[564] in Privacy_Forum
[ PRIVACY Forum ] Confirmed: Twitter DNS diversion used Twitter login
daemon@ATHENA.MIT.EDU (privacy@vortex.com)
Fri Dec 18 16:00:03 2009
Date: Fri, 18 Dec 2009 12:39:42 -0800
To: privacy-list@vortex.com
Message-ID: <20091218203942.GA22578@vortex.com>
MIME-Version: 1.0
Content-Disposition: inline
From: privacy@vortex.com
Reply-To: PRIVACY Forum Digest mailing list <privacy@vortex.com>
Content-Type: text/plain; charset="iso-8859-1"
Errors-To: privacy-bounces+privacy-forum=mit.edu@vortex.com
Content-Transfer-Encoding: 8bit
Now confirming [ Ref: http://www.nnsquad.org/archives/nnsquad/msg02460.html ]
that the Twitter DNS diversion last night was the result of someone using
Twitter's own login credentials to change DNS data at Dyn's site,
according to Dyn's CTO:
http://bit.ly/80Ve4Y (Wired)
So as suspected, this was not a "sophisticated" attack (e.g.,
DNS cache poisoning) but rather a conventional login attack.
It is interesting to consider that apparently a single
username/password pair was able to take Twitter's entire Web site
effectively offline globally.
At the very least one would hope that more advanced account control
mechanisms (e.g., certificate-based access authentication) would be
employed with critical accounts for organizations at this level.
--Lauren--
Lauren Weinstein
lauren@vortex.com
Tel: +1 (818) 225-2800
http://www.pfir.org/lauren
Co-Founder, PFIR
- People For Internet Responsibility - http://www.pfir.org
Co-Founder, NNSquad
- Network Neutrality Squad - http://www.nnsquad.org
Founder, GCTIP - Global Coalition
for Transparent Internet Performance - http://www.gctip.org
Founder, PRIVACY Forum - http://www.vortex.com
Member, ACM Committee on Computers and Public Policy
Lauren's Blog: http://lauren.vortex.com
Twitter: https://twitter.com/laurenweinstein
_______________________________________________
privacy mailing list
http://lists.vortex.com/mailman/listinfo/privacy