Main

January 6, 2009

Phishing is not just for email anymore: Twitter under attack

I always find it interesting the way old scams are redressed for new and emerging channels.


That was the case during the last few days when Twitter users and employees found themselves under attack by phishers and hackers: follow these links to find a good account of the former and the latter.


Today I'll talk about the phishing attack, which consisted in luring people to give away their twitter passwords to a fake site, the novel aspect is that it used twitter-generated messages (Direct Messages) to propagate to your list of contacts (Followers).


This is all pretty similar to what we have seen with phishing via e-mail, but with two key differences:


- The first one is that e-mail phishing is a "mature product" where phishers are one cog in the big underground economy of stolen bank/e-commerce passwords and credit card numbers, whereas this twitter phishing looked like a "prototype". The good news is that apparently no big harm was done and the Twitter team reacted quickly to reset accounts. The bad news is that the twitter phishing prototype worked, and the bad guys will come up with ideas on how to use it more effectively.


- The second aspect, which I find more disturbing, is that the Twitter media is more time-sensitive than e-mail, capable of reaching a lot of people in very little time. That is why I think there is potential for much greater damage if you combine twitter phishing with events with intensive twitter coverage such as the Mumbai attacks.


A short-term measure that Tweeter could take to beef up its defenses would be to upgrade their SSL certificate to an EV cert and tell their users to check the green bar when they login.


In the meantime, my twitter guru Bob Angus tells me that some of the buzz in the twittershpere is that these attacks confirm Twitter's arrival as a relevant media.


These past attacks seem to confirm that at least the bad guys seem to agree with that.

February 15, 2008

OpenID Announcement Well Received

We were pleasantly surprised by the positive response to our announcement around VeriSign joining the OpenID Foundation. These articles feature our VP of Innovation, Nico Popp.


OpenID Gets Star Power By Kenneth Corbin of InternetNews.com


Tech heavyweights join OpenID Foundation board By Deborah Gage of The San Francisco Chronicle


OpenID gains support for online single sign-on By Shane Schick of ComputerWorld Canada

February 7, 2008

Protecting the Keymaster

Today's announcement that Google, Microsoft, Yahoo!, IBM, and VeriSign are joining the OpenID Foundation's board is great news for the future of online identity. A single portable online identity has long been elusive, and we're excited to see it come one step closer to reality. I certainly won't miss my ever growing list of usernames and passwords!


But what happens when your entire online identity is consolidated into a single entity? It becomes a prime target for attack. In the pre-OpenID world, attackers need to steal your individual credentials for each and every site you visit; but if they're all replaced with a single OpenID, hacking just one account gives you the keys to the castle.


The need for strong account protection has never been greater, which is why we've integrated our VIP Authentication Service with the VeriSign Labs' Personal Identity Provider as a showcase for how strong authentication melds with user-centric identity. Our users agree - a significant percentage of PIP users already protect their OpenID with a PayPal Security Key or a VIP Security Card.


Once you add strong authentication to OpenID, you need a way for relying parties to request it, and for identity providers to answer those requests. This is where the PAPE standard comes in, providing a standardized language for OpenID sites to talk about the strength of their authentication.


In the OpenID world, we're encouraged to put all of our eggs into one basket. Just make sure you stick a good lock on it!

VeriSign Identity Protection

Search

Disclaimer: Opinions expressed here and in any corresponding comments are the personal opinions of the original authors, not of VeriSign.

VeriSign Legal Notices

Read our Privacy Policy