<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Léoville - Latest Comments in Twitter Hacked</title><link>http://leolaporte.disqus.com/</link><description>The personal blog of technology pundit Leo Laporte</description><atom:link href="https://leolaporte.disqus.com/twitter_hacked/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Wed, 21 Jan 2009 17:22:37 -0000</lastBuildDate><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-5448037</link><description>&lt;p&gt;O'Reilly's membership would be rejected&lt;/p&gt;&lt;p&gt;we would not want to be associated with him&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">MarcC</dc:creator><pubDate>Wed, 21 Jan 2009 17:22:37 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-5010448</link><description>&lt;p&gt;Twitter broke some very simple security rules: enforce complex passwords (especially for your admin accounts), and lock an account out after a certain number of failed attempts.  The hacker used a simple dictionary password attack to break in.&lt;/p&gt;&lt;p&gt;What I really find deplorable is John's comment that obtaining the hacked users' real e-mail address from a backup would be "very time consuming."  I think the very least you'd want to do for your most prominent users is to send them a new password so they can get back on Twitter ASAP.  I'd understand if it were the hacked users that chose poor passwords, but it was Twitter's own staff that provided the security hole.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">artanis</dc:creator><pubDate>Fri, 09 Jan 2009 08:20:45 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4971767</link><description>&lt;p&gt;twitter been hacked? very scary about that thing happen. admin area is very sensitive and need to give an extra security after this. you can learn more to get a good care about security admin after this. keep it a good job team twitter....&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">My Inventory Management</dc:creator><pubDate>Wed, 07 Jan 2009 20:14:17 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4944667</link><description>&lt;p&gt;Who's asking the questions? It doesn't sound like Leo's voice &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ulricr</dc:creator><pubDate>Tue, 06 Jan 2009 20:54:44 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4943739</link><description>&lt;p&gt;Too bad, really. I was psyched that O'reilly had finally come out...&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">J.R. Orci</dc:creator><pubDate>Tue, 06 Jan 2009 19:43:31 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4938664</link><description>&lt;p&gt;Wish they would have posted that I got lucky. :-)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Hoosierguy</dc:creator><pubDate>Tue, 06 Jan 2009 15:56:39 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4937635</link><description>&lt;p&gt;While we're at it, there is a secondary and far more widespread issue here with many of the services in the twitter ecosystem requiring you to hand over your username and password. Many do so without a second thought, and since people are often lazy with passwords this could lead to much upset.&lt;/p&gt;&lt;p&gt;Services which require you to hand over the virtual keys to your house to work are always going to be problematic - a possibly reason why the facebook platform has been deprecated.&lt;/p&gt;&lt;p&gt;Perhaps now is a good time for twitter to push towards using something like OAuth?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Marcus Povey</dc:creator><pubDate>Tue, 06 Jan 2009 14:56:40 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4933668</link><description>&lt;p&gt;Not to get too far off topic, but....&lt;/p&gt;&lt;p&gt;When will the rest of us be able to get Qik for our iPhones.  Seems like it has been "Coming Soon" for 6 months now...&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bryan</dc:creator><pubDate>Tue, 06 Jan 2009 10:33:21 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4933339</link><description>&lt;p&gt;It's working for me, but I get that error a lot, outta the blue, even on apples website when they embed .movs etc.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ChrisTheFeral</dc:creator><pubDate>Tue, 06 Jan 2009 10:09:49 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4932654</link><description>&lt;p&gt;I really appreciated your openess, John. It's good to know what actually happened.&lt;/p&gt;&lt;p&gt;The full conversation is on Qik: &lt;a href="http://qik.com/twit#v=813128" rel="nofollow noopener" target="_blank" title="http://qik.com/twit#v=813128"&gt;http://qik.com/twit#v=813128&lt;/a&gt; (along with other videos of the revelry last night) Our conversation begins about 3 minutes in at the 10:00 mark. It was good meeting you too - sorry about the camera work!!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">leolaporte</dc:creator><pubDate>Tue, 06 Jan 2009 09:01:17 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4932649</link><description>&lt;p&gt;Britney Spears' account also got hacked. I read her latest tweet and definately did a double take. I screen captured it before it dissapeared 18 minutes later.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jonathan</dc:creator><pubDate>Tue, 06 Jan 2009 08:59:12 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4932457</link><description>&lt;p&gt;it is no different to what people using windows operating system have been exposed to over the last few decades - with popularity comes traffic and an urge from those of the dark side of the force to corrupt and get some kind of status kick out of it.    it should be expected as a by product of success.&lt;/p&gt;&lt;p&gt;Always someone out there wanting you to fall. :)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">phil campbell</dc:creator><pubDate>Tue, 06 Jan 2009 08:35:45 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4930562</link><description>&lt;p&gt;Leo has cut out some of the discussion I had with him here, but, basically, an admin tool was abused allowing a rogue user to modify some accounts on Twitter. As described in our status blog at &lt;a href="http://status.twitter.com" rel="nofollow noopener" target="_blank" title="status.twitter.com"&gt;status.twitter.com&lt;/a&gt;, we have modified our site to restrict admin privileges to appropriate users and to prevent the abuse that allowed this attack to occur.&lt;/p&gt;&lt;p&gt;Please understand that our staff is on the job and we will do all we can to protect our users, and have dedicated a team of engineers to this issue.&lt;/p&gt;&lt;p&gt;Nice meeting you this evening, Leo.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netik</dc:creator><pubDate>Tue, 06 Jan 2009 03:16:39 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4930469</link><description>&lt;p&gt;Well, I'm not one of the famous people and my account was hacked too. Not once but twice in 1 day. &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">cntrysigns</dc:creator><pubDate>Tue, 06 Jan 2009 03:03:22 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4930453</link><description>&lt;p&gt;Holy Moly!  That is seriously scary.&lt;/p&gt;&lt;p&gt;On a similar note, I've seen some of the most popular UStreamers get hacked in the past week.  I wonder what is in the air lately?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">SuzannadannaTARDIS</dc:creator><pubDate>Tue, 06 Jan 2009 03:01:11 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4930387</link><description>&lt;p&gt;Remember the 17 year old kid that took down Yahoo?  These challenges are candy for hackers &lt;a href="http://www.dennismoran.org/media/stacks.msnbc.com/news/376219.html" rel="nofollow noopener" target="_blank" title="http://www.dennismoran.org/media/stacks.msnbc.com/news/376219.html"&gt;http://www.dennismoran.org/...&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">SoniaT</dc:creator><pubDate>Tue, 06 Jan 2009 02:54:04 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4930177</link><description>&lt;p&gt;A lesson for anyone building Internet-accessible applications: make admin security one of your highest priorities. There are ways to make hacker attacks much less likely; now that Twitter have presumably fixed the issue, I'd love to hear the details. It'd surely be useful and interesting to anyone building or running an app, and therefore make everyone's web presences just that little bit safer.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ben Werdmuller</dc:creator><pubDate>Tue, 06 Jan 2009 02:30:46 -0000</pubDate></item><item><title>Re: Twitter Hacked</title><link>http://leoville.com/2009/01/05/21740/#comment-4927495</link><description>&lt;p&gt;I see a big ? instead of a Quicktime movie.&lt;/p&gt;&lt;p&gt;(FF nightly, OSX, Quicktime 7.5.5)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ryan Doherty</dc:creator><pubDate>Tue, 06 Jan 2009 02:03:31 -0000</pubDate></item></channel></rss>