Related Links

Related Stories

  • Daily Telegraph third-party website hacked and defaced
    A Daily Telegraph third-party website is the latest high-profile site to be defaced by hackers apparently unhappy about the news organisation referring to Romanians as gypsies.
  • Twitter accounts being hacked by cybecriminals looking for value
    Internet user accounts and passwords – known as credentials in security circles – are rising in value and, say some reports, the credentials on Twitter, the social networking portal, can be worth up to $1000.
  • CPP fears for consumer identity safety
    Life assistance company, CPP, has issued a warning to consumers over identity fraud. The company’s research reveals that less than half of UK consumers are concerned for the security of their personal bank accounts. The survey indicates that one third of people fear that their bank account is at risk of being hacked into.
  • Tor IP anonymising internet service hacked
    The developers behind the Tor Project, a voluntary IP anonymising project that allows internet users to proxy through to destination websites using a variety of free-to-use servers around the world, appears to have been hacked.
  • Tony Blair's hacked Facebook profile contains a serious message
    Politics aside, the recent hack of Tony Blair’s Faith Foundation Facebook page reveals a serious problem with the application used in the page’s creation, says application vulnerability specialist, Fortify Software.

News

VIPs need extra web 2.0 security

05 July 2010

There has been spate of high-profile Facebook, Twitter and other social networking account hacks recently, the most recent of which was the compromise of the Facebook and Twitter accounts of Conservative MP Therese Coffey.

According to Dr Paul Judge, chief research officer with Barracuda Networks, Ms Coffey's account hacks were probably due to a lack of security awareness on her part, as well as the use of the same password on multiple accounts.

"The social media platforms of highly visible people will always be an irresistible target to hackers, whether commercially or politically motivated", he said.

The solution to the problem, he told Infosecurity, is a mixture of improved security on the part of the user, and technology to help to defend against this type of account security compromise.

Proper password and personal security controls are, he explained, something that almost all business technology users know about, but few follow rigorously.

"Any large organisations such as Parliament down to the smallest SMB can buy in the appropriate security technology like web application firewalls or spyware removal tools, but the weakest link is always the human element", he said. "It appears in this case that Therese Coffey used the same passwords across several sites, leaving her completely open to compromise," he added.

Dr Judge went on to say that IT managers need to address Web 2.0 services. "You really do need to control access to social networking sites and services on both a user and granular level, controlling who can do what and on which service. Then there is the question of timing – you might want to limit social networking access to 60 minutes during work hours, or, in some cases, limit access to outside working hours or lunch breaks", he said.

Some organisations, he says, now require users to load a virtual machine up for social networking site usage, and, when they log out, the virtual machine session shuts down, only for a second session to be loaded for 'normal' work usage. "Using this approach means that, when the virtual machine session is closed down, any potential security issues close down with them. It's a useful way of securing access to social networking services", he explained.

 

This article is featured in:
Identity and Access Management Internet and Network Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.