Home Editor's News First Tweet suffers certificate issues

First Tweet suffers certificate issues

March 20, 2014 | Posted by Dan Raywood

Twitter’s eighth birthday has been marred by a certificate issue that saw users face a warning page on its “First Tweet” page.

 

The page, which offered to show users their first ever tweet, worked on a standard HTTP request, but when using HTTPS users faced a page warning them that the connection was untrusted. Amar Singh, CISO and head of the UK chapter of ISACA, told IT Security Guru that despite the website being owned by Twitter, the website gives a certificate error, as the certificate could not be verified.

 

Twitter added HTTPS across the whole website in 2011 and in this incident, the First Tweet website was not recognised as the site certificate is registered to Twitter.com.

 

Speaking to IT Security Guru, Bruce Morton director of certificate services at Entrust, said that this was a “really bad mistake on the web server” as the domain name does not match the certificate name. “The browser does not trust the certificate as the names do not match and so this brings up the error page,” he said.

 

“The certificate for Twitter.com has SSL and I think that the manager of the server has put the wrong certificate on the server. It let me redirect through to another page and I found the error page showed when using Internet Explorer, Mozilla Firefox and Google Chrome.”

 

Morton discouraged users from generally clicking through as they could end up at a compromised site. “This appears to be a silly error and it is either done wrong by someone at Twitter, or they have not tested it or they put it in without SSL, maybe the testing is not complete?”

 

Singh said that the likes of Twitter, Facebook and LinkedIn are mostly seen as trusted organisations by the majority of their users, and most users may not pay attention to a warning and over time, and especially if this is repeated, most regular users would ignore this type of an error message.

 

He said: “What’s the right behaviour? No user should accept and continue on to the site, but the question is how many actually will notice? Also, when a real certificate issue happens, the typical mind may think ‘oh this happened with this big company website too so it’s nothing big and serious, but all it takes is one certificate, one website, one incident.”

 

The page was set up to mark Twitter’s eighth birthday by allowing users to see their first tweet by putting a username into the website.  However some users have claimed that the site is not working, with Guardian technology editor claiming that what was supposed to be the first tweet was three years out of date.

 

Twitter has been made aware of the issue.

Recent

Facebook denies DDoS attack

Just after 6am this morning, Facebook as well as photo sharing site Instagram suffered outages, leading to speculations of a hack. Amidst the droves that took to Twitter to complain about the outage, the infamous hacking group Lizard Squad also tried to lay claim to the attack, stating: “Facebook, Instagram, Tinder, AIM, Hipchat #offline #LizardSquad”. (…read more)

January 27, 2015

Google defends decision not to patch the Jelly Bean WebView vulnerability

According to Google’s head of Android security, Adrian Ludwig, support for the WebView extension used in Android versions 4.3 Jelly Bean is too time consuming and costly. Ludwig explained in a Google+ blog post that “WebKit alone is over 5 million lines of code and hundreds of developers are adding thousands of new commits every (…read more)

January 26, 2015

Lizard Squad hijacks Malaysia Airline DNS

Hackers purporting to be from the “Lizard Squad – Official Cyber Caliphate” group have attacked the official website of Malaysia Airlines, leaving visitors to see a message that read: “ISIS WILL PREVAIL”. The airline’s ticket-booking and other services were also unavailable. Instead, a large picture of a Malaysia Airlines A380 plane and the words “404-Plane (…read more)

January 26, 2015