FTC smacks Twitter for privacy lapses

By Julianne Pepitone, staff reporter


NEW YORK (CNNMoney.com) -- Twitter agreed to settle charges that it "deceived customers" and failed to protect their personal information, the Federal Trade Commission said Thursday.

The FTC's complaint against Twitter said "serious lapses" in the service's data security allowed hackers to obtain administrative control of the site multiple times between January and May 2009.

The FTC has brought charges against companies 30 times over faulty data security, but this marked the first such case against a social network.

In January 2009, a hacker used an automated password-guessing tool to submit thousands attempts at Twitter's login page. The hacker eventually obtained the site's administrative password, which was "a weak, lowercase, common dictionary word."

Hackers were then able to access tweets that users had set to private. They also sent fake tweets from nine accounts, including those of President Obama and Fox News.

During a second security breach in April 2009, a hacker was able to access a Twitter employee's personal e-mail account and found two passwords similar to the employee's Twitter administrative password. The hacker was able to use those passwords to guess the employee's Twitter password.

"Put simply, we were the victim of an attack and user accounts were improperly accessed," Alexander Macgillivray, Twitter's general counsel, said in a prepared statement.

Macgillivray said that within hours of the January breach, Twitter closed the security hole, notified affected account holders and posted a statement on its blog post. After the April breach, Twitter cut off the hacker's administrative access within 18 minutes and "quickly notified affected users."

The FTC said Twitter was vulnerable to these attacks because it "failed to take reasonable steps to prevent unauthorized control of its system," including requiring employees to use a hard-to-guess password and suspending administrative accounts after several unsuccessful login attempts.

Under the terms of the settlement, Twitter "will be barred for 20 years from misleading consumers" about its protection of private data. The company will also have to maintain an information security program that a third-party observer will assess every other year for 10 years.

"When a company promises consumers that their personal information is secure, it must live up to that promise," David Vladeck, director of the FTC's Bureau of Consumer Protection, said in a statement.

"Consumers who use social networking sites may choose to share some information with others," Vladeck added, "but they still have a right to expect that their personal information will be kept private and secure."

Twitter has suffered through other embarrassing glitches. In May, thousands of people took advantage of a vulnerability that let users "force" others to become their followers. Twitter quickly patched the glitch, but it had to temporarily take down its "follow" counts to do it.

The FTC smackdown comes at the end of a stretch in which Twitter has been battling its most publicized growing pains to date.

Hammered by World Cup traffic and battling issues with its network infrastructure, Twitter has suffered serious downtime almost every day this month. On Thursday, the site had several of its automated feeds disabled as it worked on stability issues.  To top of page

Frontline troops push for solar energy
The U.S. Marines are testing renewable energy technologies like solar to reduce costs and casualties associated with fossil fuels. Play
25 Best Places to find rich singles
Looking for Mr. or Ms. Moneybags? Hunt down the perfect mate in these wealthy cities, which are brimming with unattached professionals. More
Fun festivals: Twins to mustard to pirates!
You'll see double in Twinsburg, Ohio, and Ketchup lovers should beware in Middleton, WI. Here's some of the best and strangest town festivals. Play
Index Last Change % Change
Dow 16,408.54 -16.31 -0.10%
Nasdaq 4,095.52 9.29 0.23%
S&P 500 1,864.85 2.54 0.14%
Treasuries 2.72 0.08 3.19%
Data as of 2:14am ET
Company Price Change % Change
Bank of America Corp... 16.15 0.00 0.00%
Facebook Inc 58.94 0.00 0.00%
General Electric Co 26.56 0.00 0.00%
Cisco Systems Inc 23.21 0.00 0.00%
Micron Technology In... 23.91 0.00 0.00%
Data as of Apr 17
Sponsors

Sections

Spencer has been a supporting member of the "Good Morning America" cast for the past three years. More

Obamacare sign ups hit 8 million, though final enrollment remains to be seen. More

Office for iPad move is a symbolic victory for Nadella's Microsoft, but the company is still weighed down by many of the same old issues. More

Schwinn, Trek and Cannondale are all iconic American bicycle brands. But none of them are made in the United States. More

As Detroit moves closer to reaching a bankruptcy deal, retired civilian workers are poised to be left worse off than firemen and police officers. More

Market indexes are shown in real time, except for the DJIA, which is delayed by two minutes. All times are ET. Disclaimer LIBOR Warning: Neither BBA Enterprises Limited, nor the BBA LIBOR Contributor Banks, nor Reuters, can be held liable for any irregularity or inaccuracy of BBA LIBOR. Disclaimer. Morningstar: © 2014 Morningstar, Inc. All Rights Reserved. Disclaimer The Dow Jones IndexesSM are proprietary to and distributed by Dow Jones & Company, Inc. and have been licensed for use. All content of the Dow Jones IndexesSM © 2014 is proprietary to Dow Jones & Company, Inc. Chicago Mercantile Association. The market data is the property of Chicago Mercantile Exchange Inc. and its licensors. All rights reserved. FactSet Research Systems Inc. 2014. All rights reserved. Most stock quote data provided by BATS.