Last Updated Jun 24, 2010 2:21 PM EDT
According to the FTC complaint, Twitter collects a significant amount of information about people, including the following:
- email address
- IP addresses
- mobile carrier and/or mobile phone number, for those updating by phone
- other users that the person has blocked
- non-public messages sent
- establish or enforce policies sufficient to make administrative passwords hard to guess, including policies that: (1) prohibit the use of common dictionary words as administrative passwords; and (2) require that such passwords be unique â€" i.e., different from any password that the employee uses to access third-party programs, websites, and networks;
- establish or enforce policies sufficient to prohibit storage of administrative passwords in plain text in personal email accounts;
- suspend or disable administrative passwords after a reasonable number of unsuccessful login attempts;
- provide an administrative login webpage that is made known only to authorized persons and is separate from the login webpage provided to other users;
- enforce periodic changes of administrative passwords, such as by setting these passwords to expire every 90 days;
- restrict each person's access to administrative controls according to the needs of that person's job; and
- impose other reasonable restrictions on administrative access, such as by restricting access to specified IP addresses.
Twitter is very concerned about safeguarding the confidentiality of your personally identifiable information. We employ administrative, physical and electronic measures designed to protect your information from unauthorized access.In the consent decree, Twitter doesn't admit to violating the law, or even that the FTC's allegations are correct. Big deal. The company is now saddled with keeping the agency happy and having to prove itself over an extended period of time. Twitter must put a real security infrastructure into place, including ongoing risk assessment, and undergo security audits every two years by an FTC-approved third party.
For the first six months, the FTC gets a copy of every consumer complaint about security. For two years, the agency gets copies of all subpoenas and law enforcement communications.
Under the terms of the settlement, Twitter will be barred for 20 years from misleading consumers about the extent to which it maintains and protects the security, privacy, and confidentiality of nonpublic consumer information, including the measures it takes to prevent authorized access to information and honor the privacy choices made by consumers.Should the FTC or the U.S. government file a complaint in federal court alleging that Twitter has violated the order, the agreement then extends from that date. This does little to assuage user mistrust of the service.
As consent decrees go, this was relatively small in scope. But they get far worse, and the entire tech industry should take this as a warning shot across the bow.
- Facebook's Biggest Obstacle: No One Trusts It
- Google's Big Wi-Fi Problem May Be Wiretapping, Not Privacy
- Facebook's New Privacy Problem: Partners and Guilt by Association
- AT&T Says Oops! Hacking Becomes Mobile's Soft Underbelly