Wednesday, 7 September 2011

Alledged - Twitter Hacks would Destroy Time and Reputations

Just recently a client advised via Twitter that ourTwitter account had been hacked and that we were sending out Direct Messages to the effect of:

"lmao...omg i am laughing so hard at this pic of you u i just found http://XXXXXXXX" (link removed to protect readers).

Twitter advises that if your account is sending SPAM or has been COMPROMISED to follow the instructions shown in this link.  Worth reading if you haven't already done so.  Having said that, RES Info-Tech is an IT Support and Consultancy company specialising in security and we doubt that 'your' account has been compromised.  We think in fact that it is TWITTER that has been compromised.

Why do we think this? Well, the instructions in the link above tell you to change your password. Ok, so we've done this numerous times in the last three days.  The SPAM outbreak is huge in numbers and not specific just to individuals.  In other words, do you know any hackers that would sit down and take the time to individually compromise YOUR account?  No, of course not.

The instructions also advise that all associated applications be removed from your twitter account until the offending application (thats facebook, hootsuite, tweet deck etc..) has been found.  We did that.  We scanned every PC and server in our business and even uninstalled all the associated applications.  Doing this left TWITTER.com all on its own!  We even made sure that all PC's and servers were powered off for the night.

The next morning, client who resides two doors down the passage in our Enterprise Centre visited us.  "Did you know you're sending DM's to us on Twitter about photo's?" 

"Damn I said...." pause... "Hold on, you and I don't even follow one another, and all my hardware is powered off and has been all night!" 

Bingo, we thought.  The problem could be at TWITTER.com.  In addition, it would have to be beyond all the database security with all contact information. So, ladies and gentleman, alledgedly you have not been compromised, alledgedly Twitter has.  If so, what are they doing to the rest of your data such as telephone numbers and email addresses. Are they accessible by this rogue infiltrator? Could be, so don't take the risk.

Twitter, it's your turn to respond and as our support calls have been ignored, your users deserve the right to a full investigation.  If you have been compromised, you need to publicly tell the world before we all lose our clients for unsolicited, unprofessional DM's leaving our reputation in shatters.  If you haven't been compromised, please explain to the world how this stops!

Thank you.

UPDATE:
Interestingly enough, I received a message from Twitter advising that my account had been compromised and asking me to reset my password.  I wonder how many others received the same message that I did? That's ok BUT, what are Twitter doing to prevent compromisation in the future?  How safe is my contact data held on their records? Twitter, please feel free to advise on this blog what security changes you have, or intend to make?

5 comments:

  1. Despite all my past experience with Facebook, I did actually click the link from you. I know, I know but you were local and I'd just been talking to other people who run events at Dragon.

    Anyhoo, the link went to the Twitter home page...

    ReplyDelete
  2. PS... Were we actually following each other then, I'm not sure!

    ReplyDelete
  3. Jo, thanks for the post. The link has now been corrected above. I was following you.. but not sure if you were following me (you should be..lol). Give me a call at the Dragon sometime. Would like to know what you do etc... Regards Ray

    ReplyDelete
  4. Ray, Had another thought. If I wasn't following you, it's not possible for you to send me a direct message...?

    https://support.twitter.com/entries/13920-frequently-asked-questions

    Like I said, some people will even resort to a Twitter scam to get my attention :P

    http://lollipoplocal.co.uk

    ReplyDelete
  5. Exactly, so the Twitter security in the database has definitely been compromised.... As for attention,I've got your attention. Shame we haven't got Twitters attention to this case.

    ReplyDelete