Live data from Hacker News

Trump's Twitter account hacked after Dutch researcher guessed password?

theguardian.com

81–90 of 111 posts

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#81
post #9

Sorry, I just can't believe that the first person to guess Trump's (surely the most valuable target in the world for hackers) password as 'maga2020' would be a white hat. This looks like a hoax to me.

Or, he's both the first who's brave enough to try, and honest enough to admit it.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#82
post #77

The Trump-tie aside, does anyone have a good reason why 2FA isn't absolutely enforced on all verified accounts? I can't really see a situation where the need for "authenticity" of a person/account meets the bar for needing verification, but not be considered important enough for basic security practices.

I can guess. People lose or break their phones often enough. It is a routine thing in an organisation of just 120 people. Now imagine that instead of an educated and selective group, you are dealing with a pool of desperately partying, drunk globetrotting influencers, political figures with Neanderthal technical skills or other walking security disasters. How often do you think account recovery due to lost 2FA would…

I'm not talking about all accounts though, just the ones which have been verified by twitter.

I would expect that if the identity of the account owner has already been verified, the account recovery process in this situation would be much more straight forward than a non-verified user.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#85

Earlier quoted context omitted.

What are they going to do, kick him off? This man's account has been the singular reason for Twitter's relevance over the past four years.

2FA would be ideal, but GeoIP restriction requires no action on the part of the end-user. If implemented properly, Twitter should have been alerted that something was fishy when an IP from the Netherlands sent a successful login password and prevented it, then e-mailed the user to ask if the login attempt was legitimate. It saved my butt once when Gmail prevented an IP originating in India from logging into my accoun…

i would have assumed a security researcher was smart enough to use a vpn located in the US

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#86
Completely made up. Three submissions, ~50, ~100 and ~150 points in HN. Everyone having a laugh, no one cares for site rules. No moderation in sight. Everyone knows it's fake, no one cares. Rinse and repeat about three times a day over four years. Some of them make it into HN, each one makes in into the minds of thousands. But dare to defend truth and the cavalry is there in seconds.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#87
post #40

Earlier quoted context omitted.

It's got everything a strong password needs. Letters, numbers, and special characters!

No capital letters, though. It is important to follow all security rules. Weakest link and such. If only his password was Maga2020!, it would be impossible to hack.

MAGA2020! has 4 capital letters. 4x more secure.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#88
post #40

Earlier quoted context omitted.

No capital letters, though. It is important to follow all security rules. Weakest link and such. If only his password was Maga2020!, it would be impossible to hack.

MAGA2020! has 4 capital letters. 4x more secure.

2020! alone is 5,802 digits long.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#89
post #73

Earlier quoted context omitted.

A somewhat educated guess: Probably the "cost-to-serve" metrics that Twitter considers when making these changes. Force 2FA on your most high-profile customers, and your support costs skyrocket as a steady stream of these customers who didn't want this new and (relatively) complicated measure forget or lose their 2FA setup, and you find yourself constantly resetting it or changing it, which probably in the long term…

I've stumbled upon enough verified accounts that had their display name and photos changed to Elon Musk's and pretended to give away Bitcoins that I believe it's a worthy sacrifice to make.

You and me both, but Twitter is a public company with fiduciary responsibilities to shareholders above all else (including the public good), so here we are.

Until these kinds of problems affect their brand enough to cause financial harm, don't hold your breath for higher security and accountability measures by default.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#90

The password format is surely the most common password pattern that everyone seems to have independently adopted

It's not happening independently, it's cargo-culted. There's lots of "security advice" out there recommending doing exactly this. Plus, if you're missing a requirement when trying to set your password, the easiest thing to do is just append the missing requirement at the end. Especially if it's punctuation, which naturally goes at the end of words/sentences anyway.

I've taken to using random passwords for signup and password reset for each login, since that's what password guidelines eventually force me to do anyway.
Post reply on HN