Top Tech News

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Product Reviews for Tech Leaders
Barium Ferrite (BaFe):
Higher Capacity, Superior
Performance, Longer Archival Life

www.thefutureoftape.com
Thursday, April 17th 
The future of tape is here.
This ad will display for the next 20 seconds. Please click for more information, or scroll down to pass the ad, or Close Ad.
Trending Topics:   Security Heartbleed Big Data Cloud Computing Windows XP Data Centers OS X Mavericks
Home
Network Security
Tech Trends
Cloud Computing
Hardware
Applications
Microsoft/Windows
Apple/Mac
Mobile Tech
World Wide Web
Big Data
Communications
Hackers
Chips & Processors
Linux/Open Source
Personal Tech
Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Hackers

Twitter Hack 'Not the Work of Amateurs'

Twitter Hack
February 4, 2013 1:57PM

Bookmark and Share
"Social media platforms are not immune to the IT Security challenges facing small. medium and large companies each and every day," said security researcher Chris Petersen of the Twitter hack. In essence, they face greater challenges attempting to protect not only the proprietary information on their users, but also mission-critical corporate info."

Barium Ferrite Is The Future Of Tape: Barium Ferrite (BaFe) offers greater capacity, superior performance, and longer archival life compared to legacy metal particle (MP) tape. Click here to learn more.

The fallout from the Twitter hack is still, well, falling out. Twitter admitted on Friday that 250,000 of its user accounts may have been hacked. Who's to blame? Java? Chinese hackers?

On the heels of The New York Times and The Wall Street Journal Chinese hacking revelations, Twitter said it also detected unusual access patterns that led it to identify unauthorized access attempts to Twitter user data. Twitter even shut down a live attack in progress.

"This attack was not the work of amateurs, and we do not believe it was an isolated incident," said Bob Lord, Twitter's director of Information Security, writing in a blog post. "The attackers were extremely sophisticated, and we believe other companies and organizations have also been recently similarly attacked."

Is Java to Blame?

Paul Henry, a security and forensic analyst at Lumension, said the Twitter hack was an odd one.

"There's not much information about it yet, so we don't know exactly what information the attackers got, but we do know that a whole bunch of people had to change their passwords," Henry said. "While there's been speculation that this was an organized attack, we don't know for certain, since very little information about the attack has been disclosed."

Henry noted that there has also been speculation that Java might have played a role, but he doesn't believe that Java was a factor. Since Java is used to attack and compromise single users, he explained, it's unlikely that it would have been the vector for an attack compromising 250,000 users. Still, he said, the warnings about Java that have been circulating for the last month or so should be heeded.

"Java is a flawed component and is one of the biggest attack vectors out there right now. Unfortunately, there's not much you can do to get around it, as many sites require it to function properly. Oracle has yet to fix many of its underlying flaws and we probably won't see a truly secure version of Java for another year or two. By then, I hope that developers have moved away from Java. Otherwise, the problem with Java is only going to get worse."

Henry also echoed Twitter's advice to practice "good password hygiene." In addition to not using the same passwords across multiple sites and using a combination of letters -- capitalized and lower case -- numbers and symbols, he recommended that changing passwords regularly. A monthly change is ideal for best practices, he said, but changing your passwords quarterly at a minimum is a good idea."

Follow the Money

Chris Petersen, chief technology officer at LogRhythm, told us it should come as no surprise that network intrusion attempts are on the rise given hackers' continued success in monetizing their efforts that often times yield high returns.

"Social media platforms are not immune to the IT Security challenges facing small. medium and large companies each and every day. In essence, they face greater challenges attempting to protect not only the proprietary information on their users, but also mission-critical corporate info as well," Petersen said.

"Regardless of the level of hackers' sophistication, the best policy enterprises and blue-chip organizations can have in place includes continuous network monitoring. Detecting anomalous activity in its early stages is critical and often times the difference between fast containment and mitigation or longer-term, more severe consequences."

Tell Us What You Think
Comment:

Name:

MJQ:

Posted: 2013-02-20 @ 1:37pm PT
"A monthly change is ideal for best practices, he said, but changing your passwords quarterly at a minimum is a good idea."

There are some contrary ideas circulating. One basic argument is that requiring overly frequent password changes, prompts users to write them down and paste them on their monitor or in some other obvious location. If you set up passwords to expire monthly and then give say two weeks notice that passwords are going to expire, you give people at most half a month without having to think about a password change.

A good read to a least start rethinking this can be found at: http://www.cerias.purdue.edu/site/blog/post/password-change-myths/



 Hackers
1. Teen Arrested for Heartbleed Hack
2. iPad Hacker Conviction Overturned
3. Is Heartbleed the Biggest Threat Ever?
4. Heartbleed Bug Breaks Web Security
5. Retailers Liable for Hacking Damage?




 Most Popular Articles
1. BlackBerry Drops T-Mobile After Nasty Spat
2. Salesforce CRM Gets Industry Specific for Internet of Customers
3. $200 'Micro' 3D Printer Earns Big on Kickstarter
4. Fast Seagate 6 TB Drive Offered for Enterprise Data Centers
5. Google Video Shows Off Modular Project Ara Phone

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Teen Arrested for Heartbleed Hack
  Android Gets Chrome Remote Desktop
  Malware Targets Facebook Users
  Intel Reports Lower 1Q Net Income
  Mt. Gox Is Headed for Liquidation

 Technology Marketplace

Business Intelligence
Get real-time, cloud-based information services with Neustar.
 
Cloud Computing
BMC's I.T. solutions unleash the power of your business
Next Generation Data Center Is Here! Vblock™ Systems from VCE
 
Contact Centers
HP delivers the future of the contact center with HP Qfiniti 10.
 
Data Storage
Next Generation Data Center Is Here! Vblock™ Systems from VCE
Barium Ferrite (BaFe) is the future of tape.
2.5" Enterprise-class SATA & SAS SSDs for server & storage applications
 
Enterprise Hardware
Barium Ferrite (BaFe) is the future of tape.
2.5" Enterprise-class SATA & SAS SSDs for server & storage applications
 
Enterprise I.T.
BMC's I.T. solutions unleash the power of your business
 
Hardware
Protect your network with APC Smart-UPS battery backup
 
Network Security
Protect your network with APC Smart-UPS battery backup
 

Network Security Spotlight
Canadian Teen Arrested for Heartbleed Hack
One week after the OpenSSL Heartbleed vulnerability was unveiled, Canadian authorities have made the first arrest -- a London, Ontario teenager -- connected to exploiting the security hole.
 
IBM Offers Security, Disaster Recovery as SoftLayer Service
New disaster recovery and security services for SoftLayer clients are being added by IBM. Big Blue said the new capabilities will speed cloud adoption by alleviating concern over business continuity.
 
How To Beat the Heartbleed Bug
Heartbleed headlines continue as IT admins scramble for answers no one has. Early reports of stolen personal data, including 900 social insurance numbers in Canada, are starting to trickle in.
 

Enterprise Hardware Spotlight
Vaio Fit 11A Battery Danger Forces Recall by Sony
Using a Sony Vaio Fit 11A laptop? It's time to send it back to Sony. In fact, Sony is encouraging people to stop using the laptop after several reports of its Panasonic battery overheating.
 
Continued Drop in Global PC Shipments Slows
Worldwide shipments of PCs fell during the first three months of the year, but the global slump in PC demand may be easing, with a considerable slowdown from last year's drops.
 
Google Glass Finds a Home in Medical Education, Practice
Google Glass may find its first markets in verticals in which hands-free access to data is a boon. Medicine is among the most prominent of those, as seen in a number of Glass experiments under way.
 

Mobile Technology Spotlight
Google Releases Chrome Remote Desktop App for Android
You're out on a sales call, and use your Android mobile device to grab a file you have back at the office on your desktop. That's a bit easier now with Google's Chrome Remote Desktop app for Android.
 
Amazon 3D Smartphone Pics Leaked
E-commerce giant Amazon is reportedly set to launch a smartphone after years of development. Photos of the phone, which may feature a unique 3D interface, were leaked by tech pub BGR.
 
Zebra Tech Buys Motorola Enterprise for $3.45B
Weeks after Lenovo bought Motorola Mobility’s assets from Google for $2.91 billion, Zebra Technologies is throwing down $3.45 billion for Motorola’s Enterprise business in an all-cash deal.
 

Navigation
Top Tech News
Home/Top News | Network Security | Tech Trends | Cloud Computing | Hardware | Applications | Microsoft/Windows
Apple/Mac | Mobile Tech | World Wide Web | Big Data | Communications | Hackers | Chips & Processors
Linux/Open Source | Personal Tech | Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 Top Tech News. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.