Tag Archive for: flawed

Twitter transgression proves why its flawed 2FA system is such a privacy trap

Cartoon image of a sperm whale being held aloft by balloons,

Enlarge (credit: Twitter)

If ever there was a surefire way to sour users against a two-factor authentication system that was already highly flawed, Twitter has found it. On Tuesday, the social media site said that it used phone numbers and email addresses provided for 2FA protection to tailor ads to users.

Twitter requires users to provide a valid phone number to be eligible for 2FA protection. A working cell phone number is mandatory even when users’ 2FA protection is based solely on security keys or authenticator apps, which don’t rely on phone numbers to work. Deleting a phone number from a user’s Twitter settings immediately withdraws account from Twitter 2FA, as I confirmed just prior to publishing this post.

Security and privacy advocates have long grumbled about this requirement, which isn’t a condition of using 2FA protection from Google, Github, and other top-ranked sites. On Tuesday, Twitter gave critics a new reason to complain. The site said it may have inadvertently used email addresses and phone numbers provided for 2FA and other security purposes to match users to marketing lists provided by advertisers. Twitter didn’t say if the number of users affected by the blunder affected was in the hundreds or the millions or how long the improper targeting lasted.

Read 9 remaining paragraphs | Comments

Biz & IT – Ars Technica

Flawed routers with hardcoded passwords were manufactured by firm that posed ‘national security risk’ to UK

Flawed routers with hardcoded passwords were manufactured by firm that posed 'national security risk' to UK

Researchers discovered it was possible to compromise Hyperoptic’s ZTE-manufactured routers simply by tricking an intended victim into clicking on a malicious link.

Read more in my article on the Hot for Security blog.

Graham Cluley

A Flawed Tale of Cyberwarfare Is Fanning ‘Russiagate’ Obsession

  1. A Flawed Tale of Cyberwarfare Is Fanning ‘Russiagate’ Obsession  Truthdig
  2. The Russia Collusion Suspect Nobody’s Talking About: CrowdStrike’s Dmitri Alperovitch  The New American
  3. Full coverage

cyber warfare news – read more

Is internet security fundamentally flawed? – ITProPortal


ITProPortal

Is internet security fundamentally flawed?
ITProPortal
Is internet security fundamentally flawed? While there certainly are challenges and that some will say that security is fundamentally broken, the good news is that there are things that you can do that will greatly increase the chances of a more
Akamai Releases Third Quarter 2016 State of the Internet / Security ReportPR Newswire (press release)
DDoS Attacks Hit Unprecedented Scales in 2016 Third Quarter: Akamai ReporteWeek
Major DDoS Attack Causes US Outages on Twitter, Reddit, OthersCIO Today
TechRepublic –Business Recorder (press release) (registration) (blog) –IDTechEx.com (press release)
all 77 news articles »

“internet security” – read more