Twitter malware filter 'disappointing'

By Vivian Yeo, ZDNet Asia
Tuesday, August 04, 2009 07:23 PM

Twitter's new malware filter is a sign the social media site is stepping up efforts to stem attacks, but the measure has its shortcomings, say security experts.

Twitter's filtering mechanism was highlighted by Mikko Hyponen, chief research officer of F-Secure, in a blog post Monday. When a user tries to submit a tweet with a suspect Web link, the following warning appears:

"Oops! Your tweet contained a URL to a known malware site!"

Twitter's latest security measure was a positive one, especially in light of the current threats directed at the site, Hyponen told ZDNet Asia in an e-mail interview. The site, he noted, has been "attacked in many ways" including spam, worms such as Mikeyy, and phishing, he noted.

"None of these problems are at epidemic levels yet, but it's great to see Twitter take real action on this," he said.

Hacking is another challenge the popular microblogging site faces. In May, Twitter confirmed its network was hacked and some individual account information were leaked.

Dancho Danchev, independent security consultant and cyber threats analyst, noted that the site's latest security move was an indication "Twitter is finally moving from reactive to proactive security practices". However, he pointed out in a blog post on ZDNet Asia's sister site ZDNet.com, that the malware filter was "clearly still in development" and showed "disappointing results".

Danchev pointed to how a MySpace phishing page used in a tweet triggered the security filter, but was eventually accepted by adding a "http://" or removing the "www".

He noted that the site also allowed tweets containing links to several known malicious sites listed in Stopbadware's database, which has identified over 380,000 sites identified as unsafe. While it would not prevent the abuse of Twitter in the longer term, the failure to integrate such databases listing known malware was a "missed opportunity", Danchev said.

Twitter did not respond to e-mail queries from ZDNet Asia at press time.


WORTHWHILE?

0

0 votes
Blog

Talkback 1 comments

Twitter malware filter 'disappointing'
for me it works fine BitDefender. It filters all the phishing pages. i'm very pleased of it
Posted by Edward Stream on Tuesday, August 04 2009 07:51 PM


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web