Government // Enterprise Architecture
News
12/5/2012
08:16 AM
Connect Directly
Facebook
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

US Twitter Users Not Vulnerable To SMS Spoof

A vulnerability in Twitter would allow spoofed posts to a user's account if the account were enabled for SMS updates. Twitter said Tuesday that users in the U.S. are not vulnerable and that users abroad who are should configure their accounts to require a PIN for SMS updates.

A vulnerability in Twitter described by security researcher Jonathan Rudenberg does not affect U.S. users according to Twitter's product security engineering manager Moxie Marlinspike.

Twitter allows users to configure their accounts to receive posts and some profile changes via SMS commands sent to a particular code. In the U.S., this is a particular short code, specifically 40404. Elsewhere, a long code might be required. Rudenberg demonstrated how to trick the service into accepting commands from unauthorized sources.

Rudenberg said in a update to his post that Twitter fixed the problem for short code countries and recommends that other users configure their accounts to require a PIN for updates. But in his blog post Tuesday, Marlinspike said that users in countries with short code support, including U.S. users, are not vulnerable, making no reference to fixing the problem.

The posts imply a disagreement over when any fixes were made to Twitter, especially inasmuch as Marlinspike says "...it has been misreported that U.S.-based Twitter users are currently vulnerable to this type of attack." He doesn't specifically attribute such misreporting to Rudenberg.

Rudenberg had found a similar problem for Facebook and Venmo, but those services fixed the vulnerability before Rudenberg went live with his disclosure.

Comment  | 
Print  | 
More Insights
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Must Reads Oct. 21, 2014
InformationWeek's new Must Reads is a compendium of our best recent coverage of digital strategy. Learn why you should learn to embrace DevOps, how to avoid roadblocks for digital projects, what the five steps to API management are, and more.
Video
Slideshows
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
A roundup of the top stories and trends on InformationWeek.com
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.