Apr 09

Twitter Vulnerable to Spoofing?

posted in In The News on 04/09/07 at 10:04 AM

If you're new here, you may want to subscribe to my RSS feed. Thanks for visiting!

Can someone pose as you on Twitter? With a very simple trick, yes they can.

Both Twitter and Jott authenticate users by their phone number. Twitter does this by validating users based upon the source of SMS messages sent to the phone number 40404 (US), and Jott does this by trusting the incoming Caller ID when someone calls 877-568-848. From a security perspective this means the following:

* Anyone who knows your phone number can update your Twitter page by spoofing a SMS message, i.e. post a Twitter entry as you.
* Anyone who knows your phone number can spoof his or her caller ID to send a Jott message as you.

Read Twitter and Jott Vulnerable to SMS and Caller ID Spoofing by Nitesh Dhanjani for the full details. Needless to say I hope they are able to fix this. I don’t know much about the SMS world but hopefully they’ll be able to block these fake sender services. The problem is new ones will fill up all the time. Does this mean Twitter and similar services need another layer of authentication? I know a lot of people on Twitter publish their cell phone numbers on their web sites so this could get ugly kinda quick like.

Technorati Tags: , ,

One Response to “Twitter Vulnerable to Spoofing?”

commentstyle
1 links for 2007-04-18 « My Weblog Says:

[...] Twitter Hacks » Blog Archive » Twitter Vulnerable to Spoofing? (tags: malware spoof twitter web20) [...]

Leave a Reply

By submitting a comment here you grant this site a perpetual license to reproduce your words and name/web site in attribution. I reserve the right to delete any comment for any reason with and will aggressively smite spam, flames and unsavory behavior.