users, only 1 percent had 1000 or more followers.

“The site saw huge growth in 2009 and half of the most popular users joined in this period, as did those who like to follow them," Peck said.

"The crime rate also increased by 66 per cent and there was a large spike with the FIFA World Cup, with everything from spam to malicious stream viewing being promoted."

This article originally appeared at scmagazineuk.com

Copyright © SC Magazine, US edition


 
 
 
Top Stories
IBM denies plans to cut 112k jobs
But admits to further restructuring.
 
ATO investigates 25 tech giants in tax hunt
Prepared to take tax evaders to court.
 
Immigration, Customs restructure IT leadership
Customs CIO promoted into transformation role.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  36%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  9%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  18%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 3003

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  27%
 
I DON'T support shutting the OAIC.
  73%
TOTAL VOTES: 954

Vote