[FSec] Twitter's Password Fails

Newsfeed

Nachrichtenbote
Let's say you want to hack Jack Dorsey's online banking account. Where to start? His username?

Challenging… his online banking username is a secret. But how about his Twitter account?

Oh, that's easy. It's @jack.

That's the problem with "social" usernames — they're meant to be known.

Twitter_Password_Jack01.png


Another problem, Twitter appears to validate e-mail addresses:

Twitter_Password_Jack02.png


Looks like nobody's home at [email protected]:

Twitter_Password_Jack03.png


Twitter's settings include an option to require "personal" infomation such as an e-mail or phone number:

Twitter_Password_Jack04.png


But that's less than useless if Twitter won't actually let you add your number:

Twitter_Password_Jack05.png


And just how "personal" is a phone number anyway?

Twitter_Password_Jack06.png


Two-factor authentication?

Sure.

But Twitter should first stop validating e-mail addresses.

And then maybe it could add an option to disallow logins via the publicly known username.
On 07/05/13 At 12:51 PM

Weiterlesen...
 
Zurück
Oben