TMCnet Feature Free eNews Subscription
April 26, 2013

Be Prepared, Hackers Here to Stay

By Ed Silverstein, TMCnet Contributor

Hackers like the Syrian Electronic Army are likely here to stay – so their victims need to be prepared. Earlier this week, a Twitter account used by The Associated Press (News - Alert) apparently was taken over by the group.

Before the account was shut down, it was able to send out a fake Tweet that two explosions took place in the White House and that President Barack Obama was injured, TechZone360 reported.  In response, the Dow Industrial Average lost over 100 points but soon rebounded.

The Syrian Electronic Army claimed responsibility for the attack. The group has also attacked CBS, the BBC and Al Jazeera.

Jillian York, director of International Freedom of Expression at the Electronic Frontier Foundation, told The World this week that the Syrian Electronic Army is a “pro-Syrian government organization, possibly funded by the Syrian government.” Also, it is supported by Syrian President Bashar al-Assad, but may involve hackers from different parts of the world.

“This is the only group registered as a government network and has a clear affiliation with the Syrian government,” York added.

The hacking attack against The AP provides an important lesson: “You can't run a business or a country if you can't differentiate between known, trusted visitors and a hacker using stolen credentials,” Alisdair Faulkner, chief products officer of ThreatMetrix, told TMCnet in a statement on Thursday. “Unfortunately, user account takeover attacks are the new spam in terms of its prevalence and automation, but with a much more explosive impact on commerce, privacy and national security.”

He says that in the last six months alone, the ThreatMetrix Cybercrime Index has shown that account hijack attacks have increased 180 percent across the over 10,000 websites included in the firm’s Global Trust Intelligence Network.

“If the traditional security players are going to remain relevant in this new environment, they will need to stop milking their anti-virus and firewall cash cows and actually invest in enabling trusted commerce in a real way,” Faulkner said. “Otherwise, people will just unplug.” 

Michael Hussey, CEO of PeekAnalytics, said that operators of any account need to protect their login credentials.

“Companies also need to teach their employees how to detect phishing scams,” Hussey added in a statement Friday to TMCnet. “Corporate networks can be setup to reduce the odds of being targeted by malicious phishers and hackers.”

In addition, there still is not an “official standard” when it comes to protecting consumers and businesses from phishing attacks.

One option may be that e-mail services provide users “sender authentication” and keep an approved list of Twitter (News - Alert) servers, Hussey said.

For its part, Twitter could require authentication from computers, laptops and smartphones that are not recognized “as a normal machine from which a user typically logs in,” Hussey added. “Lots of banks do this.”

In retrospect, some industry watchers have recommended that The AP should have had two-factor authentication for its Twitter account.

“While two-factor authentication is a powerful tool for securing user accounts, it cannot solve all problems,” responded PC Magazine. “Having two-factor would not have helped @AP because the hackers broke in via a phishing attack. Adversaries would just find another way to trick users into bypassing the security layer,” said Aaron Higbee, CTO of PhishMe.




Edited by Alisen Downey
» More TMCnet Feature Articles
Get stories like this delivered straight to your inbox. [Free eNews Subscription]
SHARE THIS ARTICLE

LATEST TMCNET ARTICLES

» More TMCnet Feature Articles