Well, this is scary.
I had [incorrectly] assumed to get a blue check, you had to have 2FA turned on.
Apparently, The president had neither a strong password or 2FA.
@serrenity - IDK, it's entirely possible the researcher was using a VPN, so I'm gonna give that one a pass.
@0x56 I mean, yeah if i had taken another 30 seconds to think about it, I would expect a white-hat to be able to easily sidestep twitters automated alerts.
But even if they were justified in missing it, I don't think Twitter is in the space to be like "Whoopsies!"