Twitter's Password Reset Morning

Twitter's Password Reset Morning

Tech News hacking passwords security twitter

So I opened Twitter this morning like I do every morning, coffee not even finished brewing yet, and instead of my feed I got the "please reset your password" wall. Figured it was just me being an idiot and typing my password wrong for the third time this week. Nope. Turns out Twitter itself put out a post last night called "Keeping our users secure," and the short version is: someone got into their systems and may have gotten live access to info for around 250,000 accounts before anyone noticed. Usernames, emails, session tokens, the encrypted/salted password data. Twitter's response was to reset all of those passwords and yank the session tokens so whoever was in there gets kicked back out.

What I actually appreciated, and this is rare for a corporate security post, is that they didn't try to make it sound smaller than it was. They flat out said this didn't look like some random script kiddie thing, that the sophistication suggested it wasn't an isolated incident, and they pointed at the string of other companies that have said the same thing in just the last couple days. The New York Times ran a big piece Wednesday about Chinese hackers being inside their network for months, reading reporters' emails, and the Wall Street Journal came out and said basically the same thing happened to them. So now Twitter's saying, yeah, us too, probably related infrastructure or techniques. That's a weird kind of honesty to see from a company with 200 million-plus users who mostly just want to post about what they had for lunch.

The part that got me was the advice at the bottom of their post: turn off Java in your browser. Not update it. Turn it off. Which, fine, I get it, there's been a genuinely nasty Java zero-day making the rounds since the start of the month and Homeland Security themselves told people to disable it a few weeks back. But it's a little funny to me that "disable an entire browser plugin" is where we've landed as mainstream security advice in 2013. That's not a fix, that's everyone quietly admitting Java's browser plugin has been a liability for years and nobody wants to say it plainly.

Anyway, I did the thing everyone tells you to do and never does, and actually changed my Twitter password to something that isn't a slight variation of the password I use on four other sites. I've been putting off setting up a real system for this for probably a year now. I keep meaning to try LastPass properly instead of just having it installed and ignored, but there's something about generating a 20-character string of garbage for a site where I mostly retweet articles about Django that feels excessive, right up until a morning like this one where it very much doesn't feel excessive.

None of this is the biggest tech story of the week, not with BlackBerry spending Wednesday trying to convince everyone that the Z10 and the whole BB10 relaunch is a real comeback and not a hail mary. I've got opinions on that too, mostly that a touchscreen keyboard with the little upward flick gesture is a neat trick that isn't going to save a company that's been bleeding market share for three straight years, but that's a post for another day when I've actually had hands on one.

What strikes me about the Twitter thing specifically is how normal it's starting to feel. A quarter million accounts getting compromised used to be the kind of headline that would've dominated a whole week. Now it's Friday morning news, people grumble about resetting a password, and by lunch everyone's back to posting like nothing happened. I don't know if that's resilience or just fatigue. Probably some of both. Either way I've got a new password now, it's actually good, and it's written down on an actual piece of paper in my desk drawer because apparently that's still the most reliable password manager I own.