woensdag 3 februari 2010

Phishing attack on Twitter

Yesterday, Twitter asked some users to reset their password as a security measure. Twitter has officially confirmed that it was a security issue and has given us some background information.

Twitter calls it: "Reason #4132 for Changing Your Password."

Twitter discovered a surge of followers to some suspicious accounts, decided to investigate, and discovered that a number of accounts were compromised through an attack involving torrent-related sites and forums.

When you carefully read Twitter's description, you will find some sound advice there:

"The takeaway from this is that people are continuing to use the same email address and password (or a variant) on multiple sites. Through our discussions with affected users, we’ve discovered a high correlation between folks who have used third party forums and download sites and folks who were on our list of possibly affected accounts. While not all users who were sent a password reset request fall into this category, we felt that it was important to put this knowledge out there so that users would know of the possibility of compromise of their data by a third party unrelated to their Twitter account. We strongly suggest that you use different passwords for each service you sign up for"

Indeed, reason #4132.