Twitter settles with FTC over data security lapses

Jun 24, 2010 By JOELLE TESSLER , AP Technology Writer

(AP) -- Twitter has agreed to settle charges by federal regulators that it put the privacy of its users at risk by failing to protect them from data security lapses last year that let hackers access their accounts.

The said Thursday the settlement bars from misleading consumers about its security and privacy practices and requires the start-up to establish a comprehensive information security program.

No monetary damages were assessed.

The FTC complaint said the breaches allowed hackers to gain administrative control over the online service, which lets users send brief messages called tweets to each other. According to the FTC, hackers were able to view email addresses and other private user information, gain access to user messages, reset user passwords and send phony tweets from user accounts.

At least one phony tweet was sent from the account of Fox News and another phony tweet was sent from the account of then-President-elect Barack Obama offering more than 150,000 followers a chance to win $500 in free gasoline, the FTC said.

The agency charges the incidents deceived users because Twitter's privacy policy pledged to "employ administrative, physical, and electronic measures designed to protect your information from unauthorized access."

"When a company promises consumers that their personal information is secure, it must live up to that promise," David Vladeck, head of the FTC's Bureau of Consumer Protection, said in a statement.

One breach occurred in January 2009 after a hacker used an automated password-guessing tool to gain control of Twitter. The second breach occurred in April 2009 after a hacker broke into a Twitter employee's personal email account, which stored two passwords that were very similar to the employee's administrative password for Twitter.

The FTC said Twitter was vulnerable to these attacks because it used weak, lower case common dictionary words as administrative passwords and failed to take reasonable steps to prevent unauthorized access to its system. Such steps include prohibiting employees from storing administrative passwords in plain text in their email accounts, periodically changing administrative passwords and restricting access to administrative controls.

In a blog post, Twitter General Counsel Alexander Macgillivray said that even before the company reached the agreement with the FTC, it had already implemented many of the security practices highlighted by the agency. He added that the company quickly closed the security holes, notified affected users and disclosed what had happened in blog posts following both incidents.

Macgillivray also noted that Twitter employed fewer than 50 people when the breaches occurred.

"At the time of the incidents, we were ... in the midst of perhaps unprecedented user growth for an Internet company; and, didn't employ the security methods that we use today," the company said on Thursday.

Twitter said 45 accounts were accessed in the first incident and 10 accounts in the second incident.

Explore further: Twitter tightens security after high-profile breaches (Update)

not rated yet
add to favorites email to friend print save as pdf

Related Stories

Twitter hacked by old technique -- again

Jul 15, 2009

(AP) -- Breaking into someone's e-mail can be child's play for a determined hacker, as Twitter Inc. employees have learned the hard way - again.

Suspected Twitter infiltrator: 'I'm a nice hacker'

Mar 25, 2010

(AP) -- He's unemployed and isn't much of a computer expert. The Frenchman accused of infiltrating Twitter and peeping at the accounts of President Barack Obama and singers Britney Spears and Lily Allen says he wanted to ...

Twitter bug zaps followers (Update)

May 10, 2010

Twitter was bitten by a bug on Monday that caused users of the fast-growing micro-blogging service to temporarily lose the list of followers of their accounts.

Recommended for you

Facebook joins Web freedom group

6 hours ago

Facebook on Wednesday became a full member of the Global Network Initiative, a non-governmental organization promoting Internet freedom and privacy rights.

Big Data—for better or worse

11 hours ago

A full 90% of all the data in the world has been generated over the last two years. The internet companies are awash with data that can be grouped and utilised. Is this a good thing?

Risky behaviour starts young on social media: survey

12 hours ago

Australian children are accessing social media websites at an increasingly younger age, a new survey suggests, with one in five "tweens" admitting they have chatted to someone online they do not know.

Poll: Teens migrating to Twitter (Update)

May 21, 2013

Twitter is booming as a social media destination for teenagers who complain about too many adults and too much drama on Facebook, according to a new study published Tuesday about online behavior. It said ...

User comments : 0

More news stories

NASA: Austin, calling Austin. 3-D pizzas to go

(Phys.org) —The idea of living with 3-D printed food is neither unthinkable nor new; designers and futurists have been looking to 3-D printing as food's next frontier. In 2012, there was news that the Thiel ...

Forecast for Titan: Wild weather could be ahead

(Phys.org) —Saturn's moon Titan might be in for some wild weather as it heads into its spring and summer, if two new models are correct. Scientists think that as the seasons change in Titan's northern hemisphere, ...