4 ms·
Trump had a hilariously bad password. But it appears that twitter has even worse password protection policies. The account was “hacked” by manually entering s
by webel0 6y ago
Trump had a hilariously bad password.
But it appears that twitter has even worse password protection policies.
The account was “hacked” by manually entering several different password ideas into Twitter’s login. The guy got it on the fifth try. Why not lock it down sooner?
- nicoburns 6y agoBefore 5 attempts? That's well within the range of a few careless typos. If he'd tried thousands of attempts then sure, but 5 seems completely reasonable.
- Jorsiem 6y agoHe had a password you could guess in 5 tries and didnt have 2FA and your blaming Twitter?
- sheepdestroyer 6y agoI find the hacker mischievously hilarious : "The question remains why Trump was using such a weak and simple password. Gevers has a possible explanation: ‘Trump is over 70 – elderly people often switch off two-step verification because they find it too complicated."
- rexreed 6y agoYes. Twitter shouldn't treat a random person's account the same way they treat someone who wields a ridiculous amount of power and influence. Typical person: 5 tries and no 2FA, that's ok (I Guess) President: 5 tries and no 2FA? Twitter shouldn't have applied same ol' same ol' policies. Sometimes you need to provide differential security. After all, the president doesn't ride around in an unprotected car even though pretty much everyone else does.
- xenospn 6y agoIf you ever had to manage a site that had user accounts, you'd have realized that locking down access before the 5th attempt is a recipe for an insane amount of user frustration.
- pelliphant 6y agoIf I got locked out from any of my accounts for just typing in the wrong password 5 times, a few seconds apart, I would get kinda pissed.
- 0xffff2 6y agoBecause that's a thing that you do regularly? I would like for all of my accounts to at least start massively rate limiting me after 2 or 3 failed attempts. I honestly can't remember the last time I mistyped a password 3 times in a row, especially because it's increasingly rare that I actually have to type the password in by hand.