Sorry, I just can't believe that the first person to guess Trump's (surely the most valuable target in the world for hackers) password as 'maga2020' would be a white hat. This looks like a hoax to me.
Trump's Twitter account hacked after Dutch researcher guessed password?
81–90 of 111 posts
Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#82The Trump-tie aside, does anyone have a good reason why 2FA isn't absolutely enforced on all verified accounts? I can't really see a situation where the need for "authenticity" of a person/account meets the bar for needing verification, but not be considered important enough for basic security practices.
I can guess. People lose or break their phones often enough. It is a routine thing in an organisation of just 120 people. Now imagine that instead of an educated and selective group, you are dealing with a pool of desperately partying, drunk globetrotting influencers, political figures with Neanderthal technical skills or other walking security disasters. How often do you think account recovery due to lost 2FA would…
I would expect that if the identity of the account owner has already been verified, the account recovery process in this situation would be much more straight forward than a non-verified user.
Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#83Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#84Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#85Earlier quoted context omitted.
What are they going to do, kick him off? This man's account has been the singular reason for Twitter's relevance over the past four years.
2FA would be ideal, but GeoIP restriction requires no action on the part of the end-user. If implemented properly, Twitter should have been alerted that something was fishy when an IP from the Netherlands sent a successful login password and prevented it, then e-mailed the user to ask if the login attempt was legitimate. It saved my butt once when Gmail prevented an IP originating in India from logging into my accoun…
Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#86Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#87Earlier quoted context omitted.
It's got everything a strong password needs. Letters, numbers, and special characters!
No capital letters, though. It is important to follow all security rules. Weakest link and such. If only his password was Maga2020!, it would be impossible to hack.
Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#88Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#89Earlier quoted context omitted.
A somewhat educated guess: Probably the "cost-to-serve" metrics that Twitter considers when making these changes. Force 2FA on your most high-profile customers, and your support costs skyrocket as a steady stream of these customers who didn't want this new and (relatively) complicated measure forget or lose their 2FA setup, and you find yourself constantly resetting it or changing it, which probably in the long term…
I've stumbled upon enough verified accounts that had their display name and photos changed to Elon Musk's and pretended to give away Bitcoins that I believe it's a worthy sacrifice to make.
Until these kinds of problems affect their brand enough to cause financial harm, don't hold your breath for higher security and accountability measures by default.
Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#90The password format is surely the most common password pattern that everyone seems to have independently adopted
It's not happening independently, it's cargo-culted. There's lots of "security advice" out there recommending doing exactly this. Plus, if you're missing a requirement when trying to set your password, the easiest thing to do is just append the missing requirement at the end. Especially if it's punctuation, which naturally goes at the end of words/sentences anyway.