Friday, June 19, 2009

Beware Fake Twitter Email!

There are a lot of reports of a mass-email worm going around pretending to be a Twitter invite. Articles on this can be found here, here, and here. This has been going on for some time now, and the fact that it hasn't been eradicated yet means that you should be extra cautious in your Internet browsing.

The only real way to protect yourself from this worm is to either not use the web browser version of Twitter (using a client loaded on your computer instead) or by disabling java on your browser (which will affect other, non-Twitter, sites). If you must use Twitter, I'd recommend accessing it via an application on your phone or installing a client (like Tweetdeck) and avoiding using your browser for Twitter access.

As more and more of these social networking sites become popular, it will be very important for the companies and/or individuals who run these sites to be proactive about addressing security issues before their users become infected. This current worm is an example of how important it is to be aware that you can't rely on the services you use to protect you from viruses, worms, and malware, you need to be proactive and careful no matter what system you are accessing.

Lastly, I always tell everyone that I discuss email security with that if you receive an email and you weren't expecting it, don't open it. If it was legitimate you can always contact the sender and ask them to re-send it. Email is not a secure application and there is no way to tell if the person an email appears to be from is actually the party that sent it. When it comes to email, it is always better safe than sorry.