Live data from Hacker News

Trump's Twitter account hacked after Dutch researcher guessed password?

theguardian.com

101–110 of 111 posts

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#101

Earlier quoted context omitted.

What are they going to do, kick him off? This man's account has been the singular reason for Twitter's relevance over the past four years.

2FA would be ideal, but GeoIP restriction requires no action on the part of the end-user. If implemented properly, Twitter should have been alerted that something was fishy when an IP from the Netherlands sent a successful login password and prevented it, then e-mailed the user to ask if the login attempt was legitimate. It saved my butt once when Gmail prevented an IP originating in India from logging into my accoun…

I realize the circumstances of the world have somewhat changed over the past several months, but its not implausible that the US President might travel.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#102

Earlier quoted context omitted.

why do you find it difficult?

It's like having 12345 as the code on your luggage.

To be fair, there's really very little point to having a code for your luggage. The amount of added security it gives is laughable.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#103
post #80

Earlier quoted context omitted.

Two economists were walking down the street. The first one says: “Isn’t that a $20 bill?” The second one says: “Can’t be. If it were, somebody would have picked it up already.”

Saw a $20 on the ground in front of the elevators at a hedge fund last year. Lobby full of employees. True story.

Naturally; any employee picking it up would be immediately fired, for disbelieving in efficient markets :)

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#104
post #83

As the "great hack" is destroying my trust in bloomberg, this article is destroying my trust in the guardian. There's no chance the password was "maga2020!"

This is the same guy who wandered around, maskless, unnecessarily having close personal contact with people, during a pandemic, and ended up in hospital on experimental drugs. Why would you assume he’d take security precautions?

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#105

There's no evidence in this story, I'd take it with a grain of salt.

The TechCrunch article has a screenshot from the profile editor: https://techcrunch.com/wp-content/uploads/2020/10/trump-acce...

This security researcher uses the Grammarly extension?

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#106
post #86

Completely made up. Three submissions, ~50, ~100 and ~150 points in HN. Everyone having a laugh, no one cares for site rules. No moderation in sight. Everyone knows it's fake, no one cares. Rinse and repeat about three times a day over four years. Some of them make it into HN, each one makes in into the minds of thousands. But dare to defend truth and the cavalry is there in seconds.

Do you have proof this is fake or is that just an assumption?

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#107
post #102

Earlier quoted context omitted.

It's like having 12345 as the code on your luggage.

To be fair, there's really very little point to having a code for your luggage. The amount of added security it gives is laughable.

It's basically just there to dissuade casual pickpocket/theft.

Like if you're traveling by rail and have your briefcase overhead and are snoozing, someone could just open it, take your laptop and disappear.

That's about the sum total of cases it's preventing. Not terribly useful, no.

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#108

wait, really? there is no two factor auth on his account? Actually, someone observed that while he was debating last time with Biden his account was tweeting. So it is sort of make sense - the password is likely shared which makes two factor auth hard.

Sharing 2FA is easy with a password manager, if you have the option of Authenticator app

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#109

The password format is surely the most common password pattern that everyone seems to have independently adopted

Since many companies must follow the rules set by one compliancy or another and these have demanded passwords to contain 3 of the 4 different groups of characters AND require changing said passwords every 3 months, most employees have been trained to use a number scheme along the lines of:

Whereby word & special character are set in stone (easy to remember) and the number just increments with every change.

If only there was a way to allow more flexible demands on passwords within MS AD, things would improve so much.

Password > 14 characters and NOT listed in Pwned Passwords == allow for passphrase to be used "forever"

Password Very decent source for Pwned Passwords https://haveibeenpwned.com/Passwords

Re: Trump's Twitter account hacked after Dutch researcher guessed password?

#110
post #90

Earlier quoted context omitted.

It's not happening independently, it's cargo-culted. There's lots of "security advice" out there recommending doing exactly this. Plus, if you're missing a requirement when trying to set your password, the easiest thing to do is just append the missing requirement at the end. Especially if it's punctuation, which naturally goes at the end of words/sentences anyway.

I've taken to using random passwords for signup and password reset for each login, since that's what password guidelines eventually force me to do anyway.

One of my huge pet peeves is when sites have really idiosyncratic password requirements, like they require the use of at least 1 punctuation characters (but it's from a limited subset of available punctuation characters), or uncommon requirements on length (I've seen both can't be longer than 10 characters and must be longer than 12).

And yet, none of these requirements are visible on the login page! So I have no freaking clue what my password might actually be, and thus my typical login flow for these lesser used accounts is always going through the password reset flow. It's a joke.

Post reply on HN