Technology: The business and culture of our digital lives, from the L.A. Times

| Main |

Hacker used 'happiness' to access Twitter accounts

3:34 PM, January 7, 2009

Huffpost on Twitter

The newly notorious Twitter hacker didn't take long to show himself. An 18-year-old cyberpunk who goes by the alias GMZ used password-guessing software to gain entry to a Twitter administrator's account, he told Wired yesterday.

Once inside, he was able to gain access to any Twitter account through the administrative tools, which allowed him to leave mischievous notes under the guise of such noteworthy figures as Barack Obama and Fox News.

What was the secret key for unlocking this seemingly infinite power? Happiness.

The hack victim, a Twitter staffer who goes by the name Crystal on the social network, used that nine-letter word as the password for her account, ignoring just about every rule of smart password choices (for examples, experts suggest avoiding words in the dictionary, varying the letter case and using symbols).

Wired writes:

The intrusion began unfolding Sunday night,  when GMZ randomly targeted the Twitter account belonging to a woman identified as "Crystal." He found Crystal only because her name had popped up repeatedly as a follower on a number of Twitter feeds. "I thought she was just a really popular member," he said.

Using a tool he authored himself, he launched a dictionary attack against the account, automatically trying English words. He let the program run overnight, and when he checked the results Monday morning at around 11:00 a.m. Eastern Time, he found he was in Crystal's account.

The good news is that "happiness" isn't among the 500 worst passwords of all time, as listed in Mark Burnett's 2005 book "Perfect Passwords: Selection, Protection, Authentication." But "happy" is on the list, ranking 349th.

You know, I think I'll change my e-mail password -- as it turns out, "123456" isn't the technological equivalent of Ft. Knox after all.

-- Mark Milian

Photo: Huffington Post Twitter account hacked. Credit: Mat Honan via Flickr


TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8341c630a53ef010536bb09b4970c

Listed below are links to weblogs that reference Hacker used 'happiness' to access Twitter accounts:

Comments

i have to write a story on a cyber crime for my science class, and this one seems interesting. But, i was wondering how the hacker was caught and if any new laws or security measures have been adopted because of this peculiar crime.
Thank you
-jessica

Post a comment
If you are under 13 years of age you may read this message board, but you may not participate.
Here are the full legal terms you agree to by using this comment form.

Comments are moderated, and will not appear until they've been approved.

If you have a TypeKey or TypePad account, please Sign In





@latimes Tech, always on...


Follow @latimestech for <140c updates.
Recent Comments
Tales from the people who answer KGB's text-message search queries
Thatll be 99 cents to answer that questi...
comment by Fred
Tales from the people who answer KGB's text-message search queries
What is this Internet you speak of, Fred...
comment by Mark Milian
Tales from the people who answer KGB's text-message search queries
You know this service is available for f...
comment by Fred
TECHNOLOGY REVIEWS
Depending on the model, your device features either a hard drive or flash drive that allows you to read and write files to it just like an external drive.
More from KTLA.com