Sunday, May 30, 2010

Is an iPad a Non-Programmable Computer?

As always, before I write anything, I need to add a disclaimer. I work for Intel and tweet under @intel_chris. However, these tweets and blog entries are simply my own opinions and not the official pronouncements of Intel in any way.
Before we look at that question, we need to define what it means. There are devices that perform computations that are not programmable. However, that isn't what I'm asking about, although it is close.

So, Sherman set the way-back machine to 1890, the time of Herman Hollerith and the census. It was a big task collating the answers from all around the country and it was done by using machines which sorted the punched cards into various slots.

If you look at old movies, you can sometimes see some of these machines. (More information and pictures at technikum29.) Early on in my career, I even used them.

Now, to perform their function these machines could be programmed, by the use of levers (in the case of the ones I used) or wires that could be connected or disconnects (in others). However, the key point is that the cards themselves could NOT affect the program, only the switches or wires could. Thus, although the machines could be programmed, from the point of view of the cards, they could not.

Modern computers keep the program in the same memory as the data. This is called the Von Neumann architecture. This architecture allows the program to be changed by sending data to the computer. It is an important advancement in what computers can do. However, it also allows computers to become infected with viruses. When a modern programmer wants a computer, this is what he wants, something he can send data to in order to reprogram. This is the kind of computer your PC or MAC is.

However, there is a "computer" in my house that I never reprogram. It's my TiVo. Inside the TiVo there is a computer that can be reprogrammed, and some people "hack" their TiVo's and change that program. However, I never do. I simply let the program run and do its thing.

Now, for those of you wondering, I do change the shows I watch and various things and that might seem like programming it. However, it isn't. It is configuring it. It's like the punch cards. Changing the shows I watch never changes the way the unit functions. Most importantly, changing the shows cannot introduce a virus into the TiVo. This is a non-programmable computer.

Of course, as I noted above the computer can be programmed. In fact, TiVo (the company) does so every once in a while. However, I never program it. More importantly, I have never heard of any virus writer ever sending malware to a TiVo.

The question worth asking is whether an iPad is more like a PC or MAC or more like a TiVo? If you don't Jailbreak your iPad (or your iPhone) I would argue that it is more like a TiVo. It provides certain services. Moreover, once you have a set of apps on your iPad, you don't reprogram it, until you add another app. Using an application on an iPad, even surfing the web, does not reprogram your iPad.

Compare this to surfing the web on a more normal computer. These computers are reprogrammed regularly. In fact, for the longest time, whenever you went to a new web site, there was a reasonable anticipation that the web site was going to use some new rendering software (e.g. a new version of flash) and would link you to a site to download it. That is one of the hooks many virus writers used to get you to load their malware onto your computer. You wanted to see Anna Kournikova and you were willing to reprogram your computer to do so.

On the iPad, one doesn't do that. One has a set of applications and they do their jobs. Moreover, Apple specifically vets all of those applications. At this level, an iPad has a virus-proof OS. If you never Jailbreak your phone, and you never download any apps that aren't approved, you should never get a virus.

Now, before everyone goes out and buys an iPad and says @intel_chris said it would protect them from viruses, let me add two caveats.
  1. The fact that one programs an iPad at all, and more importantly, the fact that down deep within an iPad is a computer that can be programmed, means that it is possible to create iPad viruses. Someday, someone will do so. The more popular iPads become, the sooner that will happen. Moreover, things like Javascript embedded in web pages, are small programs, which means at some level your iPad gets reprogrammed a little by almost every web page it visits, but these programs are not supposed to persist after the web page is no longer being viewed.

  2. Not all malware requires a virus be installed on your computer. In fact, spam and phishing emails are often not viruses at all. They simply get you to do something you shouldn't, e.g. order medication from a place you have never heard of, or send your banking information to a site that isn't your bank. In addition, even properly working web browsers have techniques (e.g. Javascript as mentioned above) that allow malware writers to put up deceptive web pages and surreptitiously collect information from you.

However, despite that I think that the iPad being a non-programmable computer is actually a good thing. For many jobs, we want something that just works and we really don't care how it works. For me, my TiVo is the perfect example of that. The fact that it is programmable, only rarely tempts me to do so. (Yes, I'm still a geek, so it does tempt me from time-to-time, but I can always find better more interesting things to program than it.) An iPad looks like another device that could act that way. Would I really want to program it, or just use it? I think for most people, just using it is the obvious answer.

If just using it has a side-effect of making us even just a little safer, that is a wonderful side benefit.

Sunday, May 16, 2010

Is FaceBook A Utility

Disclaimer: These opinions are strictly my own. They do not represent the views of Intel.
Recently, Danah Boyd, @zephoria, posted an excellent article, "Facebook is a utility; utilities get regulated". If you haven't read it, you should (including the comments) and form your own opinion.

To me the real question and I believe Danah captured it well is what is the commodity the Facebook is selling. What does Facebook have a monopoly on? The answer to that question is the connectivity to its network and the private information that people have placed on it. It is that private information people want to protect. It is that connectivity they cannot afford to lose.

I will not argue with the other people commenting that Google is not as significant a near-monopoly as Facebook, nor that Facebook won't eventually be replaced by another network. In fact, I do not use Facebook that much. I prefer a different near-monopoly Twitter for most of my connections. I haven't also placed signficant private information on it at all.

However, Facebook has one attribute that some of its competitors do not, access to some of our private information. That is the information that Facebook wants to monetize. That is what has us upset. This is what people will clamor to regulate.

People do not care so much whether Facebook is a utility or not, except as it potentially exposes that private information without our consent to a much larger audience than we intended. If you read the recent polls on youth online behavior and attitudes, you will see that many of them assume that such protections against that kind of sharing are already in place. Moreover, the Facebook users who have been using the site for years also have that expectation, because that was previously the expectation set by the company.

The convenience of Facebook for reaching one's friends is hard to deny, although it does not seem to include those whom I would like to reach. In fact, the true "utility" of Facebook, what I would dearly love to have, is the universal email-address finder. The one which would allow me to find email addresses of long lost friends, and not just their home addresses and property value which I can find through scary services like Intelius. The hope that Facebook holds out is the hope of reconnection and the hope of staying connected.

Facebook is seeking to trade that for the price of our personal privacy. A price it hopes that others value more than we do. However, it has done that through what appears to many to be a bait-and-switch operation. That is what has people upset. It is not the bargain they signed up for. It is not what they were promised.

And, it is that private information that distinguishes Facebook from Google or Twitter for most people. Neither of those sites has ever asked to share information that I wouldn't naturally consider public. However, if I had a protected account on Twitter, where my tweets were construed as private I would be just as upset about having them monetized and potentially exposed. Similarly, the woman whose email name was shared to her abusive ex by Google when she joined Buzz had similar (and more dramatic) cause for upset. To whom we connect and who we are is private information.

Holding of private information is in some sense a sacred trust. It is the real reason why these companies are likely to get regulated, not their ubiquity.

Saturday, April 3, 2010

Phishers are Here on Twitter

As always, I will start this note reminding you that while I work for Intel on security features on some future Intel chips, I don't speak for Intel on security matters and what I write about is purely my own opinions.

Perhaps it is irony. Maybe it is karma. However, after retweeting that twitter links were safer than google, I got a tweet with a phishing link from a user called @FasterComputerZ.

It looked innocent enough. It came as an @ message from someone who looked like one of the many security people who follow me and whom I follow. Sure, it was a new follower, but I get new followers every week. It also looked a little bit selling oriented, but that isn't completely suspicious by itself either. This wouldn't be the first person that was trying to make money and hoped to connect with twitter to aid that.

It did include a link to a web page. Since, my link expander didn't show any problems, I foolishly followed it. When I got there I saw ads for anti-spyware programs I had never heard of before. More importantly some of them had subtle grammatical errors. This increased my suspicions.

Therefore, I asked my good friend @teksquisite to look into the site. Sadly, it turned out to be a phishing site. Of course, I had already visited the site. I've since run scans on my computer and they've found and fixed some problems. Now, they may have come from elsewhere, but given that the site contained phishing scams, it is suspect.

Could I have been more suspicious in the first place? Yes. However, not everyone has access to the security resources that I have. So, unless you want to live like a hermit and never click another link, you need to realize that someday you will probably visit an infected site.

Keeping your anti-virus and anti-spyware up-to-date should help protect you.

Being extra cautious when things seem suspect with also help. In particular, your security programs probably have more extensive scans that you can run, like mine did. If you think you may have visited an infected site, run those extra scans.

Also, while you aren't sure things are ok, don't expose yourself (and others) to more risk. Don't visit web sites from your suspect computer. If you think you got the infection via twitter, facebook, myspace, or some other social media site. If you can, go to another computer and change the relevant password(s). If you can't get to a computer that you know is uninfected, wait until you have disinfected your computer before changing the passwords.

Finally, if you want to be particularly cautious, you might choose to segregate your life into different compartments. Keep one computer for doing important and private things like banking. Use a different computer for social media and web surfing. That way, if your surfing computer gets infected, your banking and private information is not at risk. I sleep better at night knowing that my banking information is not on this computer where I twitter.

Another form of segregation you can do is to use different strong passwords (that aren't related) for the various things you access. That way, if somehow one of your passwords gets stolen, it doesn't make guessing you other passwords easier.

Thursday, January 28, 2010

I've Been Hacked

There comes a time in every security worker's life, that they get hacked. In fact, it usually happens more than once.

Now, for the necessary disclaimer. I work on security for Intel, not securing Intel, but developing devices that may someday go into chips that Intel sells to make you more secure. This blog, however, is only my own viewpoints and experiences, and is in no way an official Intel declaration, recommendation, or pronouncement. It's just me getting up on my soapbox and talking about what interests me, and what I've learned about being secure in a very open world.

Sometimes, like around April 1st, it happens because one of your co-workers decides that they want to amuse you. I got some very clever emacs macros 1 year, that changed the way the screen looked to put the status bar on the other side. I actually decided I liked emacs better that way and kept them there.

Other times, one gets hacked because one has tightened the security of something enough and someone actually does break in. I used to have a very nice Unix system for the software company I own, but which I had to administrate for myself.. I left that system too open and I got root-kitted. After that, I bought a nice firewall, and tightened up the permissions on the systems ports and was safe until I retired that machine.

Well, given the rash of facebook and twitter attacks going on last fall, I figured I was about due for another learning experience. It was never really clear what perpetrated the attacks, although the koobface virus and some suspicious IQ test links sent via DM were the top suspects. However, we were never certain that the problem was resolved and that the threat had dissipated. In fact, it is quite likely still a threat, just not an active one.

So, when I turned on my tweetdeck session and saw the note that I had tagged @barackobama using this web based twitter service, I feared the worst. Here is a wonderful twitter service, that I had been using and now my account there had been hacked. Moreover, since the account is based upon my twitter credentials, those had probably been hacked too.

Remembering the preceding viruses, I immediately tweeted out that my id had been hacked and not to follow any links I had sent. I then went about turning things off.

  1. I closed all windows except those I needed to turn things off.
  2. I revoked the service's access to my twitter account from a machine where I hadn't been running the service.
  3. I changed my twitter password.
  4. I closed my last twitter session and went to a machine where I hadn't been running it and logged in and them immediately changed the password again.
  5. I then felt secure enough to turn twitter back on.

By that time, the problem had been tracked down. It wasn't a virus that had hacked me. I was actually reporting a problem to the folks at the service and they had logged into my account there to check out the problem, but had forgotten to log out and the practical joke had been played there.

And, there lies the real moral of this story. In the end, most of our trust has to be in people. It was a person who forgot to log out of my account. It was a person who saw that as an opportunity to play a joke. All of the characters in this story were people. That is true in most security incidents. It usually isn't some very clever program that causes a security breach. It is usually some persons action, logging into a web site that one shouldn't have. Posting their vacation itinerary on their facebook wall. Choosing 123456 as their password.

Fortunately, this incident was more illustrative than dangerous. Plus, to live successfully, one must trust some people. Therefore, in the end, I decided I still trust the folks at the service. Although, I did ask them to read this entry, so that they can think about how to be more careful with other people's data.

However, when one encounters what looks like a hack attempt, one cannot be too careful. Taking immediate action to prevent the problem from getting worse was the prudent thing to do. I'm happy that the incident appeared to be more in my head than reality, but I'm still glad I didn't let it get out-of-hand, and would have been more so had I really been hacked by someone malicious.

Epilog

After writing this description, I had some additional exchanges with the fine folks at the service who explained what actually happened as opposed to what I perceived, I include some of that here:

Fair enough, but you have to know that I wasn't playing any kind of "joke" on you ... I was multi-tasking and trying very hard to help a valued user. And NOBODY else had access to your account --- the @barakobama "tag" was just the next thing I did in our service and I failed to notice that I was spoofed in as you via our system.

I readily admit the mistake and the tone of your post is very fair so I have no qualm.

I have not, however, figured out the issue you're having ... and I have to "spoof" your account to do so. Just as an FYI, I don't have ANY ACCESS to your Twitter account. We use Twitter to authenticate you but the resulting cookies are written to your computer (same as Twitter) and NEVER save that information on our end.

We know some applications do keep credentials and we see this as the type of grave threat you describe. And I personally only allow two applications access to my Twitter account (Our service being one.)

Anyway, when I diagnose your RT issue I will be more cautious, I promise.

Thanks for sharing and for being as generous as possible with your written commentary. We hope to keep you as a regular user, and we hope you continue to find value in our service.

Wednesday, November 11, 2009

Is Twitter Still Safe?

That's a good question to ask. Fortunately, with a little "common sense" the answer is still yes. But, as I've warned so many times, the world isn't as safe as it appears, so you have to be careful, maybe even a little paranoid.

So, why do I warn so often that I'm beginning to feel like the boy who cried wolf?

The answer is I work on making your computer more secure. I do that for Intel. They also gave me the right to twitter about things I work on--not to give away secrets, but to relay things that I have learned in my job. That doesn't mean I speak for Intel. These are my own insights and opinions. So, while my job at Intel is not to give advice on internet safety, I don't feel I would be doing my job if I didn't pass on things I learned along the way that could help you stay safe. Thus, I pass along these personal tips, one fellow human being to another.

If you've read previous blog postings by me, you will see how I've talked about related topics before, email spam, general twitter safety, etc.

This time, I'm going to address the current variation of that same problem: Direct Message (DM) attacks.

Twitter has gotten popular and important enough to merit its own attacks. It is not clear how serious these attacks are, but we know for certain that the attacks are acting like a worm or virus, spreading from one hacked account to others. The way this attack appears to spread is through DMs sent from the hacked accounts. The DM goes out to the followers and invites them to play a game (test your IQ) or visit a site where the followers information is supposedly saved. I've gotten both of those messages from tweeps who I was following and were hacked.

Next, when you visit the site, the site needs your twitter information, either by you logging in, or by you telling twitter to allow the application access to your account. Either way, the application then gets accessed to your account, and you've been "pwned". The application now can mascarade as you and use your follower list to spread farther.

Now, if this is all the hack is, it is basically a proof-of-concept test. Someone needed to prove that they could use twitter to spread a virus. And, so far, that may be the case. On the malware scale, this is quite benign. It takes some work to clean up, but it hasn't done any real damage, except perhaps to the hacked people's reputation.

However, experience has shown that these initial "prank" hacks get quickly replaced by more serious attacks that our out to steal something from you, something that likely has more tangible value-often to steal information that can used for identity theft or other forms of fraud.

Therefore, we need to take these pranks seriously and use them to alert us to the imminent danger that is coming when someone figures how out to use this method of spreading a virus to send a more dangerous cargo.

So, what is a person to do?
  1. The first step is to stop following links in DMs. If someone sends you a link in a DM, treat it like it was spam email.

  2. Moreover, do your firends a favor and don't use DMs to send your friends links either. If we make it a practice, to never send a link as a DM, then any DM we get with a link, is clearly a phish or a hack. In fact, I like to think of a DM as the twitter equivalent of a whisper. So, the only time I DM is when I want something to be private, something I would whisper. However, sharing information is not something I do in private (unless it's private or secret info), so DM'ing a link is odd to me, since a big part of twitter is sharing with the world.

  3. Change your password now, before you are hacked. Make it something safe and make it something different from all your other passwords. Write it down if you have to. Better yet, use a "password manager" to remember your passwords for you, so you can have lots of safe passwords, all different.

  4. Go through the list of applications you have given access to your twitter info to and revoke the permissions for any you don't use or that seem suspicious. That list can be found in your twitter settings/connections.

  5. If you have been hacked, do steps 3 and 4 at least twice in a short period of time. This will hopefully, keep the malware from noticing that you have changed the information and restealing it. There is a small window of "vulnerability" if the software has both your password and is authorized to act on your behalf that the malware can fix up the one you change by using the other access right. However, it is unlikely that this version of the virus is sophisticated enough to do that.

  6. In addition, if you suspect you may have been hacked, run your computer's virus/spyware scanner(s). Right now, it doesn't look like this particular attack is loading other malware onto systems, but it is only a matter of time before someone modifies it to download other malware onto your computer at the same time it is spreading itself.

  7. Be prepared for the attack to change. Right now the attack is spreading via DMs. The attack could have just as easily spread via @ messages or RTs or even plain tweets. That means we all have to be careful about which tweeple we follow links from.

  8. Figure out who you trust and what you trust them on. For example, if you are reading this, you probably trust me for security related tweets and maybe another topic or two, Intel, programming, science, MBTI, Enneagram, or twitter itself. However, if you were to get a tweet from me on a hot-stock pick, you should probably realize that I don't have that kind of information, and wouldn't share it in a tweet even if I did.

  9. Next, if you are sharing links, check them before you send them. Make certain the link you are sharing actually points to the item you want to share. And, if you are going to share links, make sure your virus software is running, so that you will know when you get hit by a drive-by infection from a bad link before you RT that link out to others. And, if you are visiting a link from someone you aren't certain you trust (a new friend, you have just started following for instance), use one of the tools that help you expand short links before you follow them, so that you can check that it looks like a reasonable address before actually visiting the site.

  10. Remember that these are only guidelines to stay a little safer. For now, they should suffice, but some of us still will get hacked. Eventually, unless we find a way to convince all the criminals to stop spreading malware, we will probably have to be more careful, so watch for follow up advice.
I hope this advice helps you stay safe and unhacked. If you think of something I didn't say, add a comment. If we work on educating each other, we can hopefully make common sense actually something we share in common.

Sunday, October 11, 2009

Be Paranoid

I'm not naturally a paranoid person. In fact, I'm very gullible. Just ask those who've played practical jokes on me. I like trusting people. Generally, I find myself rewarded for doing so.

However, when it comes to email, I'm not. Unfortunately, there is good reason for that. Using email is about the least safe thing you can do. And after reading the great blog post Five messages to never trust in your e-mail box, I realized that one should be even more cautious than sjvn suggested.

That doesn't mean you can't send emails to friends and colleagues or read those that they send you. In most cases, those will be safe. However, even sometimes reading those is risky, and I will expand on that in a bit.

The problem is that email has no security. You have no idea whether the person sending you an email is who they say they are or not. This includes email that looks like it is coming from your friends and co-workers. The problem is that there are people who take advantage of that and are getting quite sophisticated at abusing the system to steal things from you via email.

Now, this stealing can be relatively benign, as in spam, where the sender is simply sending you an unwanted advertisement that you can ignore and the only thing stolen is the effort it takes to wade through the mounds of spam you receive everyday. Moreover, the email services do weed out some of the spam, so that you can one-click dispose of much of it.

And perhaps, you actually like reading certain kinds of advertisements--I actually watch certain ads on TV from time to time because they are worth watching. However, with email I advise you not to. The reason again, is that the sender and/or message can be forged. On TV, (or radio) someone has to pay good money to get the message on the air, so it isn't cost effective to attempt to do a forgery.

However, email forgery is essentially zero-cost. A criminal can use computers infected with certain viruses (called bots) to send out as much email as desired with no cost, except for the small risk of getting caught. That means it is worthwhile to try and con people by impersonating someone they would normally read. That means if you read an advertisement in email, even if it looks like someone you would normally deal with, it may be fake.

Let's use an example to make it more clear. Once I took an Alaskan cruise and allowed the cruise line to add me to their email mailing list. Now, I regularly receive messages that report to be about low cost cruises that they are offering. I'm sure most of those offers are real. However, if just 1 is a fake and includes a link to a site that seems to be the cruise line's site and I follow that link thinking I'm about to get a good deal, I could be clicking on a link that loads a virus onto my computer which then captures my credit card information, as it passes the information on to the real site and registers me for the real cruise deal. Since, I get to go on the cruise, I'm none the wiser that someone has stolen my credit card information, until sometime later when charges I've never authorized start appearing. And, yes the criminals who are doing these misdeeds are getting that good.

So, if the situation is that bad what does one do.

1) Never click on any link (or call any "commercial" phone number) in any email message. If for some reason, you want to respond to the email message, contact the relevant party by another means.

For example, I once received what appeared to be a phishing message suggesting one of my accounts had been hacked. I did not click on the web address in the message nor call the number listed. Instead, I f0und the company phone number from a separate reliable source (e.g. by calling information at the telephone company) and got in touch with the company's fraud department that way. It turns out, the original link and phone numbers were both fraudulent and had I not been cautious, I would certainly have been scammed.

I had a similar experience when I received a message that suggested an account I had had been granted a special offer, but it wasn't one I regularly dealt with. Again, I got a separate number to the company and contacted them that way. The company was able to identify the special promotion that was being offered and make it available to me. The company was not able to identify the phone number that was in the offer though. So, who knows who I would have reached if I had called it.

2) Know that your bank or other company is never going to contact you about legal matters through email, unless you are already in an ongoing email dialog with them.

The closest you will get to that is "privacy notices" stating general policies or alerts you have specifically requested. However, if something happens to y0our account, email is unlikely to be the banks first choice for contacting you. It tends not to protect their legal rights, so it isn't in their best interest to do so.

If you have alerts set up, say for a credit card balance, again remember to check the information using a separate method of contacting the company. Don't click on the link in the alert. With a credit card, you can login to the web site (the one that you know because you've used it before and written down the web address) or call the number on the back of your credit card to check your balance.

3) Even if the messge appears to be from a friend, don't click on the link unless this si someone who regularly sends you such links.

Another way that is becoming increasingly popular is called spear fishing. In this case, the miscreant finds a way to get someones email address book and forges emails from the person to the addresses in the book. Those messages can look more liegitimate than ones from a bank. Such messages could contain viruses (or links to viruses). So, unless you and your friend regularly exchange information via links, assume that the link in the email is not actually from your friend but an imposter. This is particularly. true if the link appears to be to some "good deal" web site that you just must see to believe.

3) Don't reply to emails or forward chain-mails.

While some of them may be legitimate, that doesn't mean they can't be intercepted for misuse. A chain-mail can have hundreds of real email addresses on it, email addresses of people who typically will forward chain mails. Once, one of those gets into the hands of a criminal, the criminal has a whole list of easy marks to target, marks who will further spread the message to other unsuspecting people.

Unfortunately, this also includes many charity requests. Sadly, you don't know if the person sending the request really does have a child with cancer or not. Any money you send might actually be going to a criminal. Even if the message appears to be from a friend, criminals still could be diverting the money into fradulaent accounts.

Again, if you really want to do something, find a way to contact the person through another reliable channel and then mail the person the money. If you really want to give to a charity, validate that your money is really going to the charity--all charities have real addresses where you can send them a check in a letter. Almost all of them have phone numbers listed with the phone company and will happily take money that way too.

Finally, these hints apply to unsolicited phone calls, to people going door-to-door, to people communicating by twitter or facebook, to any place where you don't know the person. You can still generally buy cookies and candy safely from the kids coming to your door, but beyond that everyone you don't know is suspect. And therein lies the real lesson, the internet may have made the world a smaller place and made it easier for people with bad intent to try to scam us, but the basic techniques have been known by con-men for ages, and they will keep reworking them and making them more sophisticated to try and steal from us.

However, a little paranoia can stop you from being an easy victim. It has saved me and I would normally be an easy mark. And if you aren't an easy victim, perhaps you won't be a victim at all.

Disclaimer, I work as a security researcher at Intel, but my job has nothing to do with this advice. I don't work in fraud prevention or in securing Intel's email or web sites. All information in this posting is based solely upon my experiences and opinions.

Saturday, August 29, 2009

The Weakest Link

The latest twitter security vulnerability emphasizes one of the hardest parts of making things safe: the weakest link. It's more than just one of those many game show ideas. It is an important "common sense" concept, where we know as the old adage says that a chain is only as strong as its weakest link.

In our case, the software we use is now highly interconnected. We don't build systems from the ground up. We rely on software built by others to make it work. There are operating systems, compilers, databases, browsers, networking stacks, libraries, etc. and those are just the major categories. More importantly, the lines between these categories have blurred.

Twitter is a great example of this. At some level twitter is an application hosted on some set of servers in the cloud. This is why it was subject to the Denial of Service (DOS) attack that affected it recently. Like many network applications, it can be (and often is) accessed via html using a browser. Thus, twitter is subject to all the flaws present in your browser and any pages it serves up can trigger those flaws. Like many html applications, the rich interactive interface cannot be served up by html alone, so browser extensions like Javascript are used to program features not present in raw html. That introduces a whole new layer of flaws that can be exploited. Moreover, that rich content, often uses other extensions like Flash players that we have to download onto our computers, which is a very rich vein of flaws to exploit.

The potential weaknesses don't stop there. Because web pages get traversed by "spiders" like Google looking for content, they have to be sophisticated to help defeat those who "game" the system doing "Search engine optimization" (SEO) and attempt to get all our searches directed to their pages. Those pages can be legitimate or they can be malware (i.e. that get us to download fake versions of a flash player, which is really a virus) or pornography or a scam. Twitter turns out to be particularly sensitive to attacks by malicious web pages because it allows "applications" to enter web pages into the system, and it then runs those pages on your computer.

That vulnerability turns out to be the new weakest link. It means just by running twitter on the web you can be "sent" to a web page that you have never clicked on--a malware writers dream.

The bright spot in this particular cloud is that reading your tweets with an application like tweetdeck, you don't have quite as rich an experience and it doesn't send you to the web page. Therein lies the protection.

Eye candy such as animated web pages do make for a very compelling internet experience and have let companies like Google offer web-based applications that are slowly breaking the control of the desktop away from Microsoft. However, this rich experience has come with a very high price. The bazaar we inhabit on the web has not only a wide variety of goods at very cheap prices but also pick-pockets, con-men, drug lords, and all the other undesirables.

A less "rich" experience would make us safer. Certainly, I love playing Sudoku on my computer, but I fear getting addicted to a twitter version of some immersive reality game, where behind my back many different hidden transactions are occurring and downloading and uploading all sorts of things I don't know about and can't control.

For that reason, for a long time, I kept my email off of servers like Hotmail and Google and read it through a text only service (on an unpopular architecture) where to read a mime message, I had to manually copy the file to a different location, and run a special program, which then put the text somewhere I could read it using a different program. If that sounds inconvenient, it was, but in all that inconvenience was safety, because breaking any one of the links did not break the whole chain. Unfortunately, like everyone else, I slowly succumbed to the siren call of the rich and simple internet experience. My work email is in Microsoft Outlook and personal email is on Google. Those services are more protected than they were, but I am still vulnerable like everyone else to any flaws in them.

Therein lies the crux of the problem to me. to fully participate in this world, especially to take advantage of what's new and exciting, one has to expose oneself to a whole variety of software built on long chains of leaks, each of which can be broken, and over which one has little or no control. Even though most messages I send and receive are text, I can't go back to a simple text only world. The interconnections and dependencies have grown so strong that even to send plain text I need to participate in a much more complex ecosystem of interacting applications doing things for me automagically, often without my knowledge or asking my consent.

In that way, it is surprising that we don't suffer more infections and breakdowns. However, I attribute that to the fact that most people are actually honest and honorable and as a result we can keep some reigns on the attacks we are subjected to. That inherent honesty is an aspect of human nature that helps blunt all the bad aspects and why in most cases we can depend on there to always be security researchers like David Naylor who find the flaws in our software and don't exploit them, but instead attempt to get them fixed by posting blogs with advice. before someone does exploit them and this is not just an icon.