The lessons from Guy Kawaski's twitter attack
Lessons from the facts and from assumptions!
The lessons are sadly the same. Static passwords are weak and DNS is weak. The answer is two-factor authentication and either mutual https authentication or better DNS. Since DNS is unlikely to be fixed any time soon...

