Got My Twitter Password Reset This Morning

Got My Twitter Password Reset This Morning

Tech News hacking java passwords security twitter

So I woke up Friday to a very cheerful email from Twitter telling me my password had been reset "as a precaution." No explanation up front, just a login screen and a little "we care about your security" vibe. Turns out they'd disclosed that morning that around 250,000 accounts had their usernames, emails, and hashed/salted passwords accessed by attackers who they said were "extremely sophisticated." Bob Lord, their security director, put up a post called "Keeping our users secure" that read like it was written by a lawyer standing next to an engineer who kept trying to grab the keyboard.

I wasn't mad about the reset itself. Getting logged out and having to type a new password into my phone with my thumbs is a minor annoyance, not a tragedy. What got me was the line buried near the bottom recommending everyone disable Java in their browsers, "as a precaution," because whatever got into Twitter's systems reportedly touched machines that had Java running. I've been saying for over a year now that the Java browser plugin should just die already, and this is basically Twitter agreeing with me in the most roundabout corporate way possible. There was a zero-day in Java back in January bad enough that Oracle pushed an emergency patch, and the Department of Homeland Security told people to just turn the thing off entirely if they didn't need it for anything. Most people dont need it for anything. I turned mine off back then and havent missed it once, not for banking sites, not for anything.

What made this week weirder is that Twitter wasnt the only outfit talking about getting broken into. The New York Times ran a long piece a few days earlier laying out how Chinese hackers had been poking around inside their network for something like four months, reportedly going after the email accounts of reporters covering the Wen Jiabao family's finances. They brought in Mandiant to do the forensics and basically walked through the whole thing in public, which I respect even if it's not a great look. The Wall Street Journal said something similar happened to them. It's a strange thing to read two major papers essentially confirm they'd been living with an intruder in the walls for months without noticing.

None of this is really shocking on its own. Companies get broken into, security people write careful blog posts, everyone resets their passwords and mutters about two-factor auth for a week and then forgets about it until the next one. What I keep coming back to is how much of this traces back to the same handful of weak points over and over. Java is one. Password reuse is another, obviously, though I'll spare you the lecture since if you're reading a blog like this one you probably already have 1Password or LastPass or something and are rolling your eyes at me right now. Fair.

I did spend about twenty minutes Friday afternoon going through and turning on login verification on the handful of services that offer it, Twitter included, since they'd added SMS-based two-factor back in the spring. It's not perfect, and it's kind of annoying when you switch phones, but it beats the alternative. I'd honestly forgotten Twitter even had that option turned on for my account until I went digging through settings, which says something about how buried these features usually are.

Small tangent, but I was up too late Saturday watching the Super Bowl (the actual game, not the ads, I dont care about the ads) and that half hour power outage in the Superdome was its own little disaster-that-wasn't. Half the stadium sat there in the dark for over thirty minutes while everyone on Twitter, of all places, argued about whether it was a grid problem or something with the new relay equipment. Kind of fitting, in a dumb way, to spend the same week thinking about Twitter's security and then watching an entire NFL stadium go dark on national television. Nobody hacked the Superdome as far as I know. It just felt like a week where infrastructure of every kind was having a bad time.

Anyway. New password's in. Java's off. Back to normal posting around here soon, I've got a few drafts sitting half-finished that I keep meaning to get back to.