Live data from Hacker News

Twitter Hacker Says Admin Password Was 'Happiness'

blog.wired.com

1–10 of 44 posts

Re: Twitter Hacker Says Admin Password Was 'Happiness'

#2
He also realized he hadn't used a proxy to hide his IP address, potentially making him traceable. He didn't think the intrusion was important draw for law-enforcement attention, and "didn't think it would make headlines.

I don't understand how he thought hi-jacking Obama, Britney and Fox News twitter accounts wouldn't make headlines.

Re: Twitter Hacker Says Admin Password Was 'Happiness'

#3
This is again a reason why you shouldn't make accessing internal company services too easy. Yeah, it can be a pain but once someone figures out a little piece of the puzzle, they can run amok in your network. In hindsight, tying customer service methods to employee Twitter accounts was the big mistake.

Re: Twitter Hacker Says Admin Password Was 'Happiness'

#4
post #2

He also realized he hadn't used a proxy to hide his IP address, potentially making him traceable. He didn't think the intrusion was important draw for law-enforcement attention, and "didn't think it would make headlines. I don't understand how he thought hi-jacking Obama, Britney and Fox News twitter accounts wouldn't make headlines.

He didn't hijack those accounts; he gave out the credentials in a forum thread and others jumped on it.

Re: Twitter Hacker Says Admin Password Was 'Happiness'

#5

This is again a reason why you shouldn't make accessing internal company services too easy. Yeah, it can be a pain but once someone figures out a little piece of the puzzle, they can run amok in your network. In hindsight, tying customer service methods to employee Twitter accounts was the big mistake.

Sure was a heck of a guess to end up with a staffer.

Re: Twitter Hacker Says Admin Password Was 'Happiness'

#7
This does bring up a good tech question -- how do you prevent people from doing a rapid password attack?

Anyone have an article or some ideas on how this could be done? Is limiting attempts the simplest way?

Even if you do limits, aren't these session-based? I'm guessing a cracker isn't going to respect sessions.

Re: Twitter Hacker Says Admin Password Was 'Happiness'

#8
post #2

He also realized he hadn't used a proxy to hide his IP address, potentially making him traceable. He didn't think the intrusion was important draw for law-enforcement attention, and "didn't think it would make headlines. I don't understand how he thought hi-jacking Obama, Britney and Fox News twitter accounts wouldn't make headlines.

He didn't hijack those accounts; he gave out the credentials in a forum thread and others jumped on it.

Technically you're correct, but by giving out the credentials in a public forum he should have known better.

Re: Twitter Hacker Says Admin Password Was 'Happiness'

#9
This is why ideally you only make your admin tools available on your private network, accessible only via VPN. The very minimum is restricting access to admin functionality to specific IP addresses.

Limiting password check attempts is important too, but if all a bad guy could get access to is user accounts the damage is significantly less.

Re: Twitter Hacker Says Admin Password Was 'Happiness'

#10
post #8

Earlier quoted context omitted.

He didn't hijack those accounts; he gave out the credentials in a forum thread and others jumped on it.

Technically you're correct, but by giving out the credentials in a public forum he should have known better.

DG is an unique place.
Post reply on HN