Twitter Hack Prompts Two-Factor Authentication To Strengthen Security

By Alexandra Burlacu email: a.burlacu@mobilenapps.com | Feb 05, 2013 08:53 AM EST

Share This Story

  • Print
  • Email

Following the recent hack that compromised up to 250,000 Twitter accounts, the micro-blogging site is now pursuing two-factor authentication to enhance log-on security.

Follow us

Twitter has 250 million users, meaning the breach affected only 0.10 percent of its entire user base, but any hack attack is still a serious security issue regardless of its proportions. Twitter reset the passwords of all affected users, but said investigation remains ongoing until everything is clear, including determining exactly what data the hackers accessed.

"This week, we detected unusual access patterns that led to us identifying unauthorized access attempts to Twitter user data," Twitter's director of information security Bob Lord announced in a blog post on Friday, Feb. 1. "We discovered one live attack and were able to shut it down in process moments later. However, our investigation has thus far indicated that the attackers may have had access to limited user information - usernames, email addresses, session tokens and encrypted/salted versions of passwords - for approximately 250,000 users."

Twitter has reset the passwords for those 250,000 affected users and revoked those accounts' session tokens as a precautionary measure. According to Lord, users should have received an e-mail instructing them to create a new password.

Lord further cautioned users to pay attention to the warnings the Department of Homeland Security has issued recently regarding the Java browser plug-in. He did not, however, specifically associate the Twitter breach to a Java vulnerability exploit.

In light of the security breach, Twitter officials have apparently decided to implement two-factor authentication. A new job listing on Twitter's Web site reveals the new security measure. The job is for a software engineer - product security.

"Design and develop user-facing security features, such as multifactor authentication and fraudulent login detection," read the requirements in the job advert.

Twitter moved to HTTPS as the default option in March 2012, but two-factor authentication would add an extra layer of security to Twitter's log-in process. Google, for instance, has been offering two-factor authentication for a long time for its Gmail and other Google Apps. Dropbox has also implemented this extra security measure after facing a password breach of its own.

Users who have enabled two-factor authentication, both for Google and Dropbox, must enter both their passwords and a unique code - the second factor - generated either by an app on their smartphone or sent to their handset via SMS. Facebook has such a system in place as well.

Until it adopts such a system, all Twitter can do if it detects a breach is to reset those passwords, as it has done now. Some affected users, however, have reported that their presumably expired passwords still work when they log into Twitter via the Twitter API.

Get the Most Popular Mobile&Apps Stories in a Weekly Newsletter

© 2013 Mobile & Apps All rights reserved. Do not reproduce without permission.

Join Our Conversation

Smartphones
Google Nexus 4 White VersionWhite Nexus 4 To Launch On June 10 Rocking Latest Android 4.3
Galaxy S4 Best Selling Samsung Smartphone Of All Time?
Android 4.2.2 Jelly Bean Coming Soon For HTC One; Google Edition of HTC One On The Way
Android 4.1.2 Jelly Bean Official Firmware Update For Samsung Galaxy S3 I9300 Via XXEMD2 [How To Install]
Tablet / Laptop / PC
MacBook AirNew MacBook Air To Debut In June With Intel's New Haswell Processor?
Nexus 7 Refresh Teased In Google+ Hangouts Video, Sports Glowing Notification Light
AMD Unleashes Radeon 8900M Mobile GPU: Get It In MSI GX70 Gaming Laptop
Dell XPS 10 Drops Price To $300, Marking A New Low For Windows RT
Gadgets
Xbox Release Event InviteNext Microsoft Xbox To Sport Dashboard UI Update And Tile Changes
Google Media Streamer Hits FCC To Replace Nexus Q
Google Glass Raises Lawmakers' Concerns: Congress Demands Answers About Privacy
Seven New Apps Coming To Google Glass: Facebook, Twitter, And Evernote Included
OS / Software
HTC OneAndroid 4.2.2 Jelly Bean Coming Soon For HTC One; Google Edition of HTC One On The Way
Android 4.1.2 Jelly Bean Official Firmware Update For Samsung Galaxy S3 I9300 Via XXEMD2 [How To Install]
Windows Phone Took Third Spot From BlackBerry In Latest Worldwide Market Share Report
Sprint Releases Software Update For HTC One: Key Sensitivity Issues To Be Fixed
Internet / Social Media
The Yahoo logYahoo Is Eyeing Tumblr
Google I/O 2013: Chrome Web Browser Now Has 750 Million Active Users
Google I/O 2013: Google Maps Gets New UI And Google+ Hangouts Shows Massive Improvements
Gtalk Chat Integration Coming To Outlook.com
What's App
Intellicam Windows Phone 8Intellicam App Brings First Hands-Free Camera Feature To Windows Phone 8
Seven New Apps Coming To Google Glass: Facebook, Twitter, And Evernote Included
Itsdagram Available Now For Windows Phone: Best Instagram Client Around
Google I/O 2013: Chrome Web Browser Now Has 750 Million Active Users

DON'T MISS

Galaxy S4 White Frost
Verizon Samsung Galaxy S4 To Come On May 23
According to an update on Verizon's news page, the Galaxy S4 will now be available in Verizon
Galaxy S4 Google Edition
Samsung Galaxy S4 Google Edition Launched: Rumors Say It's Nexus 5
The new edition of the Galaxy S4 is being seen as an alternative to the Nexus smartphones as the
RIM BlackBerry 10
BlackBerry Live: 120,000 Apps in BlackBerry World, Gaining on Windows Phone
The numbers are in, and it appears BlackBerry World might walk over Windows Phone sooner or later.
Windows Blue
Windows 'Blue' Will Come As Free Update For Windows 8, Windows RT Users
Despite previous rumors, Windows 8.1 dubbed Windows 'Blue' will be available as a free update to
LG Google TV
Android 4.2.2 Jelly Bean, Chrome Update For Google TV: End Of Flash?
The Google TV has now be 'refactored' so the OEMs of the device can update their settop boxes to
Samsung Galaxy S4 'Blue Arctic'
Samsung Galaxy S4 Blue Arctic Gets Official On Docomo Network
Samsung Galaxy S4 Blue Arctic is real but it is not yet clear whether the handset is exclusively

Galaxy S4 White Frost
Samsung To Look Into 16GB Galaxy S4 Storage Woes, 'Software Optimization' Might Free More Space
Samsung has finally responded to storage woes concerning the 16GB Samsung Galaxy S4 and said it may
Samsung Galaxy S4 Mini 'Leaked' Image
Samsung Galaxy S4 Mini Spotted In Leaked Images Once Again
In the latest series of leaked pictures, the Galaxy S4 mini is shown from every possible angle and
Google Maps
Google I/O 2013: Google Maps Gets New UI And Google+ Hangouts Shows Massive Improvements
Fans of Google products will love the new look of Google Maps and Google+ Hangouts.
MSI GX70
AMD Unleashes Radeon 8900M Mobile GPU: Get It In MSI GX70 Gaming Laptop
Do you enjoy gaming on a laptop? The AMD Radeon 8900M might excite you along with the MSI GX70.
Copyright © 2013 Mobile & Apps All rights reserved. mobilenapps
Real Time Analytics