So last Tuesday (the 23rd, if you're keeping track) the AP's Twitter account got hijacked and tweeted that there'd been two explosions at the White House and that the President was hurt. It was garbage, obviously, it was up for maybe three minutes before AP and the White House both said no, none of that happened, but three minutes was apparently all it took for a chunk of Wall Street's trading algorithms to see "explosion," "White House," and "Obama" in the same sentence and just start selling. The Dow dropped something like 140-something points almost instantly. Estimates I've seen put the market cap wiped out at around $136 billion, for about three minutes, because of one tweet.
Three minutes! Then everybody figured out it was fake, the market clawed most of it back within the hour, and the cable news channels spent the rest of the afternoon interviewing people about "algorithmic trading risk" like this was some brand new discovery. It's not. We've known bots trade on headlines and sentiment for years now. What this actually proved is that a lot of very expensive trading software apparently doesn't bother checking whether the account tweeting the headline has a blue checkmark next to something that says "verified," or whether the story's been confirmed by a second source. One compromised password and a phishing email aimed at an AP staffer, and you can nudge the market around for a few minutes. That's a genuinely dumb state of affairs, and I don't think "dumb" is too strong a word for it.
The part that annoys me more than the trading-bot stuff, though, is that this is at least the fourth or fifth big media Twitter account the Syrian Electronic Army has gotten into this year. NPR got hit a while back. So did a couple of other outlets earlier in the spring. And every time it comes down to the same thing: somebody on staff clicked a link in an email that looked like it came from Twitter asking them to "verify" their account, typed their password into a fake login page, done. Twitter, as far as I can tell, still doesn't offer any kind of two-factor login. No app confirmation, no SMS code, nothing beyond a username and a password. For a service that major news organizations, government agencies, and companies with actual stock prices depend on to say true things in real time, that's a pretty enormous gap to still have open.
I'll admit part of why this one got under my skin is that it made me go check my own setup, and it wasn't great. The techpad Twitter account (small potatoes compared to the AP, obviously, nobody's crashing a market off my typos) was using a password I'd recycled from an old email account, which is exactly the kind of thing I'd roll my eyes at if I read it on somebody else's blog. So over the weekend I finally moved everything over, this blog's login, the email account tied to it, the Twitter account, into LastPass, and generated actual unique passwords for each one instead of the "add a number to the end" system I'd apparently been running since sometime back in 2011. Took maybe forty minutes total, start to finish. I have no excuse for not doing it sooner. If you're still keeping your passwords in your head, or worse, in a Notes app somewhere, take this as your nudge.
None of this is entirely Twitter's fault, in the sense that phishing works on smart people at good organizations all the time, that's just what phishing does. But "we don't have two-factor authentication in 2013" is a choice at this point, and it's one that keeps looking worse every time another one of these accounts gets popped. Facebook's had some version of login approvals for a while now. Google's had it since 2011. There isn't a real excuse left sitting on the table.
Also, separately, can we talk about how fast people RT things without reading past the headline? I watched my own feed for a few minutes that afternoon and at least three people I follow, people who are usually pretty careful, retweeted the fake AP post before anyone had walked it back. Nobody's fault exactly, that's just how the format works, but it's a reminder that "breaking news" on Twitter is often just a sentence somebody typed, with no editor standing between the typing and the fifty thousand people who see it thirty seconds later.
Nobody got hurt. No explosions happened. The market found its footing again well before the closing bell. But it's a strange thing to sit with, that a fake sentence from a hacked account moved real money around faster than any human editor could have fact-checked it. I don't think that gets less strange the more I think about it, and I've been thinking about it for four days now.