Live data from Hacker News

Twitter Hacker Says Admin Password Was 'Happiness'

blog.wired.com

41–44 of 44 posts

Re: Twitter Hacker Says Admin Password Was 'Happiness'

#41
post #28

Earlier quoted context omitted.

I don't understand how he thought hi-jacking Obama, Britney and Fox News twitter accounts wouldn't make headlines. He was hijacking a random account on some totally unknown site called twitter. I know this is hard to grasp outside the valley, but most people have not ever heard about twitter and will probably assume it's about as important to the internet as zombo.com.

Actually CNN mentions Twitter quite often and especially during the elections a lot of people started hearing of Twitter way outside of the valley. If my parents learned about Twitter from watching TV I assume it's a safe bet that many other people have as well.

The last sentence of the article:

   "He said he'd never even heard of Twitter until he saw someone mention it on YouTube. "

Re: Twitter Hacker Says Admin Password Was 'Happiness'

#42

Earlier quoted context omitted.

You don't lockout the account, you lockout the attacking client, typically by IP address. It still allows the attacked accounts access from non-attacking IP addresses.

and if the attacking client is someone sitting on the corporate internet? way to block the entire corp from logging in ...

I would think that if you have an attacker on the intside of your corporate network trying to brute force accounts on an external service, you have wayyy more problems than locking out everyone else from the corporate network.

And I still don't care if everyone else on your network can't access my service; until you find the hacker and put a stop to it, why should I have any trust in your network address? The street goes both ways here.

Re: Twitter Hacker Says Admin Password Was 'Happiness'

#43

Earlier quoted context omitted.

and if the attacking client is someone sitting on the corporate internet? way to block the entire corp from logging in ...

It seems like the three main strategies are locking the account, blocking the IP, or forcing a password reset. What if instead, the account login name automatically got changed after a few missed attempts but the password remained the same. That would get around the DoS problem and also the corporate IP / AOL problem.

what? wouldn't that mean that anyone could try to log in to barackobama n times, get his login name changed, and then get barackobama's name?

You wouldn't get his followers, but you'd get a premium name easy.

Re: Twitter Hacker Says Admin Password Was 'Happiness'

#44

Earlier quoted context omitted.

It seems like the three main strategies are locking the account, blocking the IP, or forcing a password reset. What if instead, the account login name automatically got changed after a few missed attempts but the password remained the same. That would get around the DoS problem and also the corporate IP / AOL problem.

what? wouldn't that mean that anyone could try to log in to barackobama n times, get his login name changed, and then get barackobama's name? You wouldn't get his followers, but you'd get a premium name easy.

That assumes that the login name is the same as the account name.
Post reply on HN