海角大神

Zendesk hack points to overall vulnerability on the Web

Twitter, Pinterest, and Tumblr have notified their users of a security breach from Zendesk, the customer-software provider that handles their support questions. The breach may confirm a need for tougher security standards for websites and applications.

|
Pinterest
Pinterest was one of the websites affected by the Zendesk security breach. A small percentage of Pinterest users were notified that their correspondences with support services were accessed by a hacker.

Zendesk is the latest victim of hacking, which means that Twitter, Pinterest, and Tumblr are also the latest victims of hacking.

The customer-software provider, which organizes support inquiries from the social media sites, notified its customers of a security breach this week. A hacker accessed the system and downloaded emails from users who have contacted the social media sites鈥 support departments, according to the Zendesk .

鈥淲e are also completely committed to working with authorities to bring anyone involved to justice and make certain we fully understand what happened,鈥 Zendesk says on its blog. 鈥淎s this process unfolds, we aim to update our customers in as transparent and timely a manner as possible about the new developments.

A Tumblr spokeswoman said in a statement that the security breach exposed e-mail addresses and subject lines, which may have noted the users鈥 Tumblr blog address. Those who may be affected are encouraged to review their correspondence with Tumblr鈥檚 support addresses: support@tumblr.com, abuse@tumblr.com, dmca@tumblr.com, legal@tumblr.com, enquiries@tumblr.com, and lawenforcement@tumblr.com.

鈥淵our safety is our highest priority,"聽the Tumblr statement reads.聽"We鈥檙e working with law enforcement and Zendesk to better understand this attack."

Pinterest and Twitter also contacted users who may have been affected by the breach, warning them to not give password information and to notify them of any issues, according to their statements.

Twitter posted account security tips on its Tuesday, reminding its users to have strong passwords and be wary of suspicious links and information requests.

But strong passwords and security complaints alone may not protect users from stolen e-mails or passwords. Zendesk's breach emerged the same week President Barack Obama issued an to improve infrastructure cybersecurity.

鈥淭he cyber threat to critical infrastructure continues to grow and represents one of the most serious national security challenges we must confront,鈥 the executive order states. 鈥淭he national and economic security of the United States depends on the reliable functioning of the Nation's critical infrastructure in the face of such threats.鈥

Carl Landwehr, a research scientist at the Cyber Security Policy and Research Institute at George Washington University, agrees that the slew of recent hacks point to a larger problem with infrastructure cybersecurity.

"We have a lot of systems out there that are not build to any particular standard, and so they tend to have vulnerabilities in them," Mr. Landwehr says. "That's not because people don't try to remove them, but because it's actually difficult."

With online software and services developing at such a rapid pace, it's not surprising that applications and services may not have high security standards, Landwehr notes. The marketplace tends to grade websites and applications based on their reliability (their day-to-day functionality) meaning that small security bugs tend to go unseen, at least until a hack.聽

"I wouldn't seek to blame anybody in particular for these things," he says. "The marketplace doesn't have a way of rewarding people who do a better job."聽

One solution may be a set of guidelines for programmers and developers, Landweher says. A "building code" would need to regulate online infrastructure without restricting innovation, it could lead to stronger websites and applications that protect everything from one's personal blog to confidential financial or national security material.

鈥淚 certainly won鈥檛 be happy if my personal data gets compromised, but I鈥檒l be much more concerned if the financial industry infrastructure or the national power grid gets compromised,鈥 he says.聽

You've read  of  free articles. Subscribe to continue.
Real news can be honest, hopeful, credible, constructive.
海角大神 was founded in 1908 to lift the standard of journalism and uplift humanity. We aim to 鈥渟peak the truth in love.鈥 Our goal is not to tell you what to think, but to give you the essential knowledge and understanding to come to your own intelligent conclusions. Join us in this mission by subscribing.
QR Code to Zendesk hack points to overall vulnerability on the Web
Read this article in
/Technology/2013/0222/Zendesk-hack-points-to-overall-vulnerability-on-the-Web
QR Code to Subscription page
Start your subscription today
/subscribe