The recent press on the Twitter hack shows how our personal laziness can come back to haunt us. There are tons of on-line articles to read about this incident, and there seems to be lots of blame to go around on how this happened.
To me, this incident points out the potential vulnerability of web 2.0 systems and why we need to be really careful about the information we choose to put on shared drives and in clouds. This dovetails with the password security and packet sniffer discussion we had in my HRIS class last week. It's not that the security isn't there, exactly; it's that it is fairly easy to get around when users aren't vigilent in their use.
Apparently, the Twitter administrator's password was stolen by someone hacking his personal account which used the same password as his google account. All of Twitter's internal documents are stored as Google Docs, which resulted in the hacker getting access to highly sensitive documents through Google.
I have long been concerned about security issues related to Internet communications. I never put my social security number on any web form, ever. I resisted on-line payments for longer than most, but the ease and convenience won me over. At work, I've consistently been the nay-sayer to web application and payments from our membership without encrypted security. The liability for the organization, not to mention the potential damage to the customer is just too great. I cringe when our benefits broker requests the employee census electronically. I usually feel like I'm being too conservative and behind-the-times. Now I realize there is at least some justification for my concerns.
Those who are critical of cloud computing are probably going to have a field day using this incident as an example of the problems inherent in shared resources. I'm not savvy enough to write a critique on the technological shortcomings that contributed to this situation. I do, however, recognize the inevitable operator error here. Humans are lazy. When faced with multiple accounts requiring passwords, the Twitter Admin did what many of us do regularly. He didn't use a unique password for his accounts. The hacker didn't have to be a rocket scientist to crack the code.
Here are a couple of interesting articles if you haven't reached over saturation on the topic. I have to go now..... I have a couple dozen passwords to change :)
How Microsoft and habit abetted Twitter Hack: http://tinyurl.com/n4hrvj
Twitter docs hack exploits stupidity : http://tinyurl.com/n6yngk
Subscribe to:
Post Comments (Atom)

No comments:
Post a Comment