Trump Twitter Was Hacked
bbc.co.uk
bbc.co.uk
It is very possible that this is just an article with limited info and not much has been released publicly because of privacy/security concerns.
Simply show me a video logging into the account in real time with the given password and the 'hacker' can eliminate this skepticism.
Quite funny how people can quickly believe this stuff on the internet without thinking again, especially from...
BBC online news... sigh.
Mr Gevers had told officers he had substantially
more evidence of the "hack".
An earlier article gives a little more detail, but nothing substantial. From https://www.bbc.com/news/technology-55019858 -- He did not post any tweets or change any settings, but
said he took screenshots of some parts of the
president's account.
If he has screenshots of private messages, etc, that would certainly prove he had access... but only if Trump or somebody with legit access to Trump's account was able and willing to verify them.Of course, I don't blame this researcher for lacking more concrete proof. He could easily have proved his access by changing something in Trump's account, sending a tweet/DM, etc. But by doing so he likely would have brought some serious legal issues down onto himself.
The problem with that theory is that he did heavily insinuate having posted a tweet from Trump's account.
...or the sender.
No matter what answer they gave, they'd look incompetent.
Why didn't they require 2FA (especially from him)?
Why didn't they have even more security precautions for his account that wouldn't have let just anyone even with his pw and 2FA log in?
Why didn't they have some way to detect and prevent a login from an unexpected location?
And if they did have these, it shows they were incompetent in devising or using these precautions.
Of course, if this intrusion actually happened, it's not just Twitter to blame. Whoever's on Trump's cybersecurity team also messed up, as they should have had extra precautions way above and beyond anything Twitter had.
This is the issue with the whole situation - Twitter is not an extension of the government. People can enable 2FA or not. That’s on them.
The fact that Trump uses it as his official podium is the problem, ultimately. I was worried that we’d see a declaration of war come from him announced on Twitter. The same service where I can see explicit porn right after it and where millions of keyboard warriors talk shit and troll.
But no, apparently washing their hands of it is more important than saving lives.
They checked that, according to his actions, he was within the bounds of the "coordinated vulnerability disclosure". A protective legal measure for whitehat hackers.
If he wasn't, then he could be sued for "hacking" and with malicious intent.
Source of my info was a dutch article ( the hacker is also dutch): https://tweakers.net/nieuws/175822/ethisch-hacker-wordt-niet...
( https://tweakers.net/partners/meet-up2020privacysecurity/127... )
More information about some of his findings are listed here https://gdi.foundation/#/news/README
Small extract:
> WeWork’s weak Wi-Fi security leaves sensitive documents exposed
> A huge database of Facebook users’ phone numbers found online
> China Intercepts WeChat Texts From U.S. And Abroad
> Over 90 Million Records Leaked by Chinese Public Security Department
> Unsecured MongoDB databases expose Kremlin’s backdoor into Russian businesses
Given Twitter is a broadcast medium, it would have been incredibly simple for him to provide incontrovertible proof rather than screenshots and a claim that he posted a tweet that is indistinguishable from the average Trump tweet.
https://www.politico.com/story/2016/12/donald-trump-technolo...
Second thought: But then, it's hard to think of something that an attacker could do with Trump's account that's worse than what he already does on a daily basis.