• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Trump ‘cyber tsar’ Giuliani among swathes of hacked top appointees

Status
Not open for further replies.
https://www.channel4.com/news/trump-cyber-tsar-giuliani-among-swathes-of-hacked-top-appointees

Passwords used by Donald Trump’s incoming cyber security advisor Rudy Giuliani and 13 other top staff members have been leaked in mass hacks, a Channel 4 News investigation can reveal.


Passwords used by Donald Trump’s incoming cyber security advisor Rudy Giuliani and 13 other top staff members have been leaked in mass hacks, a Channel 4 News investigation can reveal.

Passwords are publicly available for key members of Trump’s cabinet, White House policy directors and aides and some of his most senior advisors, this programme has discovered.

Digital security issues – including allegations of Russian hacking to try to influence the outcome of the US presidential elections – have dominated the headlines as Trump’s team prepares to take command of the world’s most powerful country.

NEW YORK, NY - JANUARY 12: Former New York City Mayor Rudy Giuliani speaks to reporters at Trump Tower, January 12, 2017 in New York City. President-elect Trump continues to hold meetings Trump Tower. (Photo by Drew Angerer/Getty Images)
The appointment of Giuliani, the former mayor of New York City, has been criticised by people in the cyber security community, who have highlighted exploitable security flaws on his own website.

But Giuliani says he has given “over 300 speeches” on digital security, and told Fox News earlier this month: “American corporations and the American government is not paying attention to ubiquitous hacking that is now going on.”

Lt Gen Michael Flynn has also been hacked in the past – and Channel 4 News has seen a number of passwords used by the former military intelligence officer.

He will become President Trump’s national security advisor from Friday; a crucial role stationed inside the White House itself and reporting directly to Trump.

Lt. Gen. Michael Flynn arrives for a meeting with US President-elect Donald Trump at Trump Tower December 12, 2016 in New York. / AFP / TIMOTHY A. CLARY (Photo credit should read TIMOTHY A. CLARY/AFP/Getty Images)
Staff whose accounts also appear to be affected by the hacks in recent years include people who will from Friday at 12pm take roles as:

the Secretary for the Interior
the Secretary for Labour
the Press Secretary
the Director of the Domestic Policy Council
the Director of the National Trade Council
Head of Social Media
Chief Trade Negotiator
Director of Oval Office operations
and many others
Trump’s team have not commented on this story.


Mass breaches

The passwords of the appointees were hacked in mass breaches of websites like Dropbox, LinkedIn, MySpace, and others between 2012 and 2016.

The passwords are accessible from original leaks of the data, but even more easily accessible from website charging a fee of just $4 (£3.20).

With some staffers using the same simple passwords for multiple sensitive websites, experts say the hacks may have left them vulnerable to further hacks – perhaps by foreign powers.

There is no way to check how widely the hacked passwords have been reused by the incoming government officials without actually logging in and testing them – which is illegal under British law.


Hacks of celebrities – for instance of Twitter accounts or explicit photos – sometimes occurred by hackers using precisely this method of reusing passwords that have already been leaked.

Cyber security analyst Troy Hunt, who runs the online service HaveIBeenPwned.com to notify users of data breaches, told Channel 4 News that the leaks could be problematic.

Hunt said: “How many passwords have we got that have been reused in different places and are the same as they were five years ago – even a decade ago. We’ve got a long tail of info that we’ve left on the web now.

“The problem here is that a little bit like all of us, we have this propensity to reuse our passwords.

“And let’s say someone from Trump’s team has data leaked and it appears on a totally unrelated forum somewhere and someone takes those credentials and accesses the individual’s Gmail.

If this is an individual in a position of power or influence they may well have discussions in their personal mail that could be compromising.
Cyber security analyst Troy Hunt
“If this is an individual in a position of power or influence they may well have discussions in their personal mail that could be compromising.

“And if they don’t then the attacker who gains access to that Gmail may then use that account to begin conversation with other people in the contact list, impersonate them, elicit information from other individuals.

“It then just opens up a door to a raft of much bigger problems.”


The revelations come after Trump boasted in a press conference of how the Republicans had better cyber security than the Democrats, saying: “They did a very poor job. They could’ve had hacking defense, which we had.”

Unlike Hillary Clinton’s campaign team, the Trump team officials were not targeted specifically but rather had their details leaked along with many others – but the hack would have made it easier for intruders to take control of their accounts.

The release of hacked emails belonging to Hillary Clinton’s campaign manager occurred just weeks before the US election.

Some pundits say it helped Donald Trump win the race.
 
That's actually really interesting beyond the 'har har, old man got hacked' bits because Giulani and Flynn could have some real dangerous stuff in there
 

shira

Member
Username: The_Doald
Password:TRUUMP!234

giphy.gif
 

OceanBlue

Member
I don't think it's too crazy to have been part of a mass website hacking. If your password was in the millions of passwords obtained through Yahoo, that doesn't mean you have bad cybersecurity practices in general. The problematic point is whether they reuse their passwords across services, and they couldn't really confirm that.
 

wenis

Registered for GAF on September 11, 2001.
I don't condone it but I also don't give a shit. Best of luck to the hackers.
 
Only if something important is found, but I honestly doubt Giuliani was in on any significant Trump campaign plans. It won't stop him from getting the job.

Giuliani has been advising foreign governments for the last few years so he probably has some serious shit on his computers.

Flynn too.
 

JP_

Banned
I don't think Giuliani is even close to being a competent cyber security expert but

The passwords of the appointees were hacked in mass breaches of websites like Dropbox, LinkedIn, MySpace, and others between 2012 and 2016.

Doesn't seem to have much to do with his personal security unless that password is used on multiple sites.
 

Syncytia

Member
I don't think Giuliani is even close to being a competent cyber security expert but



Doesn't seem to have much to do with his personal security unless that password is used on multiple sites.

I think you give people too much credit.
 

UberTag

Member
Who wants to bet that the people whose passwords were hacked will continue using the same passwords now that they're entrenched in their new positions of responsibility thinking "it will be OK"? I mean, they're part of Washington's elite now. Surely there will be safeguards in place to secure their accounts so they can continue to use Rudy123 to access government servers.
 
Status
Not open for further replies.
Top Bottom