Skip to main navigation Skip to search Skip to main content

Why allowing profile name reuse is a bad idea

  • Enrico Mariconti
  • , Jeremiah Onaolapo
  • , Syed Sharique Ahmad
  • , Nicolas Nikiforou
  • , Manuel Egele
  • , Nick Nikiforakis
  • , Gianluca Stringhini
  • University College London
  • Stony Brook University
  • Boston University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

7 Scopus citations

Abstract

Twitter allows their users to change profile name at their discretion. Unfortunately, this design decision can be used by attackers to effortlessly hijack user names of popular accounts. We call this practice profile name squatting. In this paper, we investigate this name squatting phenomenon, and show how this can be used to mount impersonation attacks and attract a larger number of victims to potentially malicious content. We observe that malicious users are already performing this attack on Twitter and measure its prevalence. We provide insights into the characteristics of such malicious users, and argue that these problems could be solved if the social network never released old user names for others to use.

Original languageEnglish
Title of host publicationProceedings of the 9th European Workshop on System Security, EuroSec 2016
PublisherAssociation for Computing Machinery
ISBN (Electronic)9781450342957
DOIs
StatePublished - Apr 18 2016
Event9th European Workshop on System Security, EuroSec 2016 - London, United Kingdom
Duration: Apr 18 2016 → …

Publication series

NameProceedings of the 9th European Workshop on System Security, EuroSec 2016

Conference

Conference9th European Workshop on System Security, EuroSec 2016
Country/TerritoryUnited Kingdom
CityLondon
Period04/18/16 → …

Fingerprint

Dive into the research topics of 'Why allowing profile name reuse is a bad idea'. Together they form a unique fingerprint.

Cite this