TECHNOLOGY
Security
Cybersecurity's twitter-fast shifts
Last Updated: Monday, April 27, 2009 | 1:21 PM ET
By Andy Greenberg, Forbes.com
Related
(Associated Press) Twitter, despite its chirpy logo and its endorsement from Oprah, isn't as harmless as it seems.
Throughout April, worms have ripped through the "microblogging" platform, infecting user accounts with malicious code that spread from profile to profile as Twitterers visited one another's compromised pages. Every time Twitter's administrators declared that they had cleaned up the infection, a new strain of malicious code would begin propagating through thousands of accounts, week after week.
So far, that string of 140-character epidemics has seemed to be nothing more than an experiment in hacking Twitter, designed by a 17-year-old Brooklynite named Mikey Mooney. But the warnings for the microblogging platform and its explosively growing user base are clear enough: Next time, the same sort of worm could be designed to steal users' passwords or hijack their PCs with malicious software.
Cybersecurity researchers may not be surprised that novel attacks follow every new digital medium that becomes popular. But for everyone else, the recognition that cybercriminal exploits are changing almost as rapidly as Twitter's real-time updates presents a daunting problem: How do we practice safe online behavior when the Web's safety code is constantly in flux?
"The rules are always changing as the threat landscape changes," says Jeremiah Grossman, a Web security researcher with White Hat Security. "It's like you're told not to shake hands with the guy who's coughing and whose nose is running. But then it turns out that someone who looks healthy can infect you just as easily."
One of those new rules, Grossman says, is that generic messages from "friends" on social sites like Twitter and Facebook can no longer be completely trusted, given that both sites have been repeatedly hijacked by hackers.
'Our security practices have become paranoid to the point that we have to assume that practically everything is compromised.'—Jeremiah Grossman, research
But the erosion of trust online goes further: Simply visiting a site that's been infected with malicious software can download password-stealing software to a user's PC, a technique known as a "drive-by download." An evolving breed of attack known as DNS (Domain Name System) redirection can send users to invisible look-a-like sites when they type an address directly into a browser. And hacker tricks like Cross-Site Scripting and Cross-Site Request Forgery allow some sites to steal the "cookie" files downloaded to your browser, giving hackers access to any past site you've visited.
"Our security practices have become paranoid to the point that we have to assume that practically everything is compromised," says Grossman.
Rise in phishing victims
That growing paranoia is at least partly justified. According to Gartner Research, more than 5 million Web users lost money to phishing attacks over the 12 months ending in September 2008, a 40 per cent increase in the number of victims during the same period the year before.
That increase marks a shift in strategy among cybercriminals. Thanks in part to fraud-detection systems that prevent identity thieves from withdrawing more than a few hundred dollars from compromised bank accounts, cybercriminals are expanding their tricks to draw in a higher volume of credit card numbers than ever before.
But a few simple measures can cut off most of those attacks. Preventing a compromised Web site from infecting your computer with malware, for instance, is often as simple as using a secure, well-updated browser, says Dan Holden, a Web security researcher with IBM's Internet Security Systems. "The browser is still the lowest common denominator, the universal application that attackers will look at first," he says.
Keeping your browser updated helps to ensure that any recently discovered vulnerabilities in the software won't be exploited by cybercriminals. And not all browsers are created equal. In the Pwn2own hacking contest last March, only Google's Chrome browser couldn't be hacked by contestants, thanks in part to its "sandboxing" feature that keeps Web sites from accessing a user's PC resources. Apple's Safari browser, by contrast, was compromised in minutes.
Just as important as browser security, says Holden, is updating plug-ins, the programs that run within a browser to enable functions like animation or video, such as Adobe Flash or Microsoft's ActiveX. Cybercriminals often design their infections to exploit vulnerabilities in embedded programs as well as in browser software, so every plug-in requires constant patching to avoid malware download. In fact, four out of five of the Web attacks recorded by IBM in the last year exploited weaknesses in ActiveX, Holden says.
Less common new attacks like DNS hijacking have solutions too. Those attacks exploit the Domain Name System, a kind of digital directory hosted by broadband carriers, to redirect users to look-a-like phishing sites when they type an address into their browser. But users who want to be sure that their DNS isn't being compromised can check their connection at Doxpara.com. Those who are still vulnerable can protect their browsing by switching to a private, free DNS service like OpenDNS.
Still, the truly security conscious take more serious measures. White Hat's Jeremiah Grossman, for instance, uses two browsers — one is for normal browsing, while the other is for accessing secure sites like banking and e-commerce.
By splitting his Web time between the two, Grossman argues it's less likely that an insecure site could use a trick like Cross-Site Scripting or Cross-Site Request Forgery to steal the "cookie" files that would allow access to the secure sites. "That way I compartmentalize my risks," says Grossman.
Call it cyber paranoia. Or, given the Web's roiling landscape of risk, you could also call it common sense.
Share Tools
Top News Headlines
- Everest victim's husband says family not seeking government help
- The husband of a Toronto woman who died trying to climb Mt. Everest on Saturday says his family is not seeking government help to cover the cost of bringing his wife's body home. more »
- Henrique's OT goal sends Devils into Stanley Cup final
- The New Jersey Devils will vie for a potential fourth Stanley Cup in franchise history after completing a six-game series win Friday night over the New York Rangers in the Eastern Conference final, courtesy of rookie Adam Henrique's goal early in overtime. more »
- Employment Insurance review boards to be scrapped
- The federal government is scrapping two review boards used by people appealing decisions made about their employment insurance. more »
- Teens share bullying tales in confession booth
- Raw stories about bullying emerged when a video booth was set up inside a Quebec high school. more »
Latest Technology & Science News Headlines
- Unloading of docked SpaceX capsule to start Saturday
- The privately bankrolled SpaceX Dragon capsule made a historic arrival at the International Space Station on Friday, and astronauts will begin unloading some of the 544 kilograms of food, water, clothing and other supplies its carrying starting Saturday.
more »
- South Africa, Australia to share world's largest telescope
- South Africa and Australia will jointly host the Square Kilometre Array, which promises to be the world's largest telescope, the international consortium in charge of the project said Friday. more »
- Bonavista, N.L., 'coyote' was really wolf, tests confirm
- Wolves have not been seen in Newfoundland since around 1930 and were believed to have been hunted to extinction on the island, but genetic tests have confirmed that an 82-pound animal shot on the Bonavista Peninsula in March was, in fact, a wolf. more »
- Once-rare argus butterfly thriving thanks to climate change
- Global warming is threatening the existence of many species, such as the giant polar bear, but in the case of Britain's brown argus butterfly, it took a species in trouble and made it thrive. more »
- Yahoo scraps digital magazine designed for iPad
- Yahoo has killed Livestand, a tablet magazine, just six months after its debut on the iPad. more »
Bob McDonald's Blog
Government to shut down unique fresh water research area May. 25, 2012 12:31 PM The Experimental Lakes Area research facility in Northern Ontario is being closed down after 44 years of providing invaluable data to scientists in Canada and internationally, a decision that has stunned researchers and environmental groups.
Quirks & Quarks
- May 26: Before the Lights Go Out May. 25, 2012 4:15 PM A new book, "Before the Lights Go Out: Conquering the Energy Crisis Before It Conquers Us", suggests that the unpredictable, unplanned, ad-hoc way our energy use developed in the past will shape our energy future.
Latest Features
- Aylmer triple stabbing leads to first-degree murder charges
- Everest victim's husband says family not seeking government help
- Reclaiming the dead on Mt. Everest
- Employment Insurance review boards to be scrapped
- Teens share bullying tales in confession booth
- Canada ending 'Buffalo shuffle' for visas, closing consulate
- Brave cat makes epic leap of faith
- What a Greek euro exit could mean for Canada
- Double-lung recipient dances on Ellen show


