What Is True/Slant?
275+ knowledgeable contributors.
Reporting and insight on news of the moment.
Follow them and join the news conversation.
 

Jul. 17 2009 - 9:57 am | 48 views | 0 recommendations | 5 comments

Were Twitter employees tweeting their porn names?

Image representing Twitter as depicted in Crun...

Image via CrunchBase

I’ve written before about the hazards of weak passwords. See: ‘Porn Name’ game part of devious plot to steal your money and identity.

Essentially, most of us have terribly uncreative passwords — often based on our addresses, our birthdays and anniversaries, and the names of our pets and children — making it easy for someone with a lot of time and a lot of curiosity to break into our accounts.

Twitter was burned by the weak password phenomenon this week. A hacker broke into the personal accounts of a number of Twitter employees as well as the Gmail account of the Twitter CEO’s wife, by guessing or cracking their passwords. “Hacker Croll” accessed hundreds of sensitive documents and then leaked them to blogs, including TechCrunch, which has chosen to publish some of the documents.

Having exploited these weak links, [Hacker Croll] apparently used Web sites’ password-retrieval features to get passwords for other accounts, including Google Apps, in a technique known as hopping….

The breach has shone a bright light on the security of confidential data that we store in increasingly popular “cloud” services like webmail accounts and Google Apps, where data can be accessed from any computer, typically with just a username and password. But with this convenience comes extra risk.

It’s also a vivid example of how our choices about how we protect our personal accounts – or don’t -– can have serious consequences for our family members and our employers. It turns out not to be just a personal choice — we put others at risk, too.

via Twitter Gets Hacked. Can It Happen to You? – Gadgetwise Blog – NYTimes.com.

Gadgetwise offers some tips on strengthening the protections around your online data, including using different passwords for different accounts and picking strong passwords.

The question of course is whether our desire for privacy and security will outweigh our laziness. Using a variation of one password for all of your accounts is definitely stupid, but it sure does make life easy. That is, until your accounts get hacked.


Comments

2 T/S Member Comments Called Out, 5 Total Comments
Post your comment »
 
  1. collapse expand

    A password I’ve used for a while now, which I use for several accounts (oops), is phrase reflecting a philosophical belief system of mine comprised of upper and lower case letters, numbers and underscores with some of the words missing a vowel or consonant or two. If anyone’s trying to hack my accounts, there’s your clue!

  2. collapse expand

    My first Facebook password was ‘facebook’. I once posted a status update in the third person stating just that, and several people contacted me saying that theirs too had at some point been ‘facebook’. None of us had been hacked, which puzzled me, and still does. Can a password be so-obvious that it’s secure?

Log in for notification options
Comments RSS

Post Your Comment

You must be logged in to post a comment

Log in with your True/Slant account.

Previously logged in with Facebook?

Create an account to join True/Slant now.

Facebook users:
Create T/S account with Facebook
 

My T/S Activity Feed

 
     

    About Me

    I am a writer, reporter, editor and blogger. I'm an editor at Above The Law, where I blog about lawyers, judges, law firms and the legal industry. Here at True/Slant, I write about our changing notions of privacy.

    If you have story ideas or tips, e-mail me at kashhill@trueslant.com. I've hung out in quite a few newsrooms over the last few years. Currently, I can be found in Breaking Media's Nolita office. In the past, I've been found in midtown Manhattan at The Week Magazine, in Hong Kong at the International Herald Tribune, and in D.C. at the National Press Foundation and the Washington Examiner.

    I have few illusions about privacy -- feel free to follow me on Twitter: kashhill. Or friend me on Facebook... though I might put you on limited profile.

    See my profile »
    Followers: 401
    Contributor Since: March 2009
    Location:New York, NY

    What I'm Up To

    • Staying Above The Law

      judge

      Over at Above The Law, I write about lawyers, law firms, judges and the legal industry.

      We especially like “colorful news.” (Yes, that’s a euphemism for gossip.)

      Check out the site here and my stuff here.

      logo

       
    • Writing with real ink

      While most of my writing occurs online at Above The Law and True/Slant, I do occasionally venture into the world of print.  These are some of the magazines and newspapers that I’ve written for:

      The Washington Post

      Washingtonian Magazine

      Time Out New York

      The Orange County Register

      The Washington Examiner

       
    • Recent projects

      washingtonian issue for tsThe latest (and longest) “real ink” project: the cover story for Washingtonian Magazine’s December issue.

      While I’m usually a writer and reporter, I’m sometimes asked to play pundit. In November, the New York Times asked me to write a mini op-ed for its Room for Debate blog. In December, BBC radio asked me to talk about Mark Zuckerberg and Facebook privacy settings for its Newshour (19:00 minute mark), based on this True/Slant post.

       
    .<
    • +O
    • +O
    • +O
    >.