So this happened on Tuesday and I'm still thinking about it four days later, which for me is basically the internet equivalent of "still can't stop talking about it at dinner."
At 1:07pm on April 23rd, the AP's Twitter account posted: "Breaking: Two Explosions in the White House and Barack Obama is injured." Total fabrication. The account had been phished (Syrian Electronic Army took credit, for what that's worth) and for about three minutes, a decent chunk of the internet believed the White House had just been bombed.
Here's the part that actually gets me, though, and it's not the hack itself. Phishing happens. Accounts get popped all the time, and honestly I'm a little surprised it doesn't happen to verified news orgs more often given how many interns probably have the password saved in a sticky note somewhere. What gets me is what happened to the Dow in those same three minutes. It dropped 143 points. Something like $136 billion in market value just evaporated, and then came right back once AP and the White House both said, no, actually, everyone's fine, that didn't happen.
Three minutes. That's not humans panic-selling their retirement accounts, thats algorithms. A huge chunk of trading now runs on programs that scan headlines and social media for keywords and react in milliseconds, faster than any person could even finish reading the tweet, let alone fact-check it. Nobody at these trading desks looked at that and thought "hm, let me check CNN real quick." The machines just saw "explosion," "White House," "Obama," "injured" and started selling. It's not that the algorithm believed a lie, exactly. It doesn't believe anything. It just doesn't know the difference between news and noise, and apparently neither do the systems built on top of it, at least not yet.
I keep coming back to how much weight we put on that little blue checkmark. We've basically decided, as a culture, that "verified" means "safe to trust instantly and act on," and this is what happens when that assumption gets exploited even for three minutes. My buddy Dave trades a little on the side, nothing serious, mostly just to lose money in a way that feels sophisticated, and he texted me right as it was happening going "uh is this real" like I'd have any better idea than him. I didn't. Neither did the market, apparently, until it very quickly decided it wasn't.
I'll admit I've got a personal chip on my shoulder about this one because my own email got phished back in 2011, some fake "your account has been compromised, click here to verify" garbage that looked convincing enough at 11pm that I typed my password into it before my brain caught up with my hands. Nothing catastrophic happened to me, I just had to change some passwords and feel dumb for a day. But a media organization's Twitter account isn't a personal inbox. When AP's account gets popped, the blast radius is the actual stock market. That's a genuinely different category of consequence for what's still, structurally, just some guy who fell for an email.
The AP has since said they're not tweeting for a while and are reviewing their security setup, which, sure, fine, but that misses the more interesting problem a little. The vulnerability wasn't really AP's password hygiene, though that obviously didn't help. The vulnerability is a trading system architecture that treats a single unverified tweet as tradeable information with zero human confirmation step in between. That's the part that should worry people more than "hackers exist," because hackers existing is not new information to anyone in 2013.
Feels a little like we built some genuinely impressive infrastructure for moving information (and money) at inhuman speed, and then just never got around to building the "wait, is this actually true" step to go with it. Three minutes isn't a long time. It was apparently long enough.