<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Twitter Admin + Obama + Britney Hacked</title>
	<atom:link href="http://countermeasures.trendmicro.eu/twitter-admin-obama-britney-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu/twitter-admin-obama-britney-hacked/</link>
	<description>Trend Micro’s Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Thu, 02 Feb 2012 11:11:25 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Alex</title>
		<link>http://countermeasures.trendmicro.eu/twitter-admin-obama-britney-hacked/comment-page-1/#comment-704</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Mon, 25 May 2009 04:24:54 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=529#comment-704</guid>
		<description>Please wake up dear folks.
There&#039;s no real identity in the cloud yet.
Only trust information found on the internet as long as you double check it.</description>
		<content:encoded><![CDATA[<p>Please wake up dear folks.<br />
There&#8217;s no real identity in the cloud yet.<br />
Only trust information found on the internet as long as you double check it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rik Ferguson</title>
		<link>http://countermeasures.trendmicro.eu/twitter-admin-obama-britney-hacked/comment-page-1/#comment-521</link>
		<dc:creator>Rik Ferguson</dc:creator>
		<pubDate>Thu, 07 May 2009 07:38:47 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=529#comment-521</guid>
		<description>Hi Floris,

Thanks for commenting. The point I was making in the post was this. I realise that the site owners will have full db access but certain data itmes should not be available to read in the clear. In the same way that reputable sites will not be able to read passwords in clear text I whould like to see personal information like telephone numbers on social networking sites similarly protected. Should there be a proiblem with functionality associated witht his sensitie data, then the values can be reset and re-entered, but I can&#039;t hink of a reason why they need to be read by the site or db admins.

The &quot;become&quot; function bothers me really because of an asusmption I am making. I am assuming that the &quot;become&quot; function allows the admin the full capabilities of the account holder. I would argue that in sites that rely on trust and personal interaction, that the functionality on offer to Admins through means like this should be restricted so that they are unable to, for example, post publicly as the person they have &quot;become&quot;.</description>
		<content:encoded><![CDATA[<p>Hi Floris,</p>
<p>Thanks for commenting. The point I was making in the post was this. I realise that the site owners will have full db access but certain data itmes should not be available to read in the clear. In the same way that reputable sites will not be able to read passwords in clear text I whould like to see personal information like telephone numbers on social networking sites similarly protected. Should there be a proiblem with functionality associated witht his sensitie data, then the values can be reset and re-entered, but I can&#8217;t hink of a reason why they need to be read by the site or db admins.</p>
<p>The &#8220;become&#8221; function bothers me really because of an asusmption I am making. I am assuming that the &#8220;become&#8221; function allows the admin the full capabilities of the account holder. I would argue that in sites that rely on trust and personal interaction, that the functionality on offer to Admins through means like this should be restricted so that they are unable to, for example, post publicly as the person they have &#8220;become&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Floris Fiedeldij Dop</title>
		<link>http://countermeasures.trendmicro.eu/twitter-admin-obama-britney-hacked/comment-page-1/#comment-493</link>
		<dc:creator>Floris Fiedeldij Dop</dc:creator>
		<pubDate>Tue, 05 May 2009 13:25:48 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=529#comment-493</guid>
		<description>Rik, 

Regardless, the people who run twitter have full access to the database, so the &#039;become&#039; is just a simpler way to achieve complicated steps via a browser interface. Without the link, and the function to support it, it would just require an alternative method via the console and manual commands.  That companies decide to give this to all their staff members, vs just their trusted senior staff, is what the concern should be about.</description>
		<content:encoded><![CDATA[<p>Rik, </p>
<p>Regardless, the people who run twitter have full access to the database, so the &#8216;become&#8217; is just a simpler way to achieve complicated steps via a browser interface. Without the link, and the function to support it, it would just require an alternative method via the console and manual commands.  That companies decide to give this to all their staff members, vs just their trusted senior staff, is what the concern should be about.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rik Ferguson</title>
		<link>http://countermeasures.trendmicro.eu/twitter-admin-obama-britney-hacked/comment-page-1/#comment-438</link>
		<dc:creator>Rik Ferguson</dc:creator>
		<pubDate>Fri, 01 May 2009 18:46:40 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=529#comment-438</guid>
		<description>Thanks for that Zeno, it&#039;s not a function I came across in my years of tech support :) I can see its usefulness in tracking down anomalous behaviour within a single user account definitely, but would have to question the decision to leave it implemented on an internet facing system where you literally are what you post.</description>
		<content:encoded><![CDATA[<p>Thanks for that Zeno, it&#8217;s not a function I came across in my years of tech support :) I can see its usefulness in tracking down anomalous behaviour within a single user account definitely, but would have to question the decision to leave it implemented on an internet facing system where you literally are what you post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zeno Popovici</title>
		<link>http://countermeasures.trendmicro.eu/twitter-admin-obama-britney-hacked/comment-page-1/#comment-428</link>
		<dc:creator>Zeno Popovici</dc:creator>
		<pubDate>Fri, 01 May 2009 13:20:41 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=529#comment-428</guid>
		<description>The &quot;Become&quot; function is implemented in many applications and is being used to track down user problems which cannot be tracked down using other methods. As I worked 3 years on user support with a series of such systems, this function is absoluteley necesarry in some situations. Password in not known by the admin and confidentiality is kept by strict regulation of how and when this function is used.</description>
		<content:encoded><![CDATA[<p>The &#8220;Become&#8221; function is implemented in many applications and is being used to track down user problems which cannot be tracked down using other methods. As I worked 3 years on user support with a series of such systems, this function is absoluteley necesarry in some situations. Password in not known by the admin and confidentiality is kept by strict regulation of how and when this function is used.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rik Ferguson</title>
		<link>http://countermeasures.trendmicro.eu/twitter-admin-obama-britney-hacked/comment-page-1/#comment-423</link>
		<dc:creator>Rik Ferguson</dc:creator>
		<pubDate>Fri, 01 May 2009 10:14:21 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=529#comment-423</guid>
		<description>Yes sir it is, post duly updated thank you. I had mistakenly pulled it from the thread on the board discussing the newest compromise. I try to put all things Britney out of my mind ASAP.</description>
		<content:encoded><![CDATA[<p>Yes sir it is, post duly updated thank you. I had mistakenly pulled it from the thread on the board discussing the newest compromise. I try to put all things Britney out of my mind ASAP.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Graham Cluley, Sophos</title>
		<link>http://countermeasures.trendmicro.eu/twitter-admin-obama-britney-hacked/comment-page-1/#comment-422</link>
		<dc:creator>Graham Cluley, Sophos</dc:creator>
		<pubDate>Fri, 01 May 2009 10:05:36 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=529#comment-422</guid>
		<description>Isn&#039;t that Britney tweet about the size and sharpness of her la-di-dah, from the hack that occurred in January?

http://www.sophos.com/blogs/gc/g/2009/01/05/britney-spears-twitter-account-phished/

and

http://www.sophos.com/blogs/gc/g/2009/01/05/twitter-britney-barack-rick-fox-news-phished-hacked/

for details.

Cheers
Graham</description>
		<content:encoded><![CDATA[<p>Isn&#8217;t that Britney tweet about the size and sharpness of her la-di-dah, from the hack that occurred in January?</p>
<p><a href="http://www.sophos.com/blogs/gc/g/2009/01/05/britney-spears-twitter-account-phished/" rel="nofollow">http://www.sophos.com/blogs/gc/g/2009/01/05/britney-spears-twitter-account-phished/</a></p>
<p>and</p>
<p><a href="http://www.sophos.com/blogs/gc/g/2009/01/05/twitter-britney-barack-rick-fox-news-phished-hacked/" rel="nofollow">http://www.sophos.com/blogs/gc/g/2009/01/05/twitter-britney-barack-rick-fox-news-phished-hacked/</a></p>
<p>for details.</p>
<p>Cheers<br />
Graham</p>
]]></content:encoded>
	</item>
</channel>
</rss>

