Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Twitter has announced the availability of two factor authentication (2FA) for its service, meaning that users can opt-in to something stronger than just a username and password to protect their accounts.

In a blog post, Twitter explains how the new security measure works.
If you decide to turn 2FA on for your Twitter account, every time you try to log into the site you will be prompted to enter a six-digit code that Twitter sends to your phone via SMS.
Here is a video Twitter released, demonstrating the feature:
So, the big question is this... is this going to help media organisations such as The Guardian, NPR, the Financial Times, and others who have found their Twitter accounts hijacked by the likes of the Syrian Electronic Army?
Sadly, I don't think it's going to help them at all.
Media organisations who share breaking news via social media typically have many staff, around the globe, who share the same Twitter accounts.
2FA isn't going to help these companies, because they can't all access the same phone at the same time.
Either those people will have to leave themselves permanently logged into Twitter (which is itself unwise from the security perspective), or one central trusted person will have to "own" the phone - and share the six-digit code with journalists as they try to log in to share breaking news stories.

It's a complex problem to fix, and for that reason many media organisations may choose not to enable Twitter's additional security at this time.
Of course, *another* solution would be to have an intermediary service, acting as a proxy, to which journalists could post their Twitter updates (using appropriate authentication) and then have *that* service feed the official Twitter account.
If you take that approach, just ensure that you have proper security systems in place for that proxy service - to keep out hackers and mischief-makers.
Corporations with "shared accounts" on Twitter would be wise to keep their defences updated, educate their staff on security and best practice, and learn the lessons of how Twitter accounts have been hacked in the past.
If you do enable Twitter two-factor authentication, whether you are Joe Public or a multinational corporation, realise that the technology isn't going to help if you have users who are easily phished.
Determined online criminals could use "man-in-the-middle" techniques to grab the six digit passcode alongside your password and username if they are determined.
So, even if you do turn on Twitter's 2FA, you still need to double-check that when you enter your username and password, or your six digit code, that you are *really* on Twitter's https website.

Otherwise, the crooks can just use all three items to log in as you...
In time, Twitter will surely mature and offer appropriate security, and mechanisms which recognise how many corporate brands and news organisations are using Twitter today.
Maybe they will one day adopt a system like Facebook has, where multiple users can have access to an account - all with different levels of authority, all with different usernames and passwords.
Right now Twitter's 2FA is more likely to be welcomed by individuals who own personal accounts, and small companies with a Twitter presence, than embraced by the high profile victims attacked by the Syrian Electronic Army in the past.
Follow @gcluley
The Syrian Electronic Army has struck again - this time adding the scalp of the prestigious Financial Times to its collection of hijacked accounts belonging to well-known media organisations.



Candace Bushnell, the author famous for "Sex and the City", has fallen victim to a hacker who not only broke into her Twitter account, but also posted extracts of her as-yet-unfinished next book online.


The first attempt came around May 3, when the SEA sent phishing emails to some Onion employees. It included a spoofed link, purportedly to an article about The Onion published by The Washington Post, which actually went through a few redirects before depositing its targets at a site that requested Google Apps credentials before redirecting to a Gmail inbox.
That's when the editorial team started to publish satirical articles inspired by the attack.
A security researcher and trained commercial pilot combined his interests and cooked up an exploit framework and Android app that can be used, at least theoretically, to hack a plane.
The application has four functions: discovery, information gathering, exploitation and post exploitation.

Evernote, the online note-taking service, has posted an advisory informing its near 50 million users that it has suffered a serious security breach that saw hackers steal usernames, associated email addresses and encrypted passwords. 
If you are one of the more than two million people who follow Donald Trump on Twitter, you might have seen an unusual tweet from the impossibly coiffed real estate mogul yesterday.

BlackBerry recently surprised the tech industry when they announced at their major launch event on January 30 the appointment of musician, Alicia Keys, as the Global Creative Director.


A court in London has heard that Sarah Ferguson, the former wife of Prince Andrew, is one of more than 100 people who have received significant payouts in the wake of the News of the World phone hacking scandal.
Users are getting infected with ransomware thanks to criminals managing to hack the DNS records of Go Daddy hosted websites.



Given the prevalence of attacks against web sites for the purpose of malware distribution it is high time that associated services (Registrars, hosting providers etc) pay adequate consideration to security.