It wasn't so long ago – around a week, actually – that a Twitter (News - Alert) post appeared suggesting that multiple explosions had hit the White House, and that President Obama had been injured in the attacks. Retweets flew fast and furious, the stock market took a quick nose dive, and when it was all discovered to be a hoax, the world began to take stock.
Twitter, for its part, began to issue direction on how to protect Twitter accounts from unauthorized entry, and to that end, recently released a memo about how journalists and other account holders can better protect accounts.
While some of Twitter's advice might prove a bit cumbersome – for instance, designating one computer for Twitter traffic and only for Twitter traffic so as to reduce the chance of getting hit by malware infections – some of the information provided is much easier to follow. For instance, Twitter advises regular password changes, observing proper security in e-mail accounts, maintaining a watch for security threats like the growing use of "spear phishing" tactics and the like.
A popular approach Twitter suggests is the use of either randomly-generated passwords with a variety of characters, or the use of a string of words that may be familiar or easy to remember. Several sites exist around the Web allowing users to check some measures of strength for particular passwords, though not everyone agrees on the value of these measures. Some even suggest that nearly any password of 14 characters or more is inherently secure due to the amount of time required to break a password that long.
Some see Twitter's advice about a specific Twitter computer, however, as a sign of increasing desperation. Twitter is already hard at work on a two-factor authentication system that should take care of many of the issues surrounding Twitter hacking, but it seems like Twitter is demanding some almost ludicrous countermeasures.
It's clear that the stakes are high here. When one tweet about an explosion at the White House – hoax or otherwise – can cause a direct impact in the stock market, it's obvious that there's a lot of power involved in social media. Whether it's two-factor authentication, particularly strong passwords, limited numbers of users, or even a limited-contact environment for the computer that uses social media, some kind of protection measures need to be undertaken, especially for those with large numbers of social followers.
Twitter's moves to help protect users from hackers may seem a little too stringent to some, but there's a clear need for this kind of protection to be put in play, lest a more elaborate hoax get out and do much greater damage. IT professionals looking to step up their own security measures, and ensure that company information and communications are safe from hacking attempts like those on Twitter, can attend SecureIT 2013 in New York this July.