
 {"id":482715,"date":"2020-10-22T17:40:20","date_gmt":"2020-10-22T15:40:20","guid":{"rendered":"https:\/\/www.vn.nl\/?p=482715"},"modified":"2020-10-23T11:00:04","modified_gmt":"2020-10-23T09:00:04","slug":"trump-twitter-hacked-again","status":"publish","type":"post","link":"https:\/\/www.vn.nl\/trump-twitter-hacked-again\/","title":{"rendered":"How Trump\u2019s Twitter account was hacked &#8211; again"},"content":{"rendered":"<div class=\"info-box\">\n<p><a href=\"https:\/\/www.vn.nl\/twitter-trump-opnieuw-gehackt\/\" target=\"_blank\" rel=\"noopener noreferrer\">Lees de Nederlandse versie van dit verhaal hier.<\/a><\/p>\n<\/div>\n<p>On October 16, 2020 a mysterious <a href=\"https:\/\/twitter.com\/realDonaldTrump\/status\/1317044556328730625\" target=\"_blank\" rel=\"noopener noreferrer\">message<\/a> is posted on Donald Trump\u2019s Twitter timeline.<\/p>\n<p><em>Twitter Shuts Down Entire Network To Slow Spread Of Negative Biden News https:\/\/babylonbee.com\/news\/twitter-shuts-down-entire-network-to-slow-spread-of-negative-biden-news via <\/em><em>@TheBabylonBee <\/em><\/p>\n<p><em>Wow, this has never been done in history. This includes his really bad interview last night. Why is Twitter doing this. Bringing more attention to Sleepy Joe &amp; Big T<\/em><\/p>\n<p>In the tweet, Trump references the Babylon Bee website, online information similar to The Onion (or De Speld in the Netherlands) but aimed at Trump supporters. \u2018The world\u2019s best satire site,\u2019 as the Babylon Bee refers to itself.<\/p>\n<p>Did Trump make a mistake?<br \/>\nIs it a joke?<br \/>\nOr neither of the above?<\/p>\n<p>Victor is one of the three Dutch \u2018grumpy old hackers\u2019 who gained access to Trump\u2019s Twitter account four years ago. The password was: <strong>y<\/strong>ourefired.<\/p>\n<p>I earlier wrote this <a href=\"https:\/\/www.vn.nl\/hackers-twitter-trump\/\" target=\"_blank\" rel=\"noopener noreferrer\">piece<\/a> on the matter.<\/p>\n<h5>online version of batman<\/h5>\n<p>On October 16, 2020, Victor Gevers decides to check in on Trump\u2019s account. Just to see if it is still safe. \u201cI always run random checks. Whenever someone is in the news, I monitor. I ran a check on the Biden, Pence and Harris accounts. Anyone receiving media attention is a potential target and deserves protection. Regardless of who they are.\u201d Gevers still abides by the old hacker manifesto. He does not discriminate on the basis of race, religion, class or political beliefs.<\/p>\n<p>Within the international hacker community, Gevers (44) is considered an authority. At nearly 6.5 ft tall, his physical appearance matches this description. You can compare him to an online version of Batman. During the day, he works for the Dutch government. At night, he keeps the internet safe. He leads the GDI.foundation, an organization with a network of 38 volunteers that tirelessly address data breaches, weak passwords and other vulnerabilities on the internet. For every data breach that has made headlines, the GDI.foundation has prevented one hundred others. Most of them will never see the light of day. Tracking down digital glitches comes as a second nature to Gevers.<\/p>\n<p>On Friday 16 October, 2020 Gevers runs a check on the Hunter Biden (US presidential candidate Joe Biden\u2019s son) story, whose laptop has supposedly turned up at a computer repair shop. He also searches for Hunter Biden\u2019s previously leaked passwords and then checks if these work on his Twitter account. They don\u2019t. Just to make sure, he also checks Donald Trump\u2019s Twitter account, and runs the password that was in use 4 years ago: yourefired<\/p>\n<blockquote><p>He sends a message to the Grumpy Old Hackers Signal group. \u201cmaga2020!&#8221;<\/p><\/blockquote>\n<p>Much to his surprise, the Two-Factor-Authentication for the account is disabled. For so called \u2018verified Twitter accounts\u2019, it is compulsory nowadays to submit an additional code (which is for example sent to your mobile phone) after logging in with your regular password. Gevers had a key role in this feature becoming mandatory on Twitter.<\/p>\n<h5>&#8216;Not again!&#8217;<\/h5>\n<p>It is very odd to find Trump\u2019s Two-Factor-Authentication disabled. However, Gevers suspects Trump\u2019s account has its own special security. This would also explain why Trump\u2019s account was left untouched during the Twitter hack in July 2020. During this hack, posts appeared on the accounts of Barack Obama, Elon Musk and Joe Biden, requesting Bitcoin transfers. Not on Trump\u2019s account.<\/p>\n<p>Gevers tries a few other passwords:<\/p>\n<p>!IWillAmericaGreatAgain!<br \/>\nMakeAmericaGreatAgain<br \/>\nMakeAmericaGreatAgain!<br \/>\nMaga2020<br \/>\nMaga2020!<br \/>\nmaga2020!<\/p>\n<p>Plong! At the last try, he gets kicked off the site. Or at least, that is what it seems like \u2013 for a split second. Because he then realizes, he\u2019s back in Donald Trump\u2019s Twitter account, just like he was 4 years ago.<\/p>\n<p>He sends a message to the Grumpy Old Hackers Signal group.<\/p>\n<p>\u201cmaga2020!\u201d<\/p>\n<p>\u201cNOOOOO! Not again!\u201d, is the reaction<\/p>\n<p>Gevers is able to change the password. And the profile picture. And worse: if he wants to he can download all of Trump\u2019s Twitter history as a data file. A document containing all of his DM\u2019s. And all of the messages Trump has previously deleted. Hasn\u2019t anyone learned anything?<\/p>\n<figure id=\"attachment_482691\" aria-describedby=\"caption-attachment-482691\" style=\"width: 640px\" class=\"wp-caption alignnone\"><img decoding=\"async\" class=\"size-image_640 wp-image-482691\" src=\"https:\/\/www.vn.nl\/wp-content\/uploads\/2020\/10\/afbeelding-1a-640x560.png\" srcset=\"https:\/\/www.vn.nl\/wp-content\/uploads\/2020\/10\/afbeelding-1a-320x280.png 320w, https:\/\/www.vn.nl\/wp-content\/uploads\/2020\/10\/afbeelding-1a-640x560.png 640w\" alt=\"\" width=\"640\" height=\"560\" \/><figcaption id=\"caption-attachment-482691\" class=\"wp-caption-text\">A screenshot from when Gevers had access to Trumps account<\/figcaption><\/figure>\n<p>Via Signal &#8211; the safer option to WhatsApp &#8211; Gevers tells me: \u201cGetting access to someone\u2019s Twitter account comes with much more risks than before, you can do more than just recommend bitcoins and rearrange an account. All of the account interactions are logged and saved.\u201d<\/p>\n<h5>Digital evidence<\/h5>\n<p>Gevers did learn from the incident 4 years ago. Together with his &#8216;grumpy hacker&#8217;-friends Mattijs and Edwin, he pursued an official \u2018responsible disclosure\u2019 path at the time. A discreet report to the president that \u2018he had his digital fly open\u2019. They covered up all their tracks. As a result, nobody in the US felt the need to thank them for their efforts afterwards. Another result was that several people expressed their doubts about the validity of the earlier article published on the Dutch hackers, which tells the story of how they accessed Donald Trump\u2019s Twitter account in 2016. Even a Bellingcat member questioned the piece. What if the profile screenshots of Trump\u2019s Twitter account had been photoshopped?<\/p>\n<blockquote><p>Gevers comes up with a plan to make sure that this time the White House responds.<\/p><\/blockquote>\n<p>\u201cThe Bellingcat comments kept circling my mind.\u201d This, in combination with the fact that an official thank you note from the US never arrived, made Gevers decide to leave behind more digital evidence this time. \u201cAt the same time, a sense of moral duty kicked in. There\u2019s this unwritten code in Responsible Disclosure. Each person deserves the right to a decent report. Including Donald Trump.\u201d<\/p>\n<p>Gevers comes up with a plan to make sure that this time the White House responds. He refuses to say what he did exactly, but in a tweet that has now been removed, he alludes to the fact that he was the one to post the Babylon Bee tweet in Trump\u2019s name. Shortly after, he posted a tweet in his own name, tagging Trump and Team Trump, saying the Babylon Bee-tweet could now be removed, as it had served its purpose.<\/p>\n<p>\u201cI am not saying I did it. But what if I was the one to post the tweet? Then Trump will need to either admit to never having read the Babylon Bee article and posting this bullshit tweet, OR he will need to acknowledge that someone else posted the tweet.\u201d<\/p>\n<p>Breaking into a Twitter account to prove it is poorly secured is one thing, posting a tweet is another. \u201cI took things further this time because our previous report obviously didn\u2019t have any effect\u201d, says Gevers. \u201cI hope that everything will now be resolved soon, and that mister Trump sends us a message. \u2018Thank you for your work\/report.\u2019 That should suffice and will round up things for both cases.\u201d<\/p>\n<h5>&#8216;Thank you for your message&#8217;<\/h5>\n<p>Whether the tweet is real or fake, fact is \u2013 the Babylon Bee post has not been removed. It is still there as I am writing this piece. Whether the tweet is real or fake, fact is \u2013 the Babylon Bee post has not been removed. In fact Trump \u2018acknowledges\u2019 the tweet, by reacting to it. It is unclear why, but this is something that happens more often. Sometimes his tweets even appear when he is on stage somewhere. Gevers: \u201cIt seems as if he tweets random things at times, followed by a tweet to elaborate. Team Trump, maybe?\u201d<\/p>\n<p>The media start publishing scornful stories on how Trump has put his foot in once again. <em>The New York Times<\/em>, <em>USA Today<\/em>, <em>Politico<\/em>, <em>The Independent<\/em> and <em>Daily Mail<\/em> all write about how Trump has mistaken obvious satire for reality. Meanwhile, Gevers has only been briefly in touch via DM with Team Trump. A very short reply:<\/p>\n<p>\u2018Thank you, we forwarded your message.\u2019<\/p>\n<p>Gevers succeeds at further interaction with Team Trump via Parler, an alternative to Twitter now gaining in popularity at high speed, as Twitter increasingly moderates and removes conspiracy theories and fake news. Gevers learns that because of this, their 2016 report \u2013 which was sent to Homeland security via the Dutch CERT \u2013 never reached Donald Trump.<\/p>\n<p>On Saturday evening 17 October, 2020 Gevers writes: \u201cTeam Trump reports that Donald Trump never received our emails in 2016. Nobody informed him back then either. He was never informed of the fact that three people from the Netherlands tried to inform him in a timely matter. This is now surfacing because I am actively pursuing the information myself. Twitter is not responding. It is obvious that everybody hates Trump. Which I can relate to, but purposely keeping intel away from him is unethical.\u201d<\/p>\n<p>\u201cAny news?\u201d, I ask in the morning.<br \/>\n\u201cYes, that none of the emails sent to Trump ever arrived.\u201d<br \/>\nAfter which I think I receive some sort of secret code:<br \/>\n\u2018309780p349874[&#8216; 0-92`1367yb&#8217;R_(TYgr13e4p9igbR!@#$\u2019<br \/>\n\u201cWhat does this mean?\u201d, I ask.<br \/>\n\u201cThis is me losing my shit. FUCK GMAIL\u201d, Gevers says.<\/p>\n<p>Gevers feels discouraged. All of the emails have bounced back. There seems to be no way to get a message delivered to Trump. He desperately wants to reach Trump or the people surrounding him. Which. Seems. Impossible.<\/p>\n<p>\u201cI have tried email, Twitter, Parler, contacts, DMs to contacts who know people at the White house, the Team Trump web form, the White House web form. His son. The CISA (Cybersecurity &amp; Infrastructure Security Agency), Twitter security \u2013 via their chatbot. I also tried calling Team Trump.\u201d<\/p>\n<p>The password seems to have changed, Two-Factor-Authentication has been reinstated. Other than this, nothing is happening \u2013 just like in 2016. Zero. Nothing. Nada. Not a single bleep. From anyone.\u201d<\/p>\n<h5>message in a bottle<\/h5>\n<p>Gevers is at his wits\u2019 end. He comes up with the idea of making a video to disperse via social media, in the hope that it reaches Trump, like a digital message in a bottle. He shares his draft script with me.<\/p>\n<figure id=\"attachment_482749\" aria-describedby=\"caption-attachment-482749\" style=\"width: 225px\" class=\"wp-caption alignnone\"><img decoding=\"async\" class=\"wp-image-482749\" src=\"https:\/\/www.vn.nl\/wp-content\/uploads\/2020\/10\/Afbeelding1.png\" alt=\"\" width=\"225\" height=\"300\" srcset=\"https:\/\/www.vn.nl\/wp-content\/uploads\/2020\/10\/Afbeelding1.png 510w, https:\/\/www.vn.nl\/wp-content\/uploads\/2020\/10\/Afbeelding1-450x600.png 450w, https:\/\/www.vn.nl\/wp-content\/uploads\/2020\/10\/Afbeelding1-320x427.png 320w\" sizes=\"(max-width: 225px) 100vw, 225px\" \/><figcaption id=\"caption-attachment-482749\" class=\"wp-caption-text\">The draft<\/figcaption><\/figure>\n<p>Then, the editor in chief of The Babylon Bee retweets a <em>Newsweek<\/em> story, which suggests that Trump has a sense of humor and that he has purposely posted the Babylon Bee tweet.<\/p>\n<p>\u201cThey are now going to frame it all as a joke\u201d, Gevers says. It has come to the point where he thinks anything could happen. He has taken a file with evidence containing important information to safety, in case something unexpected ends up happening to him. \u201cThe US secret service is only six minutes away from me\u201d, Gevers says. During the previous reporting procedure four years ago, he had already learned that in case of an escalation, the Dutch government would not be extending any assistance.<\/p>\n<p>During the night of Monday the 19th to Tuesday the 20th of October, 2020, Gevers spots the following video online:<\/p>\n<div class=\"gpdr-overlay-wrapper\">\n    <script type=\"text\/plain\" class=\"gpdr-iframe gdpr-service-twitter\"><\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">&quot;The only laptop that was almost as good, maybe worse, was the laptop of Anthony Weiner&quot; -- Trump talks about Hunter Biden&#39;s laptop <a href=\"https:\/\/t.co\/wCbySHlMeU\">pic.twitter.com\/wCbySHlMeU<\/a><\/p>\n<p>&mdash; Aaron Rupar (@atrupar) <a href=\"https:\/\/x.com\/atrupar\/status\/1318285337408507915?ref_src=twsrc%5Etfw\">October 19, 2020<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.x.com\/widgets.js\" charset=\"utf-8\"><\/script>    <\/script><\/p>\n<div class=\"row\">\n<div class=\"col-sm-12\">\n<div class=\"gdpr-content\">\n<h4>Twitter<\/h4>\n<p>Deze dienst is alleen beschikbaar wanneer alle cookies zijn geaccepteerd<\/p>\n<p>                <a href=\"javascript: Cookiebot.renew()\" class=\"gdpr-settings btn btn--primary button--primary\">Wijzig cookie voorkeur<\/a>\n            <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<p>Donald Trump is on a stage somewhere in Prescott, Arizona, discussing hackers. <em>\u201cI have never known anyone who says they have been hacked or who has been hacked. Nobody gets hacked. To be hacked you need someone with an IQ of a 197, and he needs to know 15% of your password. Doesn\u2019t happen\u201d.<\/em><\/p>\n<p>Gevers gives up on trying to reach Trump to warn him. He gives me permission to write this story. As a plea to everyone to use Two-Factor-Authentication.<\/p>\n<p>The absence of Two-Factor-Authentication on the Twitter account of the President of The United States of America is absurd and raises many questions. The Two-Factor-Authentication on his account was probably disabled when he was taken to hospital a few weeks ago, in order to be able to issue tweets without him personally having to log in.<\/p>\n<p>This means that the most important communication channel of the President of the United States of America &#8211; a man who is driven around in an armored vehicle, who is flanked by an army of security staff \u2013 can be cracked with an easy-to-guess password.<\/p>\n<p>Donald Trump really isn\u2019t the only world leader or politician using terrible passwords. However, Twitter should \u2013 in this case \u2013 be making it impossible for the account to be accessed so easily. This is a metaphor for the digital society, which seems to have become much too dependent on a handful of large companies, that are more interested in power and making money, than in stability and safety.<\/p>\n<p>Gevers: \u201cAll I care about is more awareness of the fact that Two-Factor-Authentication should be mandatory for everyone. Passwords are the Achilles heel of the internet. This needs to be resolved \u2013 fast \u2013 because even the President of the United States of America is no longer safe.\u201d<\/p>\n<p>On Tuesday evening 20 October, 2020, the US government finally contacts Gevers. He tweets: \u201cThank you, dear infosec community, for helping to get \u2018first contact\u2019 \u2013 Responsible disclosure #5780 will be handled by the experts now.\u201d<\/p>\n<p>Via Signal he adds: \u201cThe cause is more important than the person. 2FA for all online users (\u2026) A safer internet for EVERYONE. And fuck Big T for opposing this. I share Trump\u2019s opinion in this regard. Big T\u2019s power is something that should be addressed.\u201d<strong>\u00a0<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lees de Nederlandse versie van dit verhaal hier. On October 16, 2020 a mysterious message is posted on Donald Trump\u2019s Twitter timeline. Twitter Shuts Down Entire Network To Slow Spread Of Negative Biden News https:\/\/babylonbee.com\/news\/twitter-shuts-down-entire-network-to-slow-spread-of-negative-biden-news via @TheBabylonBee Wow, this has never been done in history. This includes his really bad interview last night. Why is [&hellip;]<\/p>\n","protected":false},"author":1258,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","ep_exclude_from_search":false,"footnotes":""},"tags":[],"class_list":["post-482715","post","type-post","status-publish","format-standard","hentry","dossier-tech"],"acf":[],"author_name":"Gerard Janssen","_links":{"self":[{"href":"https:\/\/www.vn.nl\/wpg-api\/wp\/v2\/posts\/482715","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.vn.nl\/wpg-api\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.vn.nl\/wpg-api\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/www.vn.nl\/wpg-api\/wp\/v2\/comments?post=482715"}],"version-history":[{"count":0,"href":"https:\/\/www.vn.nl\/wpg-api\/wp\/v2\/posts\/482715\/revisions"}],"author":[{"embeddable":true,"name":"Gerard Janssen","href":"https:\/\/www.vn.nl\/wpg-api\/wp\/v2\/users\/1258"}],"wp:attachment":[{"href":"https:\/\/www.vn.nl\/wpg-api\/wp\/v2\/media?parent=482715"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.vn.nl\/wpg-api\/wp\/v2\/tags?post=482715"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}