Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Community > MacNN Lounge > Twitter Attack Vectors?

Twitter Attack Vectors?
Thread Tools
subego
Clinically Insane
Join Date: Jun 2001
Location: Chicago, Bang! Bang!
Status: Offline
Reply With Quote
Feb 25, 2014, 05:37 PM
 
Had a friend who's twitter account got hacked yesterday, and I'm trying to figure out how it happened.

I'm hip to virus tweets, but this person doesn't really use twitter, so I don't see it having happened that way.

Any ideas?
     
starman
Clinically Insane
Join Date: Jun 2000
Location: Union County, NJ
Status: Offline
Reply With Quote
Feb 25, 2014, 06:16 PM
 
His password was probably 12345

But seriously, it could have happened through getting his email account hacked. I don't have an answer. Just make sure you have two-factor auth on your Twitter acct.

Home - Twitter - Sig Wall-Retired - Flickr
     
subego  (op)
Clinically Insane
Join Date: Jun 2001
Location: Chicago, Bang! Bang!
Status: Offline
Reply With Quote
Feb 25, 2014, 06:37 PM
 
I'd be surprised if her password was any good, but do people actually still try brute force login attacks?
     
starman
Clinically Insane
Join Date: Jun 2000
Location: Union County, NJ
Status: Offline
Reply With Quote
Feb 25, 2014, 06:53 PM
 
Years ago Twitter allowed it, and then shut that down. I only read about things as people write about them, so I don't know anything past that. There are other ways - like using the same password on Twitter as another site that got hacked. That's why all my passwords are different.

Home - Twitter - Sig Wall-Retired - Flickr
     
subego  (op)
Clinically Insane
Join Date: Jun 2001
Location: Chicago, Bang! Bang!
Status: Offline
Reply With Quote
Feb 25, 2014, 07:01 PM
 
This person has poor password hygiene, but I'm assuming twitter is the only account compromised because they used it for a phishing attack. If they had multiple accounts on this person, I'd assume they'd want to leverage those accounts, or look for more, rather than burn the asset looking for more twitter accounts to compromise.
     
starman
Clinically Insane
Join Date: Jun 2000
Location: Union County, NJ
Status: Offline
Reply With Quote
Feb 26, 2014, 01:01 AM
 
Question: was their account actually attacked, or did they have a third-party app with access to their Twitter account doing this?

Home - Twitter - Sig Wall-Retired - Flickr
     
subego  (op)
Clinically Insane
Join Date: Jun 2001
Location: Chicago, Bang! Bang!
Status: Offline
Reply With Quote
Feb 26, 2014, 01:43 AM
 
No idea. I'm assuming the former.
     
starman
Clinically Insane
Join Date: Jun 2000
Location: Union County, NJ
Status: Offline
Reply With Quote
Feb 26, 2014, 01:57 AM
 
Ok, because a third party app can use your Twitter ID to send spam as well. Changing your password won't fix the issue.

Home - Twitter - Sig Wall-Retired - Flickr
     
subego  (op)
Clinically Insane
Join Date: Jun 2001
Location: Chicago, Bang! Bang!
Status: Offline
Reply With Quote
Feb 26, 2014, 04:39 AM
 
I'll check into that. Thanks, BTW!
     
andi*pandi
Moderator
Join Date: Jun 2000
Location: inside 128, north of 90
Status: Offline
Reply With Quote
Feb 26, 2014, 10:47 AM
 
my twitter was hacked, and I had a decent password. Don't recall if I ever knew the cause, just changed passwords. I use a "base" plus "codeword" system. It was sending spam to my contacts via PM.
     
subego  (op)
Clinically Insane
Join Date: Jun 2001
Location: Chicago, Bang! Bang!
Status: Offline
Reply With Quote
Feb 26, 2014, 05:49 PM
 
I use 1Password, but it's too quirky for me to feel comfortable handing it over to a muggle.

You're a wizard, Andi. You can totally handle it. I highly recommend you get either that or LastPass. LastPass is cheaper.
     
starman
Clinically Insane
Join Date: Jun 2000
Location: Union County, NJ
Status: Offline
Reply With Quote
Feb 26, 2014, 05:54 PM
 
LastPass is cheaper but doesn't have the same encryption functions 1Password does. 1Password wins in my book.

EDIT: Mavericks has a password storage system as well, but I'm still running 10.8 so I don't know how well it works.

Home - Twitter - Sig Wall-Retired - Flickr
     
andi*pandi
Moderator
Join Date: Jun 2000
Location: inside 128, north of 90
Status: Offline
Reply With Quote
Feb 26, 2014, 07:01 PM
 
apparently I bought 1Password with a macupdate bundle in 2011. Huh. Ok then.

Do you all use the dropbox sync for the data file, or does that defeat the purpose?
( Last edited by andi*pandi; Feb 26, 2014 at 07:20 PM. )
     
subego  (op)
Clinically Insane
Join Date: Jun 2001
Location: Chicago, Bang! Bang!
Status: Offline
Reply With Quote
Feb 26, 2014, 08:00 PM
 
Use the DropBox sync. The keychain is encrypted.
     
turtle777
Clinically Insane
Join Date: Jun 2001
Location: planning a comeback !
Status: Offline
Reply With Quote
Feb 26, 2014, 11:47 PM
 
Same here, 1PW with Dropbox.

-t
     
starman
Clinically Insane
Join Date: Jun 2000
Location: Union County, NJ
Status: Offline
Reply With Quote
Feb 27, 2014, 01:32 AM
 
1PW w/Dropbox FTW.

Home - Twitter - Sig Wall-Retired - Flickr
     
subego  (op)
Clinically Insane
Join Date: Jun 2001
Location: Chicago, Bang! Bang!
Status: Offline
Reply With Quote
Feb 27, 2014, 07:07 AM
 
I suggest you use the DropBox.
     
   
 
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Top
Privacy Policy
All times are GMT -4. The time now is 03:53 PM.
All contents of these forums © 1995-2017 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2017, Jelsoft Enterprises Ltd.,