Wednesday, 11 June 2014

Updated: TweetDeck back online, security flaw fix still in place

Updated: TweetDeck back online, security flaw fix still in place

Update: TweetDeck access is back, according to a tweet the beleaguered service sent after an hour-plus security kerfuffle.


"We've verified our security fix and have turned TweetDeck services back on for all users. Sorry for any inconvenience," TweetDeck wrote.


It's still unclear whether users need to log in, log out and finally log back in to apply the fix. We've asked TweetDeck to confirm if that's the case or not, but we suggest you do so just to be safe.


Original article below...


TweetDeck has been taken offline in order to address a security issue, and users can't log into the service.


The development comes after the tweet-posting web app had advised users to log out and log back in to apply a fix to a security vulnerability. If you're still in TweetDeck, get out now.


An XXS security vulnerability was spotted earlier in the day, a flaw that potentially gave hackers access to users accounts when they were logged in, according to Mashable. Users on Chrome seemed to be the only ones affected.


We've asked Twitter for more on the situation and will update this post when we hear back.


Damn pop-ups


As noted by The Verge, the vulnerability let hackers remotely access javascript code and implant their own.


So far attackers have seemingly stuck to annoying pop-up windows, but they could potentially do much worse damage.


Again, only users of the TweetDeck web application on Chrome seem to be affected, but it's advisable to log out of the service no matter where you're accessing it.

















http://ift.tt/1oe9Z3H

No comments:

Post a Comment