It will be interesting to see how Victor Gevers responds.
I kind of think it's a toss-up if this is true. I can believe Trump would use a very weak password and not apply 2fa, but I'm very surprised that Twitter's additional guard-rails for important accounts didn't prevent this.
Otherwise it can be easily dismissed as a fake screenshot, even if he 'did it' in the past.
https://www.volkskrant.nl/nieuws-achtergrond/dutch-ethical-h...
Also, the guy has a history (well, both do). Gevers has got into numerous other accounts before, and uncovered some disturbing stuff - tracking of Chinese Muslims via facial recognition stuff in China for example.
https://www.vn.nl/trump-twitter-hacked-again/:
Gevers comes up with a plan to make sure that this time the White House responds. He refuses to say what he did exactly, but in a tweet that has now been removed, he alludes to the fact that he was the one to post the Babylon Bee tweet in Trump’s name. Shortly after, he posted a tweet in his own name, tagging Trump and Team Trump, saying the Babylon Bee-tweet could now be removed, as it had served its purpose.
“I am not saying I did it. But what if I was the one to post the tweet? Then Trump will need to either admit to never having read the Babylon Bee article and posting this bullshit tweet, OR he will need to acknowledge that someone else posted the tweet.”
Breaking into a Twitter account to prove it is poorly secured is one thing, posting a tweet is another. “I took things further this time because our previous report obviously didn’t have any effect”, says Gevers. “I hope that everything will now be resolved soon, and that mister Trump sends us a message. ‘Thank you for your work/report.’ That should suffice and will round up things for both cases.”
https://twitter.com/realDonaldTrump/status/13170445563287306...
Why not post a hash of a timestamped transaction on the blockchain? Wouldn't that be better for establishing credibility instead of this?
I'd be surprised if Twitter didn't have access logs. Anyway if his campaign team had the password, there may be nothing of value in those dms.