Twitter Security Collapses; Obama, Fox and Britney Accounts Hacked
readwriteweb.com
readwriteweb.com
"It will be good for the people calling for more secure, standards based authentication on Twitter and elsewhere around the web." [from article]
"it is important to note that OAuth would not have prevented either of these attacks" [from Twitter]
I see the point for OAuth third party applications, but that's not the attack vector here. That's just free association. What more secure authentication do people want? Client certificates? Dongles?
One of my guesses would have been updates via SMS. I've read it's easy to forge caller ID; if it's as easy to forge an SMS origin-number, and you knew these accounts were set up to allow updates via SMS from a certain number... voila!
But what does scale have to do with security?
why are we even discussing this?
Ouch, not exactly confidence inspiring. It's also sort of ironic that one of the headlines under "Twitter is Del.icio.us" is "Governments use Twitter for Emergency Alerts, Traffic Notices and More - Government Technology"
Imagine the havoc that would ensue if a large number of people were following some government's emergency alerts on Twitter and someone were able to gain control. It would be pretty easy to incite panic.
Or if the attacker didn't like a politician, like Obama, he could post subtly offensive comments as the politician.
http://en.wikipedia.org/wiki/List_of_fictional_South_Park_sp...