Earlier quoted context omitted.
What are they going to do, kick him off? This man's account has been the singular reason for Twitter's relevance over the past four years.
2FA would be ideal, but GeoIP restriction requires no action on the part of the end-user. If implemented properly, Twitter should have been alerted that something was fishy when an IP from the Netherlands sent a successful login password and prevented it, then e-mailed the user to ask if the login attempt was legitimate. It saved my butt once when Gmail prevented an IP originating in India from logging into my accoun…
Trump's Twitter account hacked after Dutch researcher guessed password?
101–110 of 111 posts
Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#102Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#103Earlier quoted context omitted.
Two economists were walking down the street. The first one says: “Isn’t that a $20 bill?” The second one says: “Can’t be. If it were, somebody would have picked it up already.”
Saw a $20 on the ground in front of the elevators at a hedge fund last year. Lobby full of employees. True story.
Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#104As the "great hack" is destroying my trust in bloomberg, this article is destroying my trust in the guardian. There's no chance the password was "maga2020!"
Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#105Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#106Completely made up. Three submissions, ~50, ~100 and ~150 points in HN. Everyone having a laugh, no one cares for site rules. No moderation in sight. Everyone knows it's fake, no one cares. Rinse and repeat about three times a day over four years. Some of them make it into HN, each one makes in into the minds of thousands. But dare to defend truth and the cavalry is there in seconds.
Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#107Earlier quoted context omitted.
It's like having 12345 as the code on your luggage.
To be fair, there's really very little point to having a code for your luggage. The amount of added security it gives is laughable.
Like if you're traveling by rail and have your briefcase overhead and are snoozing, someone could just open it, take your laptop and disappear.
That's about the sum total of cases it's preventing. Not terribly useful, no.
Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#108wait, really? there is no two factor auth on his account? Actually, someone observed that while he was debating last time with Biden his account was tweeting. So it is sort of make sense - the password is likely shared which makes two factor auth hard.
Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#109The password format is surely the most common password pattern that everyone seems to have independently adopted
Whereby word & special character are set in stone (easy to remember) and the number just increments with every change.
If only there was a way to allow more flexible demands on passwords within MS AD, things would improve so much.
Password > 14 characters and NOT listed in Pwned Passwords == allow for passphrase to be used "forever"
Password Very decent source for Pwned Passwords https://haveibeenpwned.com/Passwords
Re: Trump's Twitter account hacked after Dutch researcher guessed password?
#110Earlier quoted context omitted.
It's not happening independently, it's cargo-culted. There's lots of "security advice" out there recommending doing exactly this. Plus, if you're missing a requirement when trying to set your password, the easiest thing to do is just append the missing requirement at the end. Especially if it's punctuation, which naturally goes at the end of words/sentences anyway.
I've taken to using random passwords for signup and password reset for each login, since that's what password guidelines eventually force me to do anyway.
And yet, none of these requirements are visible on the login page! So I have no freaking clue what my password might actually be, and thus my typical login flow for these lesser used accounts is always going through the password reset flow. It's a joke.