<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Return On Now &#187; phishing</title>
	<atom:link href="http://returnonnow.com/tag/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://returnonnow.com</link>
	<description>White Hat / Ethical SEO, Social Media, Online Marketing</description>
	<lastBuildDate>Tue, 08 May 2012 15:59:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Twitter URL Shortener: Good Response to Phishing</title>
		<link>http://returnonnow.com/2010/03/twitter-url-shortener-good-response-phishing/</link>
		<comments>http://returnonnow.com/2010/03/twitter-url-shortener-good-response-phishing/#comments</comments>
		<pubDate>Mon, 15 Mar 2010 15:45:41 +0000</pubDate>
		<dc:creator>tpltx70</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[peter kafka]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[posterous]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[twt.tl]]></category>
		<category><![CDATA[wesley83]]></category>

		<guid isPermaLink="false">http://returnonnow.com/?p=307</guid>
		<description><![CDATA[The news sort of came out a bit under the radar, but Twitter announced a very interesting change they are implementing on their blog (March 9, 2010). Positioned as a response to phishing, they will be changing URLs in Direct Messages to their own twt.tl shortened redirects. Essentially, they can then track for bad behavior and block the URL altogether if the target web page  is found to be malicious. <a href="http://returnonnow.com/2010/03/twitter-url-shortener-good-response-phishing/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://Twitter.com" target="_blank"><img class="alignleft" style="border: 1px solid black; margin: 2px;" title="Twitter, social media" src="http://a1.twimg.com/a/1268437273/images/logo.png" alt="Twitter, social media" width="224" height="55" /></a>The news sort of came out a bit under the radar, but Twitter announced a very interesting change they are implementing on their blog (March 9, 2010). Positioned as a response to phishing, <a title="Twitter Blog" href="http://blog.twitter.com/2010/03/trust-and-safety.html" target="_blank">they will be changing URLs in Direct Messages to their own twt.tl shortened redirects</a>. Essentially, they can then track for bad behavior and block the URL altogether if the target web page  is found to be malicious.</p>
<p>I applaud them for taking some action to integrate the security layer within their own infrastructure, as it is clear that more users than we&#8217;d like to admit can be &#8220;<a title="Wikipedia: Social Engineering" href="http://en.wikipedia.org/wiki/Social_engineering_%28security%29" target="_blank">social engineered</a>&#8221; to click on almost anything. No other URL shortener service has shown an ability to build in the needed level of control, and who would be able to make this work better than Twitter itself?</p>
<p>The question remains open as to where they intend to take this newfound capability in the future. And sure, if it can be used for DMs, why not have it available for all messages.  This all comes down to how the new service is offered. Currently, it appears to be standard on all URLs in DMs, regardless whether they were shortened or not beforehand. If this were to become part of every tweet as well, would it be optional or the de facto shortener in all cases?</p>
<p>Here is the rub: sometimes you have to make tradeoffs for security purposes. Do we really lose anything important if they standardize on their own shortener, so long as we can still get all of the metrics and other &#8220;bells and whistles&#8221; we currently get via other tools? If it helps them proactively maintain a more secure environment on Twitter, I&#8217;m willing to make that sacrifice. Then again, I&#8217;m not on there trying to fool tweeps into clicking links to mischievous places.</p>
<p>I&#8217;ve seen various opinions out there, some in favor and some more cautious about Twitter having their own shortener. What&#8217;s your take on it? Fear of Big Brother or just another smart way to control misbehavior?</p>
<p style="text-align: center;">___________________________</p>
<p>Cheers to local fave <a title="Twitter: Wesley Faulkner (Wesley83)" href="http://twitter.com/wesley83" target="_blank">@Wesley83 (Wesley Faulkner)</a> for sharing <a title="Twitter Alters Some Links to Improve Security" href="http://mediamemo.allthingsd.com/20100309/twitters-new-security-strategy-rewriting-some-users-links/" target="_blank">Twitter Alters Some Links to Improve Security (by Peter Kafka)</a> on his <a title="Posterous: Wesley83" href="http://wesley83.posterous.com/" target="_blank">Posterous page</a>. That&#8217;s where I first learned the news, and he keeps a great personal blog on there.</p>
]]></content:encoded>
			<wfw:commentRss>http://returnonnow.com/2010/03/twitter-url-shortener-good-response-phishing/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

