Live data from Hacker News

Trump's Twitter account hacked after Dutch researcher guessed password?

theguardian.com

61–70 of 111 posts

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#61
post #37

This seems to be completely implausible. Whatever email is tied to this account would have been instantly notified about a "suspicious login". There is absolutely no evidence in the article (not even links or screenshots of his tweet reaching out to the White House). Furthermore I can't believe Trump's account is even going through regular authentication mechanisms. It should be trivial to restrict access to an accou…

I agree with the overall thrust of the questions. But Trump might not cooperate with anything that makes life more inconvenient for him: https://www.cnn.com/2019/12/06/politics/donald-trump-secure-....

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#62

> Gevers said the ease with which he accessed Trump’s account suggested the president was not using basic security measures like two-step verification. I am gobsmacked that Twitter allowed his account to continue without some kind of additional security measures like 2FA or geo-IP checking. This is a guy that could literally start World War III by sending a tweet like, "Eat shit, China! Missiles on their way!" And Tw…

> I am gobsmacked that Twitter allowed his account to continue without some kind of additional security measures like 2FA or geo-IP checking. This is a guy that could literally start World War III by sending a tweet like, "Eat shit, China! Missiles on their way!" And Twitter didn't think it should be locked down beyond a simple password!?!

I mean remember how bitcoin scammers got access to Twitter admin panels recently? I don't think security is Twitter's biggest concern... My old Twitter account has been hacked by a Russian spammer despite having 2FA, I just decided to close it, it became a liability.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#63

The password format is surely the most common password pattern that everyone seems to have independently adopted

Actually this is interesting, I did this myself growing up. But I seem to remember that it arose because of slowly changing password requirements. Like I remember having a password in my teens for Myspace and other web services, and one day when signing up for a new service I was prompted with "your password must contain at least one number". So I just took the same old password and put a number on the end of it. Then a few years later the same thing happened with special characters: "Your password must contain at least one number and a special character". So then "okay, just tack a special character on to the password I already know" and voila is now my password.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#65

There's no evidence in this story, I'd take it with a grain of salt.

The TechCrunch article has a screenshot from the profile editor: https://techcrunch.com/wp-content/uploads/2020/10/trump-acce...

Which doesn't show the Twitter handle. Anyone can fake this by changing an accounts name, profile picture, bio, and banner.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#66

There's no evidence in this story, I'd take it with a grain of salt.

If you follow the references they provide, you'll see that the person responsible is a respected security researcher with a history of similar discoveries. He also posted screenshots, and suggests that he was responsible for Trump's recent tweet praising a satirical Babylon Bee article. https://www.vn.nl/trump-twitter-hacked-again/ : Gevers comes up with a plan to make sure that this time the White House responds. He…

The tweet is available right now?

https://twitter.com/realDonaldTrump/status/13170445563287306...

Why not post a hash of a timestamped transaction on the blockchain? Wouldn't that be better for establishing credibility instead of this?

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#67

There's no evidence in this story, I'd take it with a grain of salt.

The guy has apparently done it before. Edit: dutch media are reporting that they have seen evidence that backs up his claim.

The source article is linked to on the story, and it says screenshots were taken. My parsing interprets it as saying that they showed these screenshots to security researchers. “screenshots were shared with de Volkskrant by the monthly opinion magazine Vrij Nederland. Dutch security experts find Gevers’ claim credible.”

https://www.volkskrant.nl/nieuws-achtergrond/dutch-ethical-h...

Also, the guy has a history (well, both do). Gevers has got into numerous other accounts before, and uncovered some disturbing stuff - tracking of Chinese Muslims via facial recognition stuff in China for example.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#68

> Gevers said the ease with which he accessed Trump’s account suggested the president was not using basic security measures like two-step verification. I am gobsmacked that Twitter allowed his account to continue without some kind of additional security measures like 2FA or geo-IP checking. This is a guy that could literally start World War III by sending a tweet like, "Eat shit, China! Missiles on their way!" And Tw…

What are they going to do, kick him off? This man's account has been the singular reason for Twitter's relevance over the past four years.

2FA would be ideal, but GeoIP restriction requires no action on the part of the end-user. If implemented properly, Twitter should have been alerted that something was fishy when an IP from the Netherlands sent a successful login password and prevented it, then e-mailed the user to ask if the login attempt was legitimate. It saved my butt once when Gmail prevented an IP originating in India from logging into my account and alerted me.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#69
post #33

Twitter spokesperson Ian Plunkett: “We’ve seen no evidence to corroborate this claim, including from the article published in the Netherlands today. We proactively implemented account security measures for a designated group of high-profile, election-related Twitter accounts in the United States, including federal branches of government.” https://techcrunch.com/2020/10/22/dutch-hacker-trump-twitter...

Proactively? Was that after the other massive hack or after this one?

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#70

> Gevers said the ease with which he accessed Trump’s account suggested the president was not using basic security measures like two-step verification. I am gobsmacked that Twitter allowed his account to continue without some kind of additional security measures like 2FA or geo-IP checking. This is a guy that could literally start World War III by sending a tweet like, "Eat shit, China! Missiles on their way!" And Tw…

But twitter supports this feature. Why is it their responsibility to enforce this?
Post reply on HN