<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Practical Issues in InfoSec &#187; twitter</title>
	<atom:link href="http://www.dlstrom.com/tag/twitter/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dlstrom.com</link>
	<description>... putting information security within reach of everyone!</description>
	<lastBuildDate>Tue, 20 Dec 2011 17:00:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>3 Lessons from the Twitter DDoS</title>
		<link>http://www.dlstrom.com/2009/08/06/3-lessons-from-the-twitter-ddos/</link>
		<comments>http://www.dlstrom.com/2009/08/06/3-lessons-from-the-twitter-ddos/#comments</comments>
		<pubDate>Fri, 07 Aug 2009 01:24:23 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[CyberSecurity]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[FaceBook]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=274</guid>
		<description><![CDATA[By now we&#8217;ve all heard that Twitter was offline for a couple of hours today, and that FaceBook was running slowly. The reports are that they both were victims of a Distributed Denial of Service (DDoS) attack. While this was limited to sites that, admittedly, have little measurable business value, what if it was a [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2009/08/06/3-lessons-from-the-twitter-ddos/" data-text="3 Lessons from the Twitter DDoS" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2009/08/06/3-lessons-from-the-twitter-ddos/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>By now we&#8217;ve all heard that Twitter was offline for a couple of hours today, and that FaceBook was running slowly. The reports are that they both were victims of a Distributed Denial of Service (DDoS) attack.</p>
<p>While this was limited to sites that, admittedly, have little measurable business value, what if it was a business-critical site that was knocked off-line?</p>
<p>Now, stay with me while we take a bit of a leap&#8230;</p>
<p>Many small businesses and individuals are moving to &#8220;cloud computing&#8221;. Working documents are in the &#8220;cloud&#8221;. Software as a Service (SaaS) is finally starting to take off.</p>
<p>Now, if the &#8220;cloud&#8221; and SaaS provider that you are using are being hit with a DDoS, what plans do you have for your business?</p>
<p>Lessons for the small business&#8230;</p>
<ol>
<li>
Know the risks associated with your technological model &#8211; in this case  &#8220;cloud&#8221; vs local.</li>
<li>
Make your DRP/BCP include plans in the event your providers are unavailable.</li>
<li>
Finally, know what response you will have if your providers never return.</li>
</ol>
<p>Here&#8217;s hoping you have a weekend full of availability!</p>
<p>- Dan</p>
<p>UPDATE: The reports now are that many more sites were affected as a result of <a href="http://news.cnet.com/8301-27080_3-10305200-245.html">targeting ONE user</a> (from cnet.com) !</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2009/08/06/3-lessons-from-the-twitter-ddos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec Tip: Keep Personal Separate From Work</title>
		<link>http://www.dlstrom.com/2009/07/17/infosec-tip-keep-personal-separate-from-work/</link>
		<comments>http://www.dlstrom.com/2009/07/17/infosec-tip-keep-personal-separate-from-work/#comments</comments>
		<pubDate>Fri, 17 Jul 2009 13:00:00 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[Awareness]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=264</guid>
		<description><![CDATA[Twitter hacked by old technique — again by AP: Yahoo! Tech This article came out yesterday. The short description is that a compromised personal email account led to a compromise at Twitter. Although the article is written with the focus on Twitter, this can just as easily happen to you and your organization. Tip: Keep [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2009/07/17/infosec-tip-keep-personal-separate-from-work/" data-text="InfoSec Tip: Keep Personal Separate From Work" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2009/07/17/infosec-tip-keep-personal-separate-from-work/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p><a href="http://tech.yahoo.com/news/ap/20090716/ap_on_hi_te/us_tec_twitter_hacked">Twitter hacked by old technique — again by  AP: Yahoo! Tech</a></p>
<p>This article came out yesterday. The short description is that a compromised personal email account led to a compromise at Twitter. </p>
<p>Although the article is written with the focus on Twitter, this can just as easily happen to you and your organization.</p>
<p><strong>Tip: Keep work email and data separate from personal email and data.</strong></p>
<p>We need to constantly remind folks that there needs to be separation between work and personal email and storage. The selling point is that it protects both the employee and the company in the event the other is compromised.</p>
<p>Once again, the weakest link is The Human.</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2009/07/17/infosec-tip-keep-personal-separate-from-work/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>15 Thoughts on Twitter</title>
		<link>http://www.dlstrom.com/2009/05/28/15-thoughts-on-twitter/</link>
		<comments>http://www.dlstrom.com/2009/05/28/15-thoughts-on-twitter/#comments</comments>
		<pubDate>Thu, 28 May 2009 20:35:06 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[Awareness]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=238</guid>
		<description><![CDATA[Tweet This! Have you seen this on a website? Twitter is often called a microblogging platform. I suppose it is. But, it also can be thought of as broadcast SMS (short message service). It&#8217;s kind of like text messaging on your cell phone. I&#8217;ve been asked my opinion of using Twitter. What follows is a [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2009/05/28/15-thoughts-on-twitter/" data-text="15 Thoughts on Twitter" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2009/05/28/15-thoughts-on-twitter/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>Tweet This!</p>
<p>Have you seen this on a website? </p>
<p>Twitter is often called a microblogging platform. I suppose it is. But, it also can be thought of as broadcast SMS (short message service). It&#8217;s kind of like text messaging on your cell phone.</p>
<p>I&#8217;ve been asked my opinion of using Twitter. What follows is a pseudo-random list of some of my thoughts. Not all of these are InfoSec related, but many of them are&#8230;</p>
<ol>
<li>
Don&#8217;t tweet things like, &#8220;I&#8217;m heading to the bathroom now&#8221;. Who really cares?</li>
<li>
Twitter helps to foster a false sense of intimacy with others. Just like Facebook, you can follow many people you don&#8217;t really know. But by following them you get an idea of who they are the things they do or care about. This is a false intimacy.</li>
<li>
Remember, everything you put on Twitter is searchable. The standard tweets are not private. Anyone can find what you tweet.</li>
<li>
Many of your followers are bots. Put some popular words in a post &#8211; try &#8220;Obama&#8221; or &#8220;democrat&#8221; or &#8220;Rush&#8221; &#8211; in a post and watch the new followers. Many of these will be bots, not real people.</li>
<li>
Don&#8217;t use your email address in a post. There are folks who have programs running that harvest these email addresses for the purpose of sending spam and phishing email.</li>
<li>
Be aware of the picture you are painting with your tweets. I follow some folks who tweet about where they are at the moment, talk about their kids and activities, mention where they work, etc. By filtering out only their posts, I can put together a pretty accurate picture of their lives and loved ones. Not good&#8230; especially if a Bad Guy is gathering info.</li>
<li>
If you hope to get your tweets re-tweeted, limit your tweet length to no more than 120 characters. This gives the re-tweeter room to add their own information.</li>
<li>
Watch out for link spam. Don&#8217;t click on every link you seen in tweets from people you don&#8217;t really know.</li>
<li>
Spend some time looking at current thoughts and trends on Twitter. Get an idea of how others are using it and why they are using it. If you want to use Twitter for your non-profit, research how other non-profits are using it. You will get some good ideas!</li>
<li>
Realize that by default, anyone can follow you. If you don&#8217;t want someone to follow, you can block them.</li>
<li>
Don&#8217;t share personally identifiable information &#8211; phone numbers, addresses, etc &#8211; in posts.</li>
<li>
Use &#8220;Protect my updates&#8221; on your Twitter account page if you don&#8217;t want your posts to be on the <a href="http://twitter.com/public_timeline">public timeline</a>.</li>
<li>
Understand that you will see inappropriate words and language as you view the public timeline, and also from many folks you choose to follow.</li>
<li>
There is a lot of noise. Your important broadcast message can get lost in the meaningless drivel. If expect someone to follow you for critical notifications, you need to keep in mind that if they follow more than just a few other folks, they will be swamped with tweets and most likely will miss your critical update.</li>
<li>
If including URL&#8217;s, use a URL shortening service, like <a href="http://www.bit.ly/">bit.ly</a>, to shorten the URL. Bit.ly also provides some capabilities for gathering metrics about each shortened URL and the number of clicks on it.</li>
</ol>
<p>And yes, I do Twitter. Here&#8217;s the <a href="http://twitter.com/DanStrom">link</a> to me.</p>
<p>- Dan</p>
<p><strong>Update</strong>: A friend suggested some other &#8220;use&#8221; types of thoughts that he would like to see on this list. Here they are&#8230;</p>
<ol>
<li>
Even though bots will follow, you need to remember that there are also real people. (This balances #4 above.)</li>
<li>
Twitter can be used to host real-time chats, often bringing together opposing views on a common topic. The Tuesday evening #agchat discussions are an example of this.</li>
<li>
The global search capabilities can be used to find like-minded people and foster on-line relationships.</li>
<li>
Creative uses for Twitter, and other social networks, are up to the users. Twitter is medium. The message is up to you.</li>
<li>
Finally, it is not unusual to have followers, or for you to follow, people with wildly divergent views. Use Twitter can be used to get your message out to folks who might not normally listen.</li>
</ol>
<p>Happy Twitter-ing!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2009/05/28/15-thoughts-on-twitter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interesting Read: Taking over the Torpig botnet</title>
		<link>http://www.dlstrom.com/2009/05/05/interesting-read-taking-over-the-torpig-botnet/</link>
		<comments>http://www.dlstrom.com/2009/05/05/interesting-read-taking-over-the-torpig-botnet/#comments</comments>
		<pubDate>Tue, 05 May 2009 16:09:24 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[CyberSecurity]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[torpig]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=215</guid>
		<description><![CDATA[If you are interested in a real-world botnet analysis, take a look at the work being done with Torpig at UC Santa Barbara. Taking over the Torpig botnet This botnet is used for the normal activities of harvesting sensitive information from computers that are controlled. Using Domain Flux, the botnet generates lists of servers for [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2009/05/05/interesting-read-taking-over-the-torpig-botnet/" data-text="Interesting Read: Taking over the Torpig botnet" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2009/05/05/interesting-read-taking-over-the-torpig-botnet/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>If you are interested in a real-world botnet analysis, take a look at the work being done with Torpig at UC Santa Barbara. </p>
<p><a href="http://www.cs.ucsb.edu/~seclab/projects/torpig/">Taking over the Torpig botnet</a></p>
<p>This botnet is used for the normal activities of harvesting sensitive information from computers that are controlled. Using Domain Flux, the botnet generates lists of servers for drive-by spreading by using information from Twitter trends. Pretty clever.</p>
<p>If you are interested in the details, be sure to download <a href="http://www.cs.ucsb.edu/~seclab/projects/torpig/torpig.pdf">The Report</a>.</p>
<p>Thanks to my bro, Steve for pointing this project out to me.</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2009/05/05/interesting-read-taking-over-the-torpig-botnet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

