Live data from Hacker News

Trump's Twitter account hacked after Dutch researcher guessed password?

theguardian.com

71–80 of 111 posts

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#71

There's no evidence in this story, I'd take it with a grain of salt.

The TechCrunch article has a screenshot from the profile editor: https://techcrunch.com/wp-content/uploads/2020/10/trump-acce...

Which is trivial to fake by going to your own profile and using your browser's inspector to swap out a few images and change a few text boxes.

I kind of think it's a toss-up if this is true. I can believe Trump would use a very weak password and not apply 2fa, but I'm very surprised that Twitter's additional guard-rails for important accounts didn't prevent this.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#72
post #37

This seems to be completely implausible. Whatever email is tied to this account would have been instantly notified about a "suspicious login". There is absolutely no evidence in the article (not even links or screenshots of his tweet reaching out to the White House). Furthermore I can't believe Trump's account is even going through regular authentication mechanisms. It should be trivial to restrict access to an accou…

There's been repeated claims that Trump has - up until recently - used personal Android and iPhone devices to make calls and tweet. Not clear if that's true or not.

https://www.politico.com/story/2018/05/21/trump-phone-securi...

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#73

The Trump-tie aside, does anyone have a good reason why 2FA isn't absolutely enforced on all verified accounts? I can't really see a situation where the need for "authenticity" of a person/account meets the bar for needing verification, but not be considered important enough for basic security practices.

A somewhat educated guess: Probably the "cost-to-serve" metrics that Twitter considers when making these changes.

Force 2FA on your most high-profile customers, and your support costs skyrocket as a steady stream of these customers who didn't want this new and (relatively) complicated measure forget or lose their 2FA setup, and you find yourself constantly resetting it or changing it, which probably in the long term reduces the effectiveness of it since it becomes a routine for your support operation and it's easier for bad actors to fake it.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#74

Earlier quoted context omitted.

The TechCrunch article has a screenshot from the profile editor: https://techcrunch.com/wp-content/uploads/2020/10/trump-acce...

Which doesn't show the Twitter handle. Anyone can fake this by changing an accounts name, profile picture, bio, and banner.

They can, but reading about Gevers shows a track record. It’s worth being skeptical, but keep his record in mind. Apply the same skepticism to Twitter too, they haven’t got a great record.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#75

There's no evidence in this story, I'd take it with a grain of salt.

I had some doubts about veracity and while still in two minds but https://www.vn.nl/trump-twitter-hacked-again/ provides enough details that if it does turn out to be bs then they are easy enough to prove or refute - " After logging in, he emailed US-CERT". But I agree with your sense of hesitancy since the sources of the story mostly originate from Yahoo News, a Dutch marketing company called DPG Media, TechCrunch rather than the usual broader sources.

It will be interesting to see how Victor Gevers responds.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#76

There's no evidence in this story, I'd take it with a grain of salt.

The TechCrunch article has a screenshot from the profile editor: https://techcrunch.com/wp-content/uploads/2020/10/trump-acce...

This is the only screenshot that the researcher posts as 'evidence' of gaining access to Trump's account. I'm afraid that this one can be easily faked with browser tools. The fact that White house officials have extra security measures on their accounts it is this only screenshot that makes it less convincing that this is true, unless the researcher publishes multiple screenshots or video evidence of logging into the account themselves.

Otherwise it can be easily dismissed as a fake screenshot, even if he 'did it' in the past.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#77

The Trump-tie aside, does anyone have a good reason why 2FA isn't absolutely enforced on all verified accounts? I can't really see a situation where the need for "authenticity" of a person/account meets the bar for needing verification, but not be considered important enough for basic security practices.

I can guess.

People lose or break their phones often enough. It is a routine thing in an organisation of just 120 people. Now imagine that instead of an educated and selective group, you are dealing with a pool of desperately partying, drunk globetrotting influencers, political figures with Neanderthal technical skills or other walking security disasters.

How often do you think account recovery due to lost 2FA would be triggered?

For proper protection you need hardware 2FA, and for usability reasons you really need the NFC enabled Yubikey so the same second factor can be neatly enforced on a mobile phone too. But you can't have just one. If the access is for anything non-trivial or of high importance, you need at least two such devices. Preferably three.

That's a lot of Yubikeys you need to subsidise, because most people sure as hell are not buying them out of their own pocket.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#78

> Gevers said the ease with which he accessed Trump’s account suggested the president was not using basic security measures like two-step verification. I am gobsmacked that Twitter allowed his account to continue without some kind of additional security measures like 2FA or geo-IP checking. This is a guy that could literally start World War III by sending a tweet like, "Eat shit, China! Missiles on their way!" And Tw…

What are they going to do, kick him off? This man's account has been the singular reason for Twitter's relevance over the past four years.

If Twitter banned Trump, a Trump-branded Twitter clone would pop up overnight with a built-in audience of 87M followers.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#79
post #73

The Trump-tie aside, does anyone have a good reason why 2FA isn't absolutely enforced on all verified accounts? I can't really see a situation where the need for "authenticity" of a person/account meets the bar for needing verification, but not be considered important enough for basic security practices.

A somewhat educated guess: Probably the "cost-to-serve" metrics that Twitter considers when making these changes. Force 2FA on your most high-profile customers, and your support costs skyrocket as a steady stream of these customers who didn't want this new and (relatively) complicated measure forget or lose their 2FA setup, and you find yourself constantly resetting it or changing it, which probably in the long term…

I've stumbled upon enough verified accounts that had their display name and photos changed to Elon Musk's and pretended to give away Bitcoins that I believe it's a worthy sacrifice to make.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#80
post #13

Earlier quoted context omitted.

Agreed. If the password was that simple it would have hacked a while back

Two economists were walking down the street. The first one says: “Isn’t that a $20 bill?” The second one says: “Can’t be. If it were, somebody would have picked it up already.”

Saw a $20 on the ground in front of the elevators at a hedge fund last year. Lobby full of employees. True story.
Post reply on HN