Dutch Ethical Hacker Logs into Trump’s Twitter Account
volkskrant.nl
volkskrant.nl
[0] https://www.theguardian.com/us-news/2020/oct/22/trump-twitte...
I wouldn't dismiss it out of hand just yet.
Um, what? That would be exceptionally bad press for Twitter.
This is frankly not believable. Doesn't the Secret Service have a digital wing to secure such things?
(I think it was an iPhone vs Blackberry thing)
I haven’t looked into this story too deeply but I find it incredible on its face. If it is true then it’s an absolute shock and a wonder of wonders why it wasn’t compromised sooner.
https://www.theguardian.com/technology/2018/may/22/donald-tr...
> But Trump wanted to be able to tweet and call people at will—neither of which is a feature of either DMCC-S device. So initially, he stuck to using his personal phone. … But he continued to resist using a secure phone for calls, because that would have meant routing those calls through the WHCA switchboard, and reportedly continued to place calls from his own Android phone from the White House residence after hours.
But, he's currently using a dedicated iPhone for twitter.
https://arstechnica.com/information-technology/2018/05/trump...
Most people know better than to try and kick that beehive.
Twitter doesn’t exactly require 2FA for us serfs, but still in a lot of cases requires SMS confirmation.
(To answer the question, if we take as a basis that people excuse Hillary for not knowing an SMTP server under her desk wasn’t secure enough for email exchange with diplomats, we need to exclude the user in any case and make technology auto-secure by default).
Also, I’d claim any attempt to log on the Twitter account of the president should have been investigated like any guy who walks up to The White House and tries their home key on it. Although I don’t agree with USA’s extreme approach to security, I’m surprised the police was so lax on attempts at cracking the president’s passwords.
...Or did you think his social media team sent all those tweets? There's a few obvious ones but I believe the vast majority are straight from the orange mind itself!
I mean, he’s not one to either be careful or listen to expert advice, so it doesn’t really sound that out there.
Normal blue ticks have 2FA, _but they can turn it off if they want to_.
He's the sort of guy who, if you warned him not to touch a hot stove, would immediately slam both hands down on it because he thought you were insulting his manhood.
It is hard to imagine someone wouldn't have guessed that password before.
Unfortunately that screenshot alone can be edited to be faked and it is the only screenshot used as 'proof' that he was 'hacked'.
It that's the case then this can be easily dismissed as fake news. Such a shame it was spread from 'news sites' like the Guardian. Who checks the Factcheckers eh?
As andlarry writes in another comment, The Guardian seems to have a quote from Twitter denying the story, though: https://www.theguardian.com/us-news/2020/oct/22/trump-twitte...
Also, this story is unbelievable. As in I literally do not believe it.
>"He tries ‘maga2020!’ (short for make America great again) and suddenly finds himself in the Twitter account of the American President."
And then everyone clapped!
If his password was that obvious, one would assume it would be guessed almost instantaneously. Maybe it had just been changed from something un-guessable minutes before, or some glitch disabled 2FA?
What incentive do they have to not do something like this? Surely anyone with millions of followers isn't going to leave Twitter because of this requirement (new users might, hence only requiring it for accounts of a certain size)
https://techcrunch.com/2020/10/22/dutch-hacker-trump-twitter...
> In a statement, Twitter spokesperson Ian Plunkett said: “We’ve seen no evidence to corroborate this claim, including from the article published in the Netherlands today. We proactively implemented account security measures for a designated group of high-profile, election-related Twitter accounts in the United States, including federal branches of government.”
> Trump’s account is said to be locked down with extra protections after he became president, though Twitter has not said publicly what those protections entail. His account was untouched by hackers who broke into Twitter’s network in July in order to abuse an “admin tool” to hijack high-profile accounts and spread a cryptocurrency scam.
> A spokesperson for the White House and the Trump campaign did not immediately comment, but White House deputy press secretary Judd Deere reportedly said the story is “absolutely not true,” but declined to comment on the president’s social media security. A spokesperson for CISA did not immediately confirm the report.
“maga2020!” and no proof, ridiculous. Easy to believe something crazy if you want to believe it, I guess.
So it seems some choose to believe claims without the actual facts and evidence unfolding over time but what's clear on Twitter and in this comments section is the number of users having symptoms of TDS. At least wait a bit until this fully develops rather than believing unverified reports or claims. We're much better than this.
Truth* is stranger than fiction. Or at least funnier.
* Apparently not truth, see below. Interesting to some degree nonetheless.
> A hard disk owned by presidential candidate Joe Biden’s son was supposedly stolen or hacked – also because Hunter Biden used an easy to guess password (Hunter02). Gevers is familiar with leaked databases of old passwords and searched these for Hunter Biden’s data. After analysing these old databases, he felt that the information was incorrect. Hunter Biden used other passwords. Gevers: ‘I could tell that it wasn’t his password.’
So this is not truth. But what I don’t know is if Gevers just read that online from a jokester, or if Trump’s people are actually claiming this.
the internet was such a better place in the 90s. now if someone gets your password in 2020 they can basically destroy your credit and social reputation
>Gevers is familiar with leaked databases of old passwords and searched these for Hunter Biden’s data. After analysing these old databases, he felt that the information was incorrect. Hunter Biden used other passwords. Gevers: ‘I could tell that it wasn’t his password.’
It's much more insane to me that the President of the United States has a twitter account with no 2FA and the password 'maga2020'.
But it appears that twitter has even worse password protection policies.
The account was “hacked” by manually entering several different password ideas into Twitter’s login. The guy got it on the fifth try. Why not lock it down sooner?
Typical person: 5 tries and no 2FA, that's ok (I Guess)
President: 5 tries and no 2FA? Twitter shouldn't have applied same ol' same ol' policies.
Sometimes you need to provide differential security. After all, the president doesn't ride around in an unprotected car even though pretty much everyone else does.
Whether that’s actually ethical or not is a tangential discussion because the existence and application of term is not controversial.