3 ms·
From the FTC website, the list of "reasonable steps" that twitter (and really, any web app) should have taken: * requiring employees to use hard-to-guess admin
by cedsav 16y ago
From the FTC website, the list of "reasonable steps" that twitter (and really, any web app) should have taken:
* requiring employees to use hard-to-guess administrative passwords that are not used for other programs, websites, or networks;
* prohibiting employees from storing administrative passwords in plain text within their personal e-mail accounts;
* suspending or disabling administrative passwords after a reasonable number of unsuccessful login attempts;
* providing an administrative login webpage that is made known only to authorized persons and is separate from the login page for users;
* enforcing periodic changes of administrative passwords by, for example, setting them to expire every 90 days;
* restricting access to administrative controls to employees whose jobs required it; and
* imposing other reasonable restrictions on administrative access, such as by restricting access to specified IP addresses.
[http://ftc.gov/opa/2010/06/twitter.shtm http://ftc.gov/opa/2010/06/twitter.shtm]