SnapChat's latest security #fail: What the experts have to say

SnapChat is once again in the headlines following news that the app has taken new measures towards improving its data vulnerabilities, by implementing a creative captcha that prompts users to identify images containing the app’s signature ghost mascot.

But when hacks and security flaws can lead to the private data of 4.6 million users being publically leaked, as SnapChat experienced at the end of last year, are measures like these enough?

An important question in light of recent reports that the new security measure can in fact be bypassed within 30 minutes.

A panel of leading IT experts discusses what IT departments and decision-makers need to look at to make sure they’re protecting themselves and their organisations against increasingly prevailing hacking attacks.

Rik Ferguson, VP of security research at Trend Micro comments on the recent hackings:

This method of attack has become a standard tactic of the SEA over the past couple of years. High profile communications media are targeted and used to broadcast political messages.

The only unusual aspect to this most recent hijack is the content of the messages, being more to do with the Snowden revelations and less to do directly with events in Syria.

It is highly likely that not only has the target remained consistent, but also the modus operandi which has proven so effective before. Key individuals in the target enterprise would have received well-crafted and convincing emails, either with a malicious file attached, or containing a credible-looking link.

Once compromised through either infection or phishing, then the account usernames and passwords would be available to the attacker, allowing further malicious activity.

This method of attack may seem simple on the surface but it mirrors very closely the methodology used in targeted attacks on businesses the world over by many more criminal groups than just the SEA. Humans are targeted as the easy to fool, weak points. Legitimate account details are compromised and the attacker is then at liberty to explore the victim network freely.

In these targeted attacks on enterprises, nothing so obvious as posting messages on a Twitter feed happens, of course, and the attacker can often stay resident in the victim network for a period of many months, undetected.

Steve Browell, chief technology officer at Intrinsic:

The recent Skype and Snapchat hacks have demonstrated IT departments need to refresh their policies on consumer apps in the workplace. Generation Y live through social media and as a result are sharing data 24/7. In the spur of the moment, how many employees stop and question applications that request access to their business contacts?

IT departments need to become more collaborative with the wider organisation. Once IT aligns itself closely with consumer mobile behaviours and seeks regular feedback on devices and apps being used in the workplace, we will see more consistent and robust policies put in place, which will help to mitigate against future risks.

Tim Patrick-Smith, CIO at Getronics:

The recent hacking of Skype and SnapChat has brought to the surface the potential security risks of allowing employees to utilise consumer communications tools for transferring business data. For many IT departments the instinctive reaction to these events is to block access to such services, but in today’s world of bring-your-own-everything this response is likely to fail as employees find ways around what they see as barriers to their preferred ways of working.

Businesses and IT departments therefore need to take a more proactive approach to managing the risks, working with the technologies users want to use, rather than against them.

Since SnapChat works as a transitory message carrier where content is removed once it is viewed, the risks of information falling into the wrong hands by accident are minimal. However recent hacks targeted obtaining end-user credentials and contact data, which opens up the possibility of identity theft.

This poses a threat to businesses where employees are in the habit of using the same passwords and user names across a range of business and social services. Businesses and IT departments should re-appraise their policies on access controls in the wake of these attacks.

IT departments must ensure that user passwords are changed regularly and that usernames are created by the organisation and not the end user. Security controls based on identity verification information such as mobile numbers and common question and answer approaches should be reviewed and updated.

Want your business, product or service to be seen regionally and nationally? Bdaily helps you get your story in front of the right audience, every day. Find out how Bdaily can help →

Join more than 55,000 subscribers by signing up to our daily bulletin each morning here.

Our Partners