Trump's Twitter account hacked after Dutch researcher guessed password?
theguardian.com
theguardian.com
“We’ve seen no evidence to corroborate this claim, including from the article published in the Netherlands today. We proactively implemented account security measures for a designated group of high-profile, election-related Twitter accounts in the United States, including federal branches of government.”
https://techcrunch.com/2020/10/22/dutch-hacker-trump-twitter...
I'd be surprised if Twitter didn't have access logs. Anyway if his campaign team had the password, there may be nothing of value in those dms.
https://www.volkskrant.nl/nieuws-achtergrond/dutch-ethical-h...
Also, the guy has a history (well, both do). Gevers has got into numerous other accounts before, and uncovered some disturbing stuff - tracking of Chinese Muslims via facial recognition stuff in China for example.
https://www.vn.nl/trump-twitter-hacked-again/:
Gevers comes up with a plan to make sure that this time the White House responds. He refuses to say what he did exactly, but in a tweet that has now been removed, he alludes to the fact that he was the one to post the Babylon Bee tweet in Trump’s name. Shortly after, he posted a tweet in his own name, tagging Trump and Team Trump, saying the Babylon Bee-tweet could now be removed, as it had served its purpose.
“I am not saying I did it. But what if I was the one to post the tweet? Then Trump will need to either admit to never having read the Babylon Bee article and posting this bullshit tweet, OR he will need to acknowledge that someone else posted the tweet.”
Breaking into a Twitter account to prove it is poorly secured is one thing, posting a tweet is another. “I took things further this time because our previous report obviously didn’t have any effect”, says Gevers. “I hope that everything will now be resolved soon, and that mister Trump sends us a message. ‘Thank you for your work/report.’ That should suffice and will round up things for both cases.”
https://twitter.com/realDonaldTrump/status/13170445563287306...
Why not post a hash of a timestamped transaction on the blockchain? Wouldn't that be better for establishing credibility instead of this?
I kind of think it's a toss-up if this is true. I can believe Trump would use a very weak password and not apply 2fa, but I'm very surprised that Twitter's additional guard-rails for important accounts didn't prevent this.
Otherwise it can be easily dismissed as a fake screenshot, even if he 'did it' in the past.
It will be interesting to see how Victor Gevers responds.
edit: title is "You Should Probably Change Your Password! | Michael McIntyre Netflix Special" if you prefer to search on youtube yourself
Plus, if you're missing a requirement when trying to set your password, the easiest thing to do is just append the missing requirement at the end. Especially if it's punctuation, which naturally goes at the end of words/sentences anyway.
And yet, none of these requirements are visible on the login page! So I have no freaking clue what my password might actually be, and thus my typical login flow for these lesser used accounts is always going through the password reset flow. It's a joke.
azalea
> Your password needs to contain a number and a special character.
azalea1!
I can practically date my old passwords (for unimportant things) by this, and/or how many times I forgot it and had to set a new, unique password.
<word> <special char> <number>
Whereby word & special character are set in stone (easy to remember) and the number just increments with every change.
If only there was a way to allow more flexible demands on passwords within MS AD, things would improve so much.
Password > 14 characters and NOT listed in Pwned Passwords == allow for passphrase to be used "forever"
Password < 14 characters OR listed in Pwned Passwords == demand (regular|immediate) change.
Very decent source for Pwned Passwords https://haveibeenpwned.com/Passwords
Whether or not this is true, Twitter definitely needs to start having multi-user functionality. Beyond TweetDeck Teams.
All this guy did was get in and then called the authorities, so he probably didn't 'intend to defraud'. If he tweeted something, which he alludes to in some articles, that might be a felony.
IANAL, get a lawyer if you are into hacking
Another “covfefe” perhaps? An innocent “ALL CAPS DAY” maybe? Or just a simple “;)”? And these are harmless examples. A targeted reference to certain prophets or Winnie the Pooh would have vast consequences.
I could have set the world alight for laughs.
And to think no extra measures were put in place by Twitter is shocking.
Like if you're traveling by rail and have your briefcase overhead and are snoozing, someone could just open it, take your laptop and disappear.
That's about the sum total of cases it's preventing. Not terribly useful, no.
* Letters - check
* Numbers - check
* Special symbols - check
So the new, secure, password should be Maga2020!
I am gobsmacked that Twitter allowed his account to continue without some kind of additional security measures like 2FA or geo-IP checking. This is a guy that could literally start World War III by sending a tweet like, "Eat shit, China! Missiles on their way!" And Twitter didn't think it should be locked down beyond a simple password!?!
I mean remember how bitcoin scammers got access to Twitter admin panels recently? I don't think security is Twitter's biggest concern... My old Twitter account has been hacked by a Russian spammer despite having 2FA, I just decided to close it, it became a liability.
There is absolutely no evidence in the article (not even links or screenshots of his tweet reaching out to the White House).
Furthermore I can't believe Trump's account is even going through regular authentication mechanisms. It should be trivial to restrict access to an account to certain address ranges of a government VPN.
https://www.politico.com/story/2018/05/21/trump-phone-securi...
I can't really see a situation where the need for "authenticity" of a person/account meets the bar for needing verification, but not be considered important enough for basic security practices.
Force 2FA on your most high-profile customers, and your support costs skyrocket as a steady stream of these customers who didn't want this new and (relatively) complicated measure forget or lose their 2FA setup, and you find yourself constantly resetting it or changing it, which probably in the long term reduces the effectiveness of it since it becomes a routine for your support operation and it's easier for bad actors to fake it.
Until these kinds of problems affect their brand enough to cause financial harm, don't hold your breath for higher security and accountability measures by default.
People lose or break their phones often enough. It is a routine thing in an organisation of just 120 people. Now imagine that instead of an educated and selective group, you are dealing with a pool of desperately partying, drunk globetrotting influencers, political figures with Neanderthal technical skills or other walking security disasters.
How often do you think account recovery due to lost 2FA would be triggered?
For proper protection you need hardware 2FA, and for usability reasons you really need the NFC enabled Yubikey so the same second factor can be neatly enforced on a mobile phone too. But you can't have just one. If the access is for anything non-trivial or of high importance, you need at least two such devices. Preferably three.
That's a lot of Yubikeys you need to subsidise, because most people sure as hell are not buying them out of their own pocket.
I would expect that if the identity of the account owner has already been verified, the account recovery process in this situation would be much more straight forward than a non-verified user.
I'll never understand how some of the brightest minds of our generation can end up following this guy. I understand we're seeing confirmation bias => brainwashing en mass, but people on this site should be smart enough to break out of the cycle
for(code blocks) { ... }
Yep, that worked.