Sunday, September 26, 2010

The Fresh Round of Twitter Hacks and Attacks

Whenever I talk about security, it is important that I remind you that I write solely my own opinions and not official positions of Intel. Hopefully, you find this useful advice, but that's all it is, advice from someone who is interested in safety.

Well, twitter has been "safe" and quiet for some time. People have begun to let their guard down. However, a new set of vectors for exploits is being mined. It started about a week ago with a tweet exploit that became a worm and spread porn and other unsavory stuff. Now, a second version has appeared. It looks like this new version has been nipped in the bud. However, the risk is ever present. There are people out there looking for security holes and when they find them, either playing pranks or spreading something more vicious.

Sadly, it is the nature of software to have such flaws. Thus, it is only wishful thinking to hope it goes away. We can erect better fences, but there will always be someone who finds out how to scale them and uses that ability to their advantage and our disadvantage. As a result a certain level of caution, vigilance, and even paranoia is appropriate. But do so in balance, if you let fears dominate your life, the result is just as bad, because your fears will cause you to miss opportunities.

So, keep the following in mind. There are people out there who are out to trick you and they are very clever and have very little scruples. These people are anxious to imitate anyone you trust as that's a source of leverage for them. Thus, they will pretend to be your bank, the government, some famous company, your friend, a web site that you often visit, a new web site with an interesting game, anything they think that will get you to trust them They will do this by every means possible: by spam emails, by links to sites that download malware, by sending misleading tweets, by hacking into your computer, by hacking into the computers of places that have your info. The more valuable they think your information is or the easier they think it is to get, the more effort they will spend getting it.

However, in most cases, they are not targeting you specifically, they are just looking for the easiest mark that will fall for their trap. Therein lies your advantage. You don't have to outrun the bear, just the other hikers. This is why fish swim in schools. Sure that makes the entire school a large target and the fish along the edge do get eaten, but the ones in the center tend to survive and breed a new generation. Your goal is to be in the safe part of the school.

Thus, when you read safety advice on the internet, remember that it is not fool-proof. Some people who do everything right will still get hacked. However, it is the best advice we have. It will keep you from doing things that are too risky and too likely to get you into trouble. It will increase your odds of using the internet safely.

See the next entry for some safety advice recommendations.

No comments:

Post a Comment