<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Wire Turf &#187; Twitter</title>
	<atom:link href="http://www.wireturf.com/tag/twitter/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.wireturf.com</link>
	<description></description>
	<lastBuildDate>Sat, 22 Oct 2011 02:38:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2</generator>
		<item>
		<title>Twitter Doc Theft &#8211; Details Revealed: Step By Step To How It Was Done</title>
		<link>http://www.wireturf.com/2009/07/19/twitter-doc-theft-details-revealed-step-by-step-to-how-it-was-done/</link>
		<comments>http://www.wireturf.com/2009/07/19/twitter-doc-theft-details-revealed-step-by-step-to-how-it-was-done/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 04:41:14 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://www.wireturf.com/?p=76</guid>
		<description><![CDATA[TechCrunch posted a great step by step account this morning that details almost exactly how Frenchman Hacker Croll (HC) was able to steal over 300 sensitive Twitter corporate docs, as well as gain access to numerous online accounts of several &#8230; <a href="http://www.wireturf.com/2009/07/19/twitter-doc-theft-details-revealed-step-by-step-to-how-it-was-done/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>TechCrunch posted <a href="http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/" target="_blank">a great step by step account</a> this morning that details almost exactly how Frenchman Hacker Croll (HC) was able to <a href="http://www.techcrunch.com/2009/07/14/in-our-inbox-hundreds-of-confidential-twitter-documents/" target="_blank">steal over 300 sensitive Twitter corporate docs</a>, as well as gain access to numerous online accounts of several <a href="http://twitter.com" rel="nofollow" target="_blank">Twitter</a> employees.</p>
<p>It&#8217;s a long article, but very interesting and if you have any interest in keeping a tight reign over the security of data that you keep online (email etc), you owe it yourself to give the TC post a thorough read. Now that we have details as to exactly what occurred and how it was done, my head is spinning with the myriad number of security issues raised by this incident. I plan to write a series of posts in the coming days discussing these issues in greater detail.</p>
<p>I quote here the TechCrunch summary of the attack:</p>
<blockquote>
<ol>
<li>HC accessed Gmail for a Twitter employee by using the password recovery feature that sends a reset link to a secondary email. In this case the secondary email was an expired Hotmail account, he simply registered it, clicked the link and reset the password. Gmail was then owned.</li>
<li>
HC then read emails to guess what the original Gmail password was successfully and reset the password so the Twitter employee would not notice the account had changed.</li>
<li>
HC then used the same password to access the employee’s Twitter email on Google Apps for your domain, getting access to a gold mine of sensitive company information from emails and, particularly, email attachments.</li>
<li>
HC then used this information along with additional password guesses and resets to take control of other Twitter employee personal and work emails.</li>
<li>
HC then used the same username/password combinations and password reset features to access AT&#038;T, MobileMe, Amazon and iTunes, among other services. A security hole in iTunes gave HC access to full credit card information in clear text. HC now also had control of Twitter’s domain names at GoDaddy.</li>
<li>
Even at this point, Twitter had absolutely no idea they had been compromised.</li>
</ol>
<p><em>Source: <a href="http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/" target="_blank">TechCrunch</a></em>
</p></blockquote>
<p>WOW! So many things jump right out at me from reading this, including:</p>
<ol>
<li>Sloppy email and password account management by Twitter employees concerned</li>
<li>Dangers of mixing work and personal email activities</li>
<li>What kind of online footprint you leave by your public participation in social networks, and how vulnerable to attack that can make you (actually this is hinted at not from the above summary account but other details in the TC post)</li>
</ol>
<p>More to come on this subject in the next few days.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.wireturf.com/2009/07/19/twitter-doc-theft-details-revealed-step-by-step-to-how-it-was-done/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter Docs Stolen off Gmail. How it was done.</title>
		<link>http://www.wireturf.com/2009/07/15/twitter-docs-stolen-off-gmail-how-it-was-done/</link>
		<comments>http://www.wireturf.com/2009/07/15/twitter-docs-stolen-off-gmail-how-it-was-done/#comments</comments>
		<pubDate>Wed, 15 Jul 2009 18:49:33 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://www.wireturf.com/?p=18</guid>
		<description><![CDATA[I&#8217;m interested to document how French hacker &#8220;Hacker Croll&#8221; was recently able to steal sensitive company documents from Twitter. My interest in this is to inform myself and hopefully others as to how to safeguard ourselves as best we can &#8230; <a href="http://www.wireturf.com/2009/07/15/twitter-docs-stolen-off-gmail-how-it-was-done/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m interested to document how French hacker &#8220;Hacker Croll&#8221; was recently able to steal sensitive company documents from Twitter.</p>
<p>My interest in this is to inform myself and hopefully others as to how to safeguard ourselves as best we can from suffering similar fates in future.</p>
<p>What I have gleaned so far:</p>
<p>From <a href="http://www.techcrunch.com/2009/07/14/twitters-ev-confirms-hacker-targeted-personal-accounts-attack-was-highly-distressing/" target="_blank">TechCrunch yesterday</a>:</p>
<blockquote><p>&#8220;Hacker Croll was able to compromise the Twitter accounts of founder Evan Williams, his wife, and several employees. Using password recovery techniques, Hacker Croll claims he gained access to various Paypal, Amazon, Apple , AT&amp;T, MobileMe and Gmail accounts.  Evan Williams&#8230; confirms:</p>
<p>Yes, we did suffer an attack a few weeks ago and are familiar with this list of stuff. This is unrelated to the hack of twitter where someone gained access to user’s accounts. This had nothing to do with the security of twitter.com, and there were no user accounts compromised here.</p>
<p>Some notes:<br />
- He did not actually gain access to my @ev Twitter account (or any Twitter accounts) nor any administrative functions of the site.<br />
- There is also no evidence that he gained access to my email. There was one administrative employee who’s email was compromised, as was my wife’s Gmail account, which is where he got access to some of my credit cards and other information.<br />
- He also successfully targeted a couple other employees personal accounts (Amazon, AT&amp;T, Paypal…)</p>
<p>In general, most of the sensitive information was personal rather than company-related. Obviously, this was highly distressing to myself, my wife, and other Twitter employees who were attacked. It was a good lesson for us that we are being targeted because we work for Twitter. We have taken extra steps to increase our security, but we know we can never be entirely comfortable with what we share via email.</p>
<p>Above and below are purported screenshots of Williams’ accounts on Twitter, Gmail, and GoDaddy. He claims he was able to access Twitter’s domain name account on GoDaddy and could have redirected the traffic to another IP address (I’m sure that would have worked for about three minutes).  The Gmail access, if true, would have been more troubling.  Once the hacker got into @ev’s Gmail account, password recovery for other accounts was easy.  He claims to have gained access to some internal documents, including projections for reaching 25 million users in 2009, 100 million in 2010, 350 million in 2010, and an outlandish goal to eventually become the first Internet service to reach one billion users. So maybe some corporate information was compromised.
</p></blockquote>
<p>And from <a href="http://www.pcworld.com/article/168462/twitter_hacked_secrets_to_be_revealed.html" target="_blank">PC World today</a>:</p>
<blockquote><p>&#8220;&#8230;what&#8217;s strange about the hack of Twitter&#8217;s Gmail accounts is that Google&#8217;s security process is not as simple as Yahoo&#8217;s allegedly was at the time of the Palin hack.</p>
<p>On the password recovery page, Google asks you for your username, and then requires you to enter a CAPTCHA. Then Google sends a link to the e-mail address you originally entered when you signed up for a Google account. If you don&#8217;t have access to that account, Google will not allow you to access your account by answering your security question until 24 hours after you&#8217;ve received the security e-mail at your alternate account. Yahoo Mail currently uses a similar password recovery method.</p>
<p>It&#8217;s not clear if this security measure was in place at the time Hacker Croll accessed the Gmail accounts associated with Twitter, but it does serve as a reminder that you must keep your information up to date and choose a security question that will be difficult for a hacker to figure out.&#8221;</p>
<p>&#8220;&#8230;Twitter co-founder Evan Williams was contacted by<a title="TechCrunch" href="http://www.techcrunch.com/2009/07/14/twitters-ev-confirms-hacker-targeted-personal-accounts-attack-was-highly-distressing/" target="_blank">TechCrunch</a>to confirm the document theft. Williams reportedly confirmed that Twitter did suffer an attack several weeks ago&#8230;</p>
<p>Williams told TC the company is familiar with the list of information Hacker Croll obtained&#8230; The Twitter co-founder confirmed the hacker gained access to his wife&#8217;s Gmail account &#8212; where some of Williams&#8217; credit card information was stored &#8212; as well as an administrative employee&#8217;s Gmail account and a number of personal accounts of other Twitter employees. Williams says Hacker Croll did not gain access to William&#8217;s Gmail account, and that Twitter has now taken further security measures to guard company property and internal documents.&#8221;</p></blockquote>
<p>This suggests that the hacks were on Gmail accounts (not Google Apps although the above does not rule out that here might have been additional hacks on other stuff, such as Google Apps). If the original point of entry by the hacker were the personal email accounts of various employees (and even relatives of employees, such as Williams&#8217; wife), how did this lead to so many sensitive company documents being compromised? I am left wondering why so much sensitive company documentation would be found on personal Gmail accounts of employees.</p>
<p>There&#8217;s also the rather interesting tidbit (take that as a warning!) that Williams&#8217; credit card info was somehow stored within his wife&#8217;s Gmail account. A big no no for sure! I can&#8217;t think of any good reason to ever keep your credit card number stored digitally somewhere that you can control (not including merchants&#8217; databases that obviously store your CC info when you transact with them). The card&#8217;s in your wallet, why keep the number online somewhere else as well?</p>
<p>I&#8217;ll post more as other details emerge, if indeed they do.</p>
<p><strong>Update 1</strong>: Twitter co-founder Biz Stone <a href="http://blog.twitter.com/2009/07/twitter-even-more-open-than-we-wanted.html" target="_blank">posted this morning</a> at 11.15am providing some clarity on what happened. Some of the salient excerpts:</p>
<blockquote><p>&#8220;About a month ago, an administrative employee here at Twitter was targeted and her personal email account was hacked. From the personal account, we believe the hacker was able to gain information which allowed access to this employee&#8217;s Google Apps account which contained Docs, Calendars, and other Google Apps Twitter relies on for sharing notes, spreadsheets, ideas, financial details and more within the company.&#8221;</p></blockquote>
<p>So as I suspected, Twitter is using Google Apps and that was where presumably the majority of those hundreds of stolen docs came from. Still interesting though is how the hacker was able to get from the personal email account of one employee into that employee&#8217;s Google Apps account. Why are employees co-mingling personal email with business? I never ever do that myself and believe it&#8217;s generally a poor practice, not just for security reasons but for several others as well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.wireturf.com/2009/07/15/twitter-docs-stolen-off-gmail-how-it-was-done/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

