Technology content trusted by users in North America and around the world.
4,952 Articles | 29,865 Posts
Select Your Edition:  
Tweakipedia
A wealth of
tech information!

TRENDING NOW: Sony teases first look at PlayStation 4 hardware, says it will be shown at E3
USA EditionYou are located: Home > All News > Internet & Websites News > Twitter's password recovery process exposes accounts to hacking, according to victim

Twitter's password recovery process exposes accounts to hacking, according to victim

By: (more) | Internet & Websites News | Posted: Oct 1, 2012 10:01 pm

A victim of a hacker has written up a long piece regarding Twitter's security processes and how he believes he became a victim. Twitter's password recovery system is reportedly to blame, as it allowed a hacker to use a brute-force style attack on his handle. A brute-force attack tries common passwords as quickly as it can until it finds a match or exhausts a word list.

 

twitter_s_password_recovery_process_exposes_accounts_to_hacking_according_to_victim

 

The issue seems to stem from the fact that Twitter doesn't limit login attempts per account, rather they limit them per IP. What this means is a hacker just needs to use a proxy network or some other way of IP switching and they would be able to brute-force an account indefinitely, or at least until the password was found.

 

However, why the victim, Daniel Dennis Jones, had chosen to use a simple, common password that could be brute-forced is beyond me. His story makes sense, though, and is why most password recovery systems limit login attempts on a per account basis, or at minimum throw up a CAPTCHA after a few failed attempts at logging into an account.

 

The happy ending: Eventually Jones was able to recover his @blanket handle with the help of Twitter.


SOURCE #1

Related Tags



Further Reading: Read and find more Internet & Websites news at our Internet & Websites news index page.

TweakTown News RSS FeedDo you get our news RSS feed? Get It! Got a news tip? Tell Us!

Post a Comment about this news



Check out our
RSS feeds!
  • Upcoming Content: PQI Air Card 4GB Wi-Fi SDHC Review
  • Upcoming Content: LaCie CloudBox 1TB Personal NAS Review
  • Upcoming Content: Star Trek: The Next Generation - Season Three (1989) Blu-ray Review
  • Upcoming Content: The Hobbit: An Unexpected Journey (2012) Blu-ray Movie Review
  • Upcoming Content: Whatever happened to Comodo Time Machine?
  • Upcoming Content: SuperSpeed RamDisk Plus 11 Software Review
  • Upcoming Content: HP Envy TouchSmart 4 Touchscreen Ultrabook Laptop Review
  • Upcoming Content: MSI Radeon HD 7790 1GB OC Overclocked Video Card Review
  • Upcoming Content: ADATA DashDrive Elite UE700 USB 3.0 Flash Drive Review
  • Upcoming Content: Kingston DT Workspace 64GB 'Windows To Go' USB 3.0 Flash Drive Review
  • Upcoming Content: Lexar Professional 128GB Compact Flash Memory Card Review
  • Upcoming Content: MyDigitalSSD BP4 240GB mSATA Review


Internet & Websites News Posts

View More Internet & Websites News Posts


TweakTown Web Poll

Question: What new stuff are you most excited to see at Computex Taipei 2013?

Cases, Coolers & PSU’s

CPU's

Gadgets

GPU's & Video Cards

Keyboards & Mice

Laptops, Tablets & Phones

Motherboards & Chipsets

New Tech

SSD's & Memory

Booth Babes

or View the Results

View More Polls

Forum Activity

View More Forum Posts

Internet & Websites Press Releases

View More Internet & Websites Press Releases