teases: on • reblogs: on

ShortFormBlog

Read a little. Learn a lot. • Ask Us Stuff!FAQArchiveTimeline

Tagged: Twitter

Our best freaking stuff right now:

May 22, 2013
17:19 • 1 day ago
Good news for Burger King: After many months of people asking for it, Twitter finally offers two-step verification for its users. “Of course, even with this new security option turned on, it’s still important for you to use a strong password and follow the rest of our advice for keeping your account secure,” the company emphasizes.

Good news for Burger King: After many months of people asking for it, Twitter finally offers two-step verification for its users. “Of course, even with this new security option turned on, it’s still important for you to use a strong password and follow the rest of our advice for keeping your account secure,” the company emphasizes.

May 8, 2013
20:47 • 2 weeks ago
Here’s how The Onion’s Twitter account got hacked. How? Hint: That link doesn’t actually go where it says it does.

Here’s how The Onion’s Twitter account got hacked. How? Hint: That link doesn’t actually go where it says it does.

May 2, 2013
15:13 • 3 weeks ago
April 30, 2013
11:50 • 3 weeks ago
seldo asks: Your point about two-factor auth at Twitter is fair, but these large brands can already be using third-party tools like Hootsuite to give individuals access to major accounts in a much more controllable way, and using insanely long, private master passwords for the accounts themselves.

» SFB says: This is a fair point regarding my argument last night. (Though if you read Twitter’s recommendations, they seem skeptical of this as well. “Even if you use a third-party platform to avoid sharing the actual Twitter account password, each of these people is a possible avenue for phishing or other compromise,” they write.) It’s also a good work-around to Twitter’s lack of two-step, though, because you can log in via OAuth and Facebook Connect, allowing you to tie into Google and Facebook’s two-step logins. Not everyone is psyched to use such tools like HootSuite, but it’s certainly a reasonably good choice for large organizations. The fact of the matter is, we’re giving the same level of security to everyone that joins Twitter, and when you’re Twitter’s size, it doesn’t make sense. If they can’t pull it off for everyone all at once, two-step for verified accounts would be a great start. — Ernie @ SFB

April 29, 2013
21:57 • 3 weeks ago

woody:

Hey shortformblog, you’re mostly wrong. 

Because Twitter cannot prevent the type of attack which has caused so many brands to loose their twitter account - malware (specifically keyloggers) logs the users credentials when they log into twitter.com, which the attacker then uses to make a perfectly “legitimate” login at a later time. 

How do you prevent this as a user, given that its the #1 vector of attack for these big name brand hijackings? Use a computer that you know isn’t infected with MalWare. How do you ensure that a computer doesn’t have any malware? Never connect it to the internet (or if you do connect, only use twitter.com, and not browsing or emailing).

Does this make sense for the average user? Not at all. Does it make sense for a global brand or news agency who want to avoid what happened to AP? Easily. The $1200 hypothetical laptop is far cheaper than the damage to a brand from a high publicity hijacking. 

The reason that I say “mostly” is that twitter could prevent this by using Google Authenticator or some other form of two-factor authentication. This would be unneeded for a normal user, but would allow big brands to add the extra security. I suspect that Twitter is probably working on this right now, and that this announcement is just until it is deployed.

You realize these accounts are used by multiple users and organizations as large as AP use third-party apps, right? And that numerous people use that single account, right? And that social media pretty much only works because you can share links? This solution is not realistic. It’s a band-aid solution until Twitter gets its stuff together.

The problem here is that large brands have been asking for that two-factor solution for at least two years (Facebook launched it two years ago, and Google has had it for years), and now, Twitter is feeling some serious pain because they only hired someone to work on the two-factor thing within the past six months.

They can’t block such attacks because they haven’t built out their system to deal with them. 

If Twitter was serious about protecting its users, it would have been working on this solution before it got to this point, especially considering the seriousness of the problems being raised and the size of the brands it was courting. But instead, they’re playing catch-up. The best solution to bad security is being proactive.

The hypothetical dedicated laptop is not the problem. The fact that the hypothetical dedicated laptop was required in the first place is the problem.

21:01 • 3 weeks ago
Designate one computer to use for Twitter. Don’t use this computer to read email or surf the web, to reduce the chances of malware infection.
The advice Twitter is giving to media outlets to prevent hacks similar to the one that hit the AP last week. That’s right… Don’t use your $1200 computer for any other reason besides sending short messages to other people. Twitter did this to themselves by not working on the security issues two years ago.
Follow us on Facebook:
April 25, 2013
20:31 • 4 weeks ago

Annoyed with all the click-baiting on Huffington Post? @HuffPoSpoilers has got you covered. This is one of the more genuinely useful gimmick accounts we’ve come across; it’s been around since August but just seems to be gaining traction today (its follower count was around 1k this morning; now it’s over 5k). To their credit, the folks at Huffington Post are being good sports about it. source

April 11, 2013
10:08 • 1 month ago
Congratulations, Twitter. You finally figured out a way to silence HuffPo’s Twitter account. More info here. (BTW, if you use an old client, the links still work.)
EDIT: The links are working again on Twitter.

Congratulations, Twitter. You finally figured out a way to silence HuffPo’s Twitter account. More info here. (BTW, if you use an old client, the links still work.)

EDIT: The links are working again on Twitter.

April 7, 2013
13:06 • 1 month ago
Some fake accounts look even better than real accounts do.
Fake Twitter Followers Become Multimillion-Dollar Business - NYTimes.com (via thisistheverge)

However, most fake accounts look terrible. This article notes that The Next Web gets a lot of automatic retweets on their posts. Sounds about right.
March 20, 2013
14:28 • 2 months ago
Recent posts and stuff we dig:
March 4, 2013
19:24 • 2 months ago
Twitter users are considerably younger than the general public and more likely to be Democrats or lean toward the Democratic Party.
Pew Research Center • Discussing Twitter’s demographics compared to that of the general public—specifically noting that Twitter is not a microcosm of the general public and should not be treated as a source for public sentiment surveys. Clearly Pew has never searched the #TCOT tag on Twitter.
18:57 • 2 months ago
avrillavigneamvs240p: whats tweetdeck

» SFB says: Twitter for people who want to grow old really, really fast. — Ernie @ SFB

(Source: theverge.com)

18:52 • 2 months ago
thisistheverge:

Twitter discontinuing iPhone, Android, and desktop versions of TweetDeck

That sound you heard was the social media journalist in the other room smashing his head into his desk in the wake of this news. To be clear, “desktop” means Adobe AIR. The native clients still work.

thisistheverge:

Twitter discontinuing iPhone, Android, and desktop versions of TweetDeck

That sound you heard was the social media journalist in the other room smashing his head into his desk in the wake of this news. To be clear, “desktop” means Adobe AIR. The native clients still work.

February 12, 2013
10:12 • 3 months ago

Would you buy a product using a hashtag? Thanks to American Express, now you can do so.

More posts:

 

ShortFormBlog is the product of Ernie Smith, Seth Millstein, Chris Tognotti, Sami Main, Scott Craft, Matthew Keys, Julius the laid-off RSS robot, awesome links from awesome sources, a hacked version of Wordpress, Tumblr's Tumblarity, the letter Q, the number 13 and a series of tubes.

Copyright 2009-2013 Ernie SmithAsk us stuff!E-mail usFollow us on TwitterFollow us on Facebook

    TwitterCounter for @shortformblog   Real Time Web Analytics   Creative Commons License Real Time Web Analytics