{"id":128,"date":"2009-04-17T11:11:01","date_gmt":"2009-04-17T16:11:01","guid":{"rendered":"http:\/\/www.hewins.org\/dhh\/?p=128"},"modified":"2009-04-17T11:14:20","modified_gmt":"2009-04-17T16:14:20","slug":"the-saga-of-a-twitter-security-problem","status":"publish","type":"post","link":"http:\/\/www.hewins.org\/dhh\/2009\/04\/17\/the-saga-of-a-twitter-security-problem\/","title":{"rendered":"The saga of a Twitter security problem"},"content":{"rendered":"<figure id=\"attachment_130\" aria-describedby=\"caption-attachment-130\" style=\"width: 500px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-130\" title=\"tweets\" src=\"http:\/\/www.hewins.org\/dhh\/wp-content\/uploads\/2009\/04\/picture-41.png\" alt=\"this is a screenshot from an account I created with the email address support@twitter.com\" width=\"500\" height=\"517\" srcset=\"http:\/\/www.hewins.org\/dhh\/wp-content\/uploads\/2009\/04\/picture-41.png 795w, http:\/\/www.hewins.org\/dhh\/wp-content\/uploads\/2009\/04\/picture-41-290x300.png 290w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-130\" class=\"wp-caption-text\">this is a screenshot from an account I created with the email address support@twitter.com<\/figcaption><\/figure>\n<p>I have a few email addresses. I hacve some that I use for my everyday life, one for work, and others for things like signing up on email lists and entering contests.<\/p>\n<p>One of the email addresses I use to subscribe to <a href=\"http:\/\/www.injesus.com\/index.php?module=message&amp;task=list&amp;GroupID=2A004N9G\" target=\"_blank\">Jim Bramlett&#8217;s &#8220;inJesus&#8221; evangelical email<\/a> list got a strange email the other day from Twitter. The subject was, &#8220;Welcoming you to Twitter!&#8221; and it began, &#8220;Hello, new Twitter-er!&#8221; This, I thought was very strange because I didn&#8217;t sign up for a Twitter account with that email address, and I looked into it. It turns out that someone had created my account and called it &#8220;PastorFurtick&#8221; with the name Steven Furtick. I immediately changed the password on the account so that nobody could access it anymore (I wish I hadn&#8217;t, more on that later). Then, naturally, I googled Steven Furtick and came up with <a href=\"http:\/\/www.stevenfurtick.com\/\" target=\"_blank\">this site<\/a>. I looked for a way to contact <a href=\"http:\/\/www.elevationchurch.org\/\" target=\"_blank\">his church<\/a> and found a phone number, called it, and didn&#8217;t reach anyone. I didn&#8217;t leave a message either. I was going to ask about the twitter account while knowing that it wa not necessarily Steven who had created it.<\/p>\n<p>As I was discussing this with my coworkers today, I decided to try it myself. I realized that I could complete the sign-up process and start tweeting without even verifying the email address that I used to create the account. I made an account called &#8220;securityproblem&#8221; with the email address support@twitter.com. (In the meantime, my coworker created one with my work email address.) It seemed that someone else had dome something like that becuase when I saw the home page, my new account was already following and followed by &#8220;<strong><a class=\"url uid\" title=\"Proud Single Mom, Navy Mom &amp; Empty Nester\" href=\"https:\/\/twitter.com\/llk4235\"><span class=\"nickname\">llk4235<\/span><\/a> \/ Lupe King<\/strong>&#8220;.<\/p>\n<p>So I tweeted. I tweeted more and tweeted @biz, the founder (nothing in reply yet). A screenshot of the first few tweets is what is above. Check out the <a href=\"http:\/\/twitter.com\/securityproblem\" target=\"_blank\">twitter account page here<\/a>. I have tested logging out and back in to this account, and that works, no problem.<\/p>\n<p>Looking around for other people talking about it, google turned up the Twitter support page on &#8220;<a href=\"http:\/\/help.twitter.com\/forums\/10713\/entries\/31796\" target=\"_blank\">My account is compromised&#8230;<\/a>&#8221; but it doesn&#8217;t really address the issue at hand. This is more about something strange happening to an existing account. I need to know about creating new accounts. I didn&#8217;t really find anything useful after googling &#8220;sign up for twitter with someone else&#8217;s email address&#8221;. Mostly, people were concerned with Twitter &#8220;impoersonators&#8221; but this was not related to the email address issue.<\/p>\n<p>If you know anything about this issue, please comment here or tweet <a href=\"http:\/\/www.twitter.com\/hewins\">@hewins<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I have a few email addresses. I hacve some that I use for my everyday life, one for work, and others for things like signing up on email lists and entering contests. One of the email addresses I use to subscribe to Jim Bramlett&#8217;s &#8220;inJesus&#8221; evangelical email list got a strange email the other day &hellip; <a href=\"http:\/\/www.hewins.org\/dhh\/2009\/04\/17\/the-saga-of-a-twitter-security-problem\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">The saga of a Twitter security problem<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21,3],"tags":[34],"class_list":["post-128","post","type-post","status-publish","format-standard","hentry","category-digg","category-random","tag-twitter"],"_links":{"self":[{"href":"http:\/\/www.hewins.org\/dhh\/wp-json\/wp\/v2\/posts\/128","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.hewins.org\/dhh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.hewins.org\/dhh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.hewins.org\/dhh\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.hewins.org\/dhh\/wp-json\/wp\/v2\/comments?post=128"}],"version-history":[{"count":4,"href":"http:\/\/www.hewins.org\/dhh\/wp-json\/wp\/v2\/posts\/128\/revisions"}],"predecessor-version":[{"id":134,"href":"http:\/\/www.hewins.org\/dhh\/wp-json\/wp\/v2\/posts\/128\/revisions\/134"}],"wp:attachment":[{"href":"http:\/\/www.hewins.org\/dhh\/wp-json\/wp\/v2\/media?parent=128"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.hewins.org\/dhh\/wp-json\/wp\/v2\/categories?post=128"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.hewins.org\/dhh\/wp-json\/wp\/v2\/tags?post=128"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}