17 May 2014

Bitly exploited

When a link is shortened using the Bitly service, it uses the HTTP 301 redirect  for the link so the change is permanent and cannot be changed back.  It uses the domain bit.ly for any shortened URLs.  It offers paid enterprise solutions called Bitly Enterprise so companies may generate their custom domain for an advanced branding feature. Security breaches on social websites and on the world wide web have increased radically recently. People tend to store more of their personal and business information on the internet. Recently on May 11th, Chief Executive Mark Josephson of Bitly wrote in their blog that their account credentials had been compromised and that they had seen accesses without proper authentication.  It was stated that they have taken enough necessary safety precautions to guard accounts.  He also stated that they have cancelled the links between Facebook and Twitter accounts so users would need to reconnect with them at their next login. The company is assuring their clients that their service is still secure and all the necessary precautionary measures are taken to ensure the security of accounts.   The company emphasizes that they take this matter seriously because they want their customers to feel secure and trust them. They apologize for any inconvenience and will update their Twitter feeds if they have something additional to convey. The security of the web comes up on the heels of a highlighted issue with the impacts of the heartbleed bug’s misuse in world wide web security.  Heartbleed left sensitive data and millions of passwords open to hackers.  A UK based website was the first to mention that security had been compromised due to the Heartbleed bug which is described as “catastrophic” because it led to insurmountable amounts of organizations and people who had to install security patches to remove the flaw. After seeing this incident, Twitter has also increased their protection by adding two more features to improve login protection.  Users will have to reset information sent to their mail account or phone number depending on the type of link done through the website. Twitter will start to monitor the login details to ensure the safety of users by saving the device used for logging and the location of the session with date and time. [AMAZONPRODUCTS asin="1466580585"]]]>