Twitter gets 20 years' good security bond

Powered by SC Magazine
 

Settles over security claim.

Twitter has been barred from overstating the extent to which it can securely manage user information for the next 20 years in a settlement with the US Federal Trade Commission.

The micro blogging site had been investigated over two hacking incidents in 2009 in which 55 accounts were hijacked, including US President Barack Obama’s.

The accounts were hijacked after someone hacked into Twitter’s support team administration tools, the company admitted after the incidents occurred.

The FTC alleged the attacks exposed non-public information and information that users had designated as private, such as private Tweets.

The regulator took exception to the wording of Twitter’s security claims in its original privacy policy, which said it employed “administrative, physical and electronic measures designed to protect your information from unauthorised access”.

Twitter's subsequent versions, which can be found here, make no claims about the level of security it provides. 

The FTC also ordered Twitter to establish and maintain a “comprehensive information security program”, which would be assessed biannually by an independent auditor for the next decade.

Copyright © iTnews.com.au . All rights reserved.


Twitter gets 20 years' good security bond
 
 
 
Top Stories
Coalition's NBN cost-benefit study finds in favour of MTM
FTTP costs too much, would take too long.
 
Telcos finally briefed on data retention details
Update: AGD offers list of data to be stored.
 
Qld Health hires short-term CIO, CTO
Ray Brown leaves after five years at IT helm.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Which is the most prevalent cyber attack method your organisation faces?




   |   View results
Phishing and social engineering
  67%
 
Advanced persistent threats
  3%
 
Unpatched or unsupported software vulnerabilities
  12%
 
Denial of service attacks
  7%
 
Insider threats
  12%
TOTAL VOTES: 560

Vote