<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:,2009:/1/tag:www.readwriteweb.com,2009://1.13987-</id>
  <updated>2009-11-23T17:31:06Z</updated>
  <title>Comments for Updated: Google Talk Worm Origin Found?</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.23-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13987</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=13987" title="Updated: Google Talk Worm Origin Found?" />
    <published>2009-02-24T22:37:24Z</published>
    <updated>2009-02-25T10:18:42Z</updated>
    <title>Updated: Google Talk Worm Origin Found?</title>
    <summary>&quot;Hey check out this video! http://tinyurl.com/xyz,&quot;; says an old friend by Google Talk IM. Well sure, you think, I&apos;d love to see a video from you - it&apos;s been a long time! Maybe you got an IM like that this afternoon, too. Maybe you got six. There&apos;s nothing wrong with clicking on such a link,...</summary>
    <author>
      <name>Marshall Kirkpatrick</name>
      <uri>http://www.readwriteweb.com</uri>
    </author>
    
    <category term="News" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img alt="googletalklogo105-2.jpg" src="http://www.readwriteweb.com/images/googletalklogo105-2.jpg" width="106" height="58">"Hey check out this video! http://tinyurl.com/xyz,"; says an old friend by Google Talk IM. Well sure, you think, I'd love to see a video from you - it's been a long time! Maybe you got an IM like that this afternoon, too. Maybe you got six.</p>

<p>There's nothing wrong with clicking on such a link, but when the site that loads as a result, Viddyho.com, asks for your Google Talk username and password in order to view the video - then you should know that trouble is afoot. Surprisingly, a whole lot of tech savvy people fell for it today. Update: The Harvard Crimson says it has unearthed the person responsible for the Viddyho worm.</p>]]>
      <![CDATA[<p>Daniel Carroll reported tonight <a href="http://www.thecrimson.com/article.aspx?ref=526749">on the Harvard Crimson newspaper's site</a> that he did a little tracing backwards, further than other reporters on the story had, and found that a San Franciscan named Hoan Ton-That appears to be responsible for the site that was harvesting the user credentials of worm victims.  Ton-That's web hosting account has been suspended, Carroll reports that he's learned from the company.  The alleged author of the worm didn't respond to his requests for comment but has a twitter account <a href="http://twitter.com/hoan">here</a> and apparently was in this author's home town of Portland, Oregon just last week. (We were not plotting the attack together, I swear.)  Ton-That's Twitter bio reads: "Anarcho-Transexual Afro-Chicano American Feminist Studies Major" - which sounds like either an immature joke or a pretty bad ass bio to us.  </p>

<h2>The Tech Issues</h2>

<p>We do think there are some big issues to discuss here, too, though.</p>

<p>The fact that many otherwise tech savvy people are falling for this trap shows that legitimate experiments in user authentication (like OpenID) still have a whole lot of explaining to do and secure APIs need more adoption.  This could just as easily have been Facebook or Twitter that hijacked your Google Talk account - we give them our passwords and just trust that they won't.</p>

<p><img alt="gtalkphishing.jpg" src="http://www.readwriteweb.com/images/gtalkphishing.jpg" width="610" height="482"><br />
</p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13987-comment:127711</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13987" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php#c127711" />
    <title>Comment from Elijah Grey on 2009-02-24</title>
    <author>
        <name>Elijah Grey</name>
        <uri>http://eligrey.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://eligrey.com/">
        <![CDATA[<p>I'm sorry, but I think you are confused on how OpenID works. You only enter your OpenID URI at the website you want to log on to using OpenID. You never enter a password until you get to your OpenID host, which doesn't tell the website that you just logged onto what it is.</p>]]>
    </content>
    <published>2009-02-24T23:21:04Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13987-comment:127712</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13987" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php#c127712" />
    <title>Comment from Marshall Kirkpatrick on 2009-02-24</title>
    <author>
        <name>Marshall Kirkpatrick</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Elijah, *I* know how OpenID works just fine.  I can give you a list of respected people in tech who are confused, though, judging from their susceptibility to this attack.  I'm pretty sure that anyone who hands over their GTalk pw in this case did so because they are confused about how 3rd party authentication systems, like OpenID, work.</p>]]>
    </content>
    <published>2009-02-24T23:27:28Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13987-comment:127718</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13987" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php#c127718" />
    <title>Comment from Michelle Murrain on 2009-02-24</title>
    <author>
        <name>Michelle Murrain</name>
        <uri>http://zenofnptech.org</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://zenofnptech.org">
        <![CDATA[<p>Marshall, that's not it at all. I'm a tech person who knows full well how OpenID works, and I use it whenever I am able to. The link came from a good friend (also a geek), so I trusted it. And people who trusted me fell for it too.</p>

<p>It's pure and simple social engineering. And it worked. (Well, only once. Probably never again.) </p>

<p>Yes, if *every* site used OpenID, then this wouldn't work, but we're still in the realm where most don't.</p>]]>
    </content>
    <published>2009-02-24T23:56:55Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13987-comment:127720</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13987" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php#c127720" />
    <title>Comment from mike &quot;glemak&quot; dunn on 2009-02-24</title>
    <author>
        <name>mike &quot;glemak&quot; dunn</name>
        <uri>http://friendfeed.com/glemak</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/glemak">
        <![CDATA[<p>ah that explains it - thanks</p>]]>
    </content>
    <published>2009-02-25T00:08:00Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13987-comment:127728</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13987" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php#c127728" />
    <title>Comment from Marshall on 2009-02-24</title>
    <author>
        <name>Marshall</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Testing Facebook Connect comment - hopefully someday OpenID will be as clear and simple as this is.</p>]]>
    </content>
    <published>2009-02-25T01:46:40Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13987-comment:127731</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13987" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php#c127731" />
    <title>Comment from Luke on 2009-02-24</title>
    <author>
        <name>Luke</name>
        <uri>http://blog.vidoop.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://blog.vidoop.com">
        <![CDATA[<p>If I can compromise one account on a trusted network, in time I can arguably compromise everyone.</p>

<p>For example: I compromise your FB account.  I send a link to all of your friends saying watch this (your favorite band) music video.  The majority click the link.  The site says they need to update their flash player.  They click the "make it work" button.  I install malicious keylogger.  I now have access to everything.</p>

<p>If I can easily attack and exploit a trusted network, then how can you call it trusted?</p>

<p>This is why "strong authentication" (something more than a password) is soooooo important.  It makes it much harder for a hacker to harvest account credentials.</p>]]>
    </content>
    <published>2009-02-25T02:15:56Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13987-comment:127771</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13987" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php#c127771" />
    <title>Comment from Tien on 2009-02-25</title>
    <author>
        <name>Tien</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>His name is definitely Vietnamese. Heh</p>]]>
    </content>
    <published>2009-02-25T11:21:49Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13987-comment:127782</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13987" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php#c127782" />
    <title>Comment from ITrush on 2009-02-25</title>
    <author>
        <name>ITrush</name>
        <uri>http://www.itrush.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.itrush.com">
        <![CDATA[<p>Got ya! anywayz, this serves as a reminder to all of us to check everything before giving personal infos.</p>]]>
    </content>
    <published>2009-02-25T13:53:17Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13987-comment:127793</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13987" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php#c127793" />
    <title>Comment from Zack B. on 2009-02-25</title>
    <author>
        <name>Zack B.</name>
        <uri>http://twitter.com/zebee</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://twitter.com/zebee">
        <![CDATA[<p>Yep, agree with Michelle here.  What made this such an effective scam was that the links were coming from trusted sources.</p>

<p>Sorry, but if it had been one of my 600 FB "friends" there's no way I would have fallen for it, but since it came from a trusted colleague in Gchat I didn't think twice about it.  I actually thought she was promoting a podcast she was on and I needed to login to be able to comment in real time.</p>

<p>It has been probably 10 years since I've fallen for anything like this, and luckily the consequences (so far) haven't been too bad - aside from spamming the rest of my friends. </p>

<p>Needless to say, this is the last time!</p>]]>
    </content>
    <published>2009-02-25T15:01:27Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13987-comment:127870</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13987" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php#c127870" />
    <title>Comment from Janet Altman on 2009-02-25</title>
    <author>
        <name>Janet Altman</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Listen, this is an age old problem that's not going to be eliminated overnight. You can't stop people out there from devising these things.  </p>

<p>You CAN however continue to devise digital security to begin to keep up with it.  </p>

<p>I think it's more of a maintenance thing.</p>

<p>I was browsing <a href="http://www.justaskgemalto.com" rel="nofollow">http://www.justaskgemalto.com</a> recently and found a great deal of information.  </p>

<p>I guess we just have to keep trying.</p>]]>
    </content>
    <published>2009-02-26T01:20:31Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13987-comment:128849</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13987" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php#c128849" />
    <title>Comment from Chris on 2009-03-05</title>
    <author>
        <name>Chris</name>
        <uri>http://www.weirdwarp.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.weirdwarp.com">
        <![CDATA[<p>Ridiculuous, who would fall for that? As the links were from trusted sources though it probably would have been me.</p>]]>
    </content>
    <published>2009-03-05T09:38:13Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13987-comment:129384</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13987" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php#c129384" />
    <title>Comment from Lee on 2009-03-10</title>
    <author>
        <name>Lee</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>FYI, this phishing scam has resurfaced. </p>

<p>I was not aware of this scam until this morning, 3/10/09, when a friend passed me the link.</p>

<p>NOTE: the NEW domain being used is</p>

<p>FASTFORWARDED.com</p>

<p>Registered on 2/24/09</p>

<p><a href="http://whois.domaintools.com/fastforwarded.com" rel="nofollow">http://whois.domaintools.com/fastforwarded.com</a></p>

<p></p>

<p> </p>]]>
    </content>
    <published>2009-03-10T16:42:24Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13987-comment:130804</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13987" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_talk_targeted_by_phishi.php#c130804" />
    <title>Comment from Emily  on 2009-03-24</title>
    <author>
        <name>Emily </name>
        <uri>http://www.globalcrypto.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.globalcrypto.com">
        <![CDATA[<p>I think the simplest way to avoid your information being comprised in this way is to simply ask the source before you enter your information.  There will always be a more clever scheme, but direct communication with a known associate is hard to manipulate</p>]]>
    </content>
    <published>2009-03-24T17:35:21Z</published>
  </entry>

</feed>