Slashdot Mirror


Twitter To Establish Information Security Program

An anonymous reader writes "Twitter has agreed to settle Federal Trade Commission charges that it deceived consumers and put their privacy at risk by failing to safeguard their personal information, marking the 30th case the FTC has brought targeting faulty data security, and the agency's first such case against a social networking service. Under the terms of the settlement, Twitter will be barred for 20 years from misleading consumers about the extent to which it maintains and protects the security, privacy, and confidentiality of nonpublic consumer information, including the measures it takes to prevent authorized access to information and honor the privacy choices made by consumers."

72 comments

  1. Message in the Bottle by Rotworm · · Score: 3, Insightful

    The company also must establish and maintain a comprehensive information security program, which will be assessed by a third party every other year for 10 years.

    Twitter must also donate five nickels to five charities. At least three of those charities must be entirely independent of Twitter. Maybe the message is: if you marginally screw with the President, we marginally screw with you.

    1. Re:Message in the Bottle by Peach+Rings · · Score: 5, Insightful

      I don't know 20 years seems like an awful long time to be barred from doing something illegal...

    2. Re:Message in the Bottle by MoeDumb · · Score: 0

      It's even harsher than that. Should they do something illegal in the next 20 years, the prohibition period jumps from 20 years to 30! Rough justice, I say.

      --
      Mod Me Up. You'll make a grown man cry.
  2. Barred for 20 years? by Mothinator · · Score: 5, Insightful

    Shouldn't they be permanently barred from misleading their customers?

    1. Re:Barred for 20 years? by Anonymous Coward · · Score: 1, Interesting

      And they should have been permanently barred from the moment they started offering a service?

    2. Re:Barred for 20 years? by davidbofinger · · Score: 1

      I agree this sounds weird.

      A suspended sentence is essentially a ban on committing further crimes, perhaps this is somehow similar?

    3. Re:Barred for 20 years? by Anonymous Coward · · Score: 0

      Ths is pote fro my iPne 4, bies

      No yelo sphs, no anea fade when touc the rim.

      Nhig bt 10 iPhn pefecin.

      Eat t bihes. Hate he htas.

      Sorry, I can't understand what you just posted. I think you're saying something about iPhone 4, but I'm not certain. Is your iPhone losing letters randomly as you type them? Maybe the yellow spots on your screen are making you think your messages are coming in completely? Maybe you're losing connectivity while submitting your comments?

    4. Re:Barred for 20 years? by msauve · · Score: 1

      Shouldn't they be permanently barred from misleading their customers?

      This is the US government meting out punishment. "Permanently barred from misleading their customers" is an unnatural concept to them.

      --
      "National Security is the chief cause of national insecurity." - Celine's First Law
    5. Re:Barred for 20 years? by luckymutt · · Score: 5, Funny

      We're talking about Twitter...a 20 years barring is permanent.
      Hell, in half that time no one will be admitting that they were a "Twit."
      Kinda like how it is now with Friendster.

    6. Re:Barred for 20 years? by Ethanol-fueled · · Score: 1

      It's funny how Twitter could get a 20-year moratorium because somebody "hacked" Barack Hussein Obama's twitter while Big Oil(TM) gets only a 6 month moratorium, if even that.

    7. Re:Barred for 20 years? by howlatthemoon · · Score: 1

      Shouldn't every company be barred from misleading their customers?

    8. Re:Barred for 20 years? by nacturation · · Score: 1

      We're talking about Twitter...a 20 years barring is permanent.

      No kidding, that's like 4 consecutive life sentences for Twitter.

      --
      Want to improve your Karma? Instead of "Post Anonymously", try the "Post Humously" option.
    9. Re:Barred for 20 years? by zkp · · Score: 1

      If they mislead customers again during the next 20 years then they will again be barred from misleading customers.

    10. Re:Barred for 20 years? by lennier1 · · Score: 1

      Guess which side has donated more towards campaign funds?

    11. Re:Barred for 20 years? by martin-boundary · · Score: 0, Troll

      Kinda like how it is now with Friendster.

      What? I Never watched that show! You can't prove anything! I have no idea what Jennifer Aniston looks like!

    12. Re:Barred for 20 years? by yahwotqa · · Score: 1

      Wow, iphone users now brag that their beloved iphone doesn't have horrible flaws? Geez, talk about low standards.

    13. Re:Barred for 20 years? by twoshortplanks · · Score: 2, Funny

      I have no idea what Jennifer Aniston looks like!

      She's got a certain flair.

      --
      -- Sorry, I can't think of anything funny to say here.
    14. Re:Barred for 20 years? by Anonymous Coward · · Score: 0

      And a red stapler?

    15. Re:Barred for 20 years? by CarpetShark · · Score: 1

      We're talking about Twitter...a 20 years barring is permanent.

      I think GP's point was more that misleading people should NEVER be allowed, by ANY business.

  3. WTF? by Anonymous Coward · · Score: 5, Funny

    Under the terms of the settlement, Twitter will be barred for 20 years from misleading consumers about the extent to which it maintains and protects the security, privacy, and confidentiality of nonpublic consumer information

    Well, gee, I'm glad they'll be able to resume misleading consumers in 2030.

    1. Re:WTF? by sakdoctor · · Score: 1

      They'll get time off for good behaviour.

    2. Re:WTF? by MrShaggy · · Score: 1

      'I recently broke a mirror. I got stuck with 7 years of bad luck. But my Lawyer feels that He can get it down to 3.'

      --Steven Wright

      --
      I have mod points and I am not afraid to use them.
    3. Re:WTF? by adiemus · · Score: 5, Informative
      --
      "Wherever you go, there you are."
    4. Re:WTF? by FlyMysticalDJ · · Score: 2, Insightful

      So the punishment from misleading consumers is a ban on misleading consumers. Does that mean if they mislead consumers again they get another ban? Or would they actually get a real punishment.

      To employ Godwin's law: Hitler, we have all gotten together and we agree... No more Holocausts for 10 years, okay? Thanks Adolf.

    5. Re:WTF? by Anonymous Coward · · Score: 1, Informative

      just to add a snippet from that (for those too lazy to click):

      It may sound silly to bar Twitter from “misleading consumers” for 20 years, but that is essentially the life of the order and gives the FTC the ability to fine Twitter for future security breaches to the tune of $16,000 per incident. Without this order and the settlement, the FTC does not have what is known as civil penalty authority.

  4. The hell? by Anonymous Coward · · Score: 0

    Someone please tell me that this is a bad summary: "Under the terms of the settlement, Twitter will be barred for 20 years from misleading consumers."

    So as punishment, they have to avoid lying to customers. Only for 20 years, though, so it's fine again in 2031.

    1. Re:The hell? by Toonol · · Score: 4, Insightful

      Fortunately, there is absolutely zero chance that twitter will be a relevant company or technology twenty years from now.

    2. Re:The hell? by fuzzyfuzzyfungus · · Score: 4, Funny

      Corporations have feelings and a whole crop of shareholders at home, needing to be fed. It would be inhumane to punish them as harshly as those degenerate potheads and copyright infringers.

  5. Why Twitter? by Psx29 · · Score: 5, Insightful

    Twitter doesn't seem to hide the fact that pretty much everything you do on the site is public. Why don't they go after facebook for deceiving people and constantly changing their privacy policy?

  6. FACEBOOK by GrumblyStuff · · Score: 3, Insightful

    I was just about comment about how they should be hounding Facebook for all shit they pull.

    Constantly changing options and putting them by default onto the most open setting? That's maliciously hoping that people are either too lazy or stupid to change them back.

    Hiding the delete option for FB accounts and implementing it in such a fucking retarded way, forcing the account holders to search out and delete every comment, photo, tag, and other info they put in instead of just having a delete button? Utter bullshit.

    1. Re:FACEBOOK by Locke2005 · · Score: 3, Informative

      Hiding the delete option for FB accounts and implementing it in such a fucking retarded way, forcing the account holders to search out and delete every comment, photo, tag, and other info they put in instead of just having a delete button? Utter bullshit. You've obviously never tried to terminate an AOL account. Most ex-AOLers decided it was easier to just cancel their credit card.

      --
      I've abandoned my search for truth; now I'm just looking for some useful delusions.
    2. Re:FACEBOOK by fuzzyfuzzyfungus · · Score: 2, Funny

      I can only assume that Facebook will be effectively immune from prosecution for anything short of building its own nuclear arsenal, just as soon as the old judges and politicians die off, and are replaced by ones whose law school years are documented on Zuckerberg's giant voyeurism datastore...

    3. Re:FACEBOOK by Ethanol-fueled · · Score: 1

      I can only assume that Facebook will be effectively immune from prosecution

      More seriously, Facebook will be immune for the same reasons that AT&T and the other big telecoms already are...

    4. Re:FACEBOOK by Anonymous Coward · · Score: 0

      Thats what I did.

    5. Re:FACEBOOK by Anonymous Coward · · Score: 0

      Yah our social networks are *exactly* what the counter-terrorism data scanners are salivating over at this very minute.

  7. Huh? by Anonymous Coward · · Score: 0

    ...including the measures it takes to prevent authorized access to information...

    So they only have to prevent authorized access? That seems silly. Boy, if I prevented authorized access at work and only allowed unauthorized access I think I would be fired pretty quickly.

    1. Re:Huh? by Locke2005 · · Score: 1

      That reminds of the message all computers at Intel used to boot up with: "Unauthorized use of this computer is strictly prohibited". Always seemed a bit circular to me, kinda like saying "Unauthorized use is strictly unauthorized!"

      --
      I've abandoned my search for truth; now I'm just looking for some useful delusions.
  8. Kinda like consecutive life sentences... by Locke2005 · · Score: 3, Interesting

    Barred for 20 years? Reviewed after 10 years? Twitter is a fad that will be passé by 2012... what the hell makes them think Twitter will still exist as a viable company in 20 years?!?

    --
    I've abandoned my search for truth; now I'm just looking for some useful delusions.
    1. Re:Kinda like consecutive life sentences... by dgatwood · · Score: 4, Interesting

      They don't, and they don't care. This is just a further example of the way in which corporate personhood results in a fundamentally broken and inequitable legal system.

      When a corporation misappropriates the secrets of hundreds of thousands of users, they get told the equivalent of "We know you stole a hundred thousand VCRs, but we're going to let you off with probation. We'll check back on you in a year, and we'd better not see a bunch of stolen VCRs when we do. But if we do, we'll check back in another year. Oh, and your punishment is that you're not allowed to steal VCRs again for twenty years."

      By contrast, if an individual steals just a couple of secrets from one corporation and leaks them to the press, the police raid the person's house and confiscate the person's equipment, and the person spends time in jail and usually ends up not being able to use the Internet for 20 years.

      All I ask is for the same punishment to apply to Twitter. Is that really so much to ask? Shouldn't corporations' privacy violations be punished just as severely as an individual committing a hundred thousand acts of corporate espionage? Seems pretty straightforward to me.

      --

      Check out my sci-fi/humor trilogy at PatriotsBooks.

    2. Re:Kinda like consecutive life sentences... by Locke2005 · · Score: 3, Informative

      I'd think you were being paranoid, but the Supreme Court today gutted the "honest services" law: "All nine justices agreed that public officials and corporate executives cannot be convicted of defrauding the public unless they enriched themselves by taking a bribe or a kickback. Secret deals or conflicts of interest are not a crime unless they involve a direct payoff." So, as long as they are committing fraud to enrich the company, which then is more profitable and pays them more money, and not taking the money directly themselves, it's ok?!? WTF?!? Sounds like all that matters is the interests of the shareholders, and the customers are irrelevant.

      --
      I've abandoned my search for truth; now I'm just looking for some useful delusions.
    3. Re:Kinda like consecutive life sentences... by Anonymous Coward · · Score: 0

      Sounds like all that matters is the interests of the shareholders, and the customers are irrelevant.Actually, the law was using against Skilling for deceiving shareholders. Sadly, in the eyes of the court it seems the law is vague, because no one knows what the definition of honest is anymore. I know many people who thing intentionally deceiving someone isn't lying or even wrong as long as what you say is literally true.

  9. For twenty years? by Bing+Tsher+E · · Score: 1

    So Twitter is barred for twenty years from misleading customers, after which.... ?

    1. Re:For twenty years? by nacturation · · Score: 1

      So Twitter is barred for twenty years from misleading customers, after which.... ?

      After which someone can register the expired domain name and get all nostalgic about how people got so worked up over such a stupid concept.

      --
      Want to improve your Karma? Instead of "Post Anonymously", try the "Post Humously" option.
  10. Twitter will be barred for 20 years from misleadin by frovingslosh · · Score: 0, Redundant

    Twitter will be barred for 20 years from misleading consumers

    What kind of a deal is that? It seems to be saying that after the twenty year period it will be OK for them to mislead customers. And if it is not saying that, then what is the point of the 20 years or the deal in the first place? How does a company that betrays public trust get away with saying "OK, for our punishment we agree to follow the law for a limited period of time" ???

    --
    I'm an American. I love this country and the freedoms that we used to have.
  11. This doesn't make sense by mysidia · · Score: 5, Insightful

    The FTC’s complaint against Twitter charges that serious lapses in the company’s data security allowed hackers to obtain administrative control of Twitter,

    The privacy policy posted on Twitter’s website stated that “Twitter is very concerned about safeguarding the confidentiality of your personally identifiable information. We employ administrative, physical, and electronic measures designed to protect your information from unauthorized access.”

    Does NOT seem to be a misrepresentation. If they employ any measures at all.

    it failed to take reasonable steps to prevent unauthorized administrative control of its system, including:

    The FTC's ideas of what "reasonable steps" are sure does make me laugh... I am sure as hell glad the FTC's job is NOT to dictate proper IT security policies. They are clearly carrying around some pretty whacky notions of what security measures are basic and reasonable.

    Requiring employees to use hard-to-guess administrative passwords that are not used for other programs, websites, or networks

    Wait. "Hard to guess" and "Not used for other programs" are separate criteria.

    It is not necessary to require that last bit, to have strong security against intruders. It is not reasonable to expect that users of a computer network memorize a separate strong password for each service, change it frequently. The whole notion of "strong password" is a direct contradiction of "remembered (but not written) password". Any password that is not weak, by current security standards, is not able to be memorized by a human.

    Enforcing periodic changes of administrative passwords by, for example, setting them to expire every 90 days

    It is well demonstrated that this does not improve security. Instead, it encourages people to choose weaker passwords, or write them down. Password expiration only helps if an account has been compromised, but (for some reason) the hacker has not used the password yet.

    The likelihood of this is slim, the security improvement is practically ZERO, and the cost is very high.

    Prohibiting employees from storing administrative passwords in plain text within their personal e-mail accounts

    It is not necessary to 'prohibit employees from storing admin passwords in plain text'. To have security

    Your admins must know better. Chances are your company doesn't have a specific policy that says "Admins may not write their passwords on giant signs and carry them down the hall. At a certain point, it's just ridiculous (and doesn't improve security) to say "But you didn't prohibit X?!"

    Suspending or disabling administrative passwords after a reasonable number of unsuccessful login attempts

    This does not improve security. Actually, it increases the chance that an administrative account could be disabled by an attacker, making it more difficult to determine the nature of or respond to an ongoing attack.

    A strong password will be secure, even in the face of a brute force attack. A brute force attack can be mitigated using less disruptive techniques, such as automatically banning any IP address for 10 minutes, if a certain number of failed logins are attempted.

    Providing an administrative login webpage that is made known only to authorized persons and is separate from the login page for users

    This is only more secure, if you assume that an administrative login is known, and compromised.

    An additional web page for admin logins just creates another potential point of exposure to attack, has to be secured separately from the main login page, and the result is likely a less overall secure system.

    Compromise of individual users' Twitter accounts leaks private information, just as badly as a compromise of an administrative login...

    Particularly if the use of administrative logins is monitored carefully, and a co

    1. Re:This doesn't make sense by Anonymous Coward · · Score: 0

      Wait a minute... Twitter's administrative interface through which one can gain full control over any Twitter account is protected solely by password? Really? Not the totally standard VPN connection secured by client-side certificate and username/password that every other company in existence uses?

      Speaking of which, why aren't the high-profile users who got "hacked" demanding a client-side certificate login option (or HTTPS OpenID login so they can have whatever security they want on an OpenID server)? Seriously, you can have real security on the internet if you care. Why does no one bother? Why the heck is "account hacking" at all acceptable for high-profile accounts? (An actual vulnerability in the server or taking control of a client computer which at some point in time may log into the admin interface is one thing, what is being described as "hacking" is just ridiculous.)

    2. Re:This doesn't make sense by sgt101 · · Score: 3, Interesting

      The statement "any password that is easy to memorize is not strong" is not true.

      The best way to create a strong easy to remember password is via a phrase.

      Iwearcoolshoes!638
      dobbinisanicehorse.112
      ponyslikejonty6eatcarrots?

      With respect to administrative controls, it is very easy to segment control and access in a system. I run a social media monitoring service, we have 3 basic types of user (Admin, Coordinator, Agent) but each one can have up to 30 options that define the precise controls and access they have. I am amazed that Twitter have not implemented a similar system.

      If my team (3 guys) can implement this, anyone can. It is reasonable to expect. In fact it's totally sensible.

      Compromise of individual accounts does not leak information as badly as administration - there is a host of stuff an admin could do that an individual couldn't.

      With respect to limiting access by IP address, again you are talking complete nonsense. It is feasible to do this on a whitelist that would enable access from anywhere, but would require an email or a phone call to set up. Hardly difficult, and again, why not segregate the machines to enable moderation (fAor example) from a browser or using ssh but locking the database away somewhere where no one can get to?
      Actually I agree that ssh is functionally strong enough to rely on - if that breaks all our games are up!

      --
      --------------------------------------------- "In the end, we're all just water and old stars."
    3. Re:This doesn't make sense by mysidia · · Score: 1

      Compromise of individual accounts does not leak information as badly as administration - there is a host of stuff an admin could do that an individual couldn't.

      Every action an admin can do should be logged. Excessively unusual admin activity should set off alerts -- there should be traps designed to quickly catch any admin abusing their access.

      With respect to limiting access by IP address, again you are talking complete nonsense. It is feasible to do this on a whitelist that would enable access from anywhere, but would require an email or a phone call to set up.

      Someone would have to answer that e-mail or phone call, it would be expensive, burdensome, and non-technical users would have difficulty communicating their IP address, which could change every 5 minutes or more often.

      You think sending an e-mail or phone call is the least bit difficult for an intruder who stole information from an insider in the past?

      Remember.. a compromise of Twitter relied on insider information, and access to admins' e-mail.

      The best way to create a strong easy to remember password is via a phrase.

      Those are not cryptographically strong passwords, in fact they are pretty weak. You might qualitatively think of those phrases as strong, but the entropy is low. Phrase-based passwords such as those are able to be guessed with an extended dictionary attack.

      With respect to administrative controls, it is very easy to segment control and access in a system.

      No.. it's possible to segment and control. It is not easy to segment and control, without impeding people's ability to do their job.

      I run a social media monitoring service, we have 3 basic types of user (Admin, Coordinator, Agent) but each one can have up to 30 options that define the precise controls and access they have. I am amazed that Twitter have not implemented a similar system.

      If my team (3 guys) can implement this, anyone can. It is reasonable to expect. In fact it's totally sensible.

      It is also not what the FTC wants them to do.

      A system with 3 levels of access does not ensure every person has access to only the administrative functions they need, it does not satisfy the FTC's requirement.

      The FTC is basically dictating a military-style security bureaucracy.

      This goes beyond what access people have when they log into the website. And includes things like... the DBA must not have access to the data, they don't need that.

      They are essentially mandating that Twitter would have to encrypt every piece of data, and make sure the server admins cannot have access

      That's fine for a bank, or other institution. But Twitter is a social networking website, basically all the personal details they store are public.

      They really only have three pieces of information to keep private: (1) Passwords, (2) Private Tweets, and (3) E-mail addresses.

      It is not reasonable that such a company have a huge security budget, and spend 90% of their development efforts on security.

      And they have enough scalability issues without introducing ACL and Policy-Fu into all their web sites and backend systems.

    4. Re:This doesn't make sense by Anonymous Coward · · Score: 0

      Requiring employees to use hard-to-guess administrative passwords that are not used for other programs, websites, or networks

      Wait. "Hard to guess" and "Not used for other programs" are separate criteria.

      It is not necessary to require that last bit, to have strong security against intruders.

      This is exactly how Twitter itself got broken into, by their administrators reusing passwords across websites. This is a solved problem — tools like 1Password for Mac generate unique, strong passwords for every website, and let you log in only having to remember one strong password for your local machine.

  12. Ummm... excuse me.... by Petersko · · Score: 0, Redundant

    "Under the terms of the settlement, Twitter will be barred for 20 years from misleading consumers about the extent to which it maintains and protects the security, privacy, and confidentiality of nonpublic consumer information, including the measures it takes to prevent authorized access to information and honor the privacy choices made by consumers."

    So in 20 years they'll again be permitted to mislead consumers?

    I think I need to RTFA. That can't be right.

  13. barred for 20 years from misleading?? by nurb432 · · Score: 1

    Twitter will be barred for 20 years from misleading consumers

    Ummm shouldn't that be a given? Why only 20 years? Why is it even in question?

    --
    ---- Booth was a patriot ----
  14. Comment removed by account_deleted · · Score: 5, Funny

    Comment removed based on user account deletion

  15. Re:Twitter will be barred for 20 years from mislea by Anonymous Coward · · Score: 0

    Maybe it is something like the punishment they should have received for this will be visited upon them if they are found to mislead customers again in the future, in addition to whatever punishment they get for that crime? Seems odd to me, but IANAL for just that reason.

  16. Legal Stuffs by bv728 · · Score: 5, Informative

    IANALBIFWI, "Twitter will be barred for 20 years ..." does NOT mean that twenty years from now they have the right to mislead. It means that if the Government finds out they're misleading within the next 20 years it does not need to have a trial to take action - they can just slam them as violating the existing ruling. This is, functionally, a suspended sentence (thus third party review of their new security measures).

    1. Re:Legal Stuffs by Genocaust · · Score: 2, Insightful

      IANALBIFWI

      ...What did you call my mother?

      --
      It could be that the only purpose of your life is to serve as a warning to others.
    2. Re:Legal Stuffs by Anonymous Coward · · Score: 0

      What does IANALBIFWI mean? A search on Google revreals only this post.

  17. Re:Twitter will be barred for 20 years from mislea by fyrewulff · · Score: 3, Informative

    It's legal language. They aren't saying they were permitted before or permitted afterwards. They're saying that Twitter is basically on probation for the next 20 years, and now if they do it again the FTC can fine them since they've now warned them.

    It'd be like say (ignore all other laws for a moment), a store advertising 20$ iPhones and they're 400$ when you get in the store. They would be told that they can't mislead customers for another 20 years, or else face heavy fines.

    --
    "We need to get over this notion, that, for Apple to win... Microsoft must lose." - Steve Jobs, 1997
  18. As you read this article (and others) by QuietLagoon · · Score: 1

    you need to be aware that the business interests behind Twitter, Facebook, et al, are playing with the public perception of their "services". Be concerned. Be aware.

  19. authorized access by Anonymous Coward · · Score: 0

    Trying to prevent all authorized access has worked wonders for the mpaa members

  20. Privacy at risk by Capt_Idle · · Score: 2, Funny

    Dang, i should have known. The signs were there. My co-workers often knew word-by-word what i published on twitter.

  21. Misleading by helix2301 · · Score: 0

    Shouldn't a big company like Twitter not mislead there customers what kind of company purposely misleads there customers. Twitter is a cool service but I think this is a slap on the wrist to them.

  22. Unlike the majority of companies in IT... by ghee22 · · Score: 1

    Does this mean they are hiring?

    --
    "Persistence is annoying success." - ghee22 11:28:1999 - 10:53:PM
    1. Re:Unlike the majority of companies in IT... by bsDaemon · · Score: 1

      Yeah, but they're only paying in PBR and black-framed Buddy Holly glasses.

  23. Re:Twitter will be barred for 20 years from mislea by CarpetShark · · Score: 1

    It seems to be saying that after the twenty year period it will be OK for them to mislead customers.

    It's legal language.

    I think it's misleading language.