Live data from Hacker News

Twitter said to be testing two-step security in wake of AP hack

crave.cnet.co.uk

11–20 of 27 posts

Re: Twitter said to be testing two-step security in wake of AP hack

#11
post #5

Two factor authentication is a funny thing in 2013. All computer users understand passwords (and the basics of password complexity/secrecy) at this point. That covers the "something you know" factor. Many users conceptually understand a "something you have/are" factor in the form of biometric scans or smartcards. Unfortunately, those approaches are not practical to deploy outside a controlled enterprise setting. On t…

I really, really wish you were right when you said "All computer users understand passwords [...]". I frequently end up doing a lot of support stuff for my father, and he's not really that old.

His line of work has him dealing with some pretty sensitive material, and a two-factor authentication is required for it... something that, when introduced, was a source for many calls and angry shouting. I could have deferred this to their tech people, but I'd much rather spare them the anguish. ;)

Bottom line: It's getting better, but you are still, unfortunately for us all, way too optimistic.

Re: Twitter said to be testing two-step security in wake of AP hack

#13
post #9

Maybe accounts for clients like the AP need not a two-factor system, but perhaps messages should only originate from a whitelisted set of IP addresses.

This isn't really a good solution for mobile phones which change IP address frequently.

Of course it isn't. But I can't imagine why the AP would want anyone to send tweets on their behalf from a mobile phone.

Maybe there isn't a single solution that meets the needs of every user.

Re: Twitter said to be testing two-step security in wake of AP hack

#14
post #9

Earlier quoted context omitted.

This isn't really a good solution for mobile phones which change IP address frequently.

Of course it isn't. But I can't imagine why the AP would want anyone to send tweets on their behalf from a mobile phone. Maybe there isn't a single solution that meets the needs of every user.

>But I can't imagine why the AP would want anyone to send tweets on their behalf from a mobile phone.

Reporters in the field? Especially in a breaking news situation where they want to be first.

Re: Twitter said to be testing two-step security in wake of AP hack

#15
I am surprised that Twitter has not used features for bigger customers like this as a monitizing strategy. When they used to have a user cap, they could have just charged companies or people to go over that cap. Same thing here, charge for two factor authentication. Maybe even charge for verified accounts.

Re: Twitter said to be testing two-step security in wake of AP hack

#16
Imagine logging in to services only using Google Glass. When prompted to log in, a temporary passcode pops up on Glass. I think it would make two-factor authentication much more streamlined and unobtrusive compared to having your phone beside you and opening an app just to log in.

Re: Twitter said to be testing two-step security in wake of AP hack

#17

A few years ago there was a strange byline on a few tweets from @spam, it said "by {username}" indicating that there was some sort of system allowing specific users to send tweets from a different account, here is a screenshot from January 2010: http://i.imgur.com/o0iVS.png Does anyone have any insight on why Twitter haven't implemented that sort of system (nominated accounts able to tweet from a corporate account) a…

Depends... Which is a worse attack vector: a single account with a shared password, or a shared account where each person has their own personal account password?

Twitter really needs shared accounts + required two-factor for the personal accounts.

Re: Twitter said to be testing two-step security in wake of AP hack

#18
post #2

Two-step authentication, especially for something as prominent as twitter, is always a good thing. So, kudos to them.

> kudos to them.

Kudos for being horribly late and reactive instead of proactive?

This should have been implemented long long ago imo. Though i do give them more slack than with all of our banking institutions that still don't offer two-factor. But these recent events show how importing two-factor(or security in general) for even things like social media are.

Re: Twitter said to be testing two-step security in wake of AP hack

#19
post #17

A few years ago there was a strange byline on a few tweets from @spam, it said "by {username}" indicating that there was some sort of system allowing specific users to send tweets from a different account, here is a screenshot from January 2010: http://i.imgur.com/o0iVS.png Does anyone have any insight on why Twitter haven't implemented that sort of system (nominated accounts able to tweet from a corporate account) a…

Depends... Which is a worse attack vector: a single account with a shared password, or a shared account where each person has their own personal account password? Twitter really needs shared accounts + required two-factor for the personal accounts.

At the very least it's better for auditing. If one of your employee's accounts is hacked to send a fake tweet you immediately know which one instead of potentially having no way to know.

Re: Twitter said to be testing two-step security in wake of AP hack

#20
post #14

Earlier quoted context omitted.

Of course it isn't. But I can't imagine why the AP would want anyone to send tweets on their behalf from a mobile phone. Maybe there isn't a single solution that meets the needs of every user.

>But I can't imagine why the AP would want anyone to send tweets on their behalf from a mobile phone. Reporters in the field? Especially in a breaking news situation where they want to be first.

Are you suggesting that there may be many AP reporters who are authorized to tweet on AP's behalf from the field, implying a total lack of editorial control (and probably a total lack of coordination as well)? I think that is very unlikely. I'd find it very hard to believe that there isn't a very well defined system in place to control all official correspondence.

They have a news desk that is staffed 24hrs per day. Surely a person there could monitor tweets or communications from reporters in the field. I'd even expect there to be a different individual with the keys to the Twittermachine.

Post reply on HN