Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

61–70 of 477 posts

Re: Twitter internal panel linked to account hijackings

#61

Earlier quoted context omitted.

I saw this Imgur album linked in one of the original tool tweets. Not sure if fake or real obv. https://imgur.com/a/2sqjNUo

I don't understand this angle because typically admin panels only let you manage the account; deactivate, manage email address, etc. As shown in the screenshots. Tweeting on behalf of another user seems like an unnecessary feature to give admins.

The feature wouldn't be tweeting per-se but acting on behalf of the user, which can prove useful for support or debugging. The side-effect is that obviously it also allows tweeting if you wanted to.

Re: Twitter internal panel linked to account hijackings

#62
So it was a social engineering attack against employees with high level access. This sentence still doesn’t make sense to me:

“ Once we became aware of the incident, we immediately locked down the affected accounts and removed Tweets posted by the attackers.”

The accounts were posting for hours after it seemed Twitter became aware what was going on.

Re: Twitter internal panel linked to account hijackings

#63
RE: social engineering, as long as a human is involved somewhere, the system can be compromised. IT security is a very depressing field because of this fact.

I also hope these incidents remind people of how little control you really have over your online identity. We're all just IDs in a database somewhere, waiting to be impersonated. Decentralization is the only solution for this IMO.

Re: Twitter internal panel linked to account hijackings

#64

I’d be surprised if Twitter didn’t have some internal tool like this but I’d expect it to only be accessible over a VPN that few had access to.

How would a VPN help in this case though? They social-engineered some employees to gain privileged access to the admin UI. If a VPN was in the way they'd do the same thing to get access to the VPN first.

Re: Twitter internal panel linked to account hijackings

#65
post #17

> Hawley said "please reach out immediately to the Department of Justice and the Federal Bureau of Investigation and take any necessary measures to secure the site before this breach expands It's kind of bizarre when you have the highest levels of government doing their critical communication on a free social media service to the point where they are critically dependent on it, then begging for support when things go…

The FBI is very commonly involved in cyber crimes and the other departments have a role to play as well. Calling the FBI during a major security incident is not unusual at all, I’ve done it a number of times.

In the early days of the internet the FBI was kind enough to call my employer and inform us that we had left open an anonymous FTP server, and it was serving up Disney movies. Those were good times.

Re: Twitter internal panel linked to account hijackings

#66
post #41

Earlier quoted context omitted.

Is there a better solution? How do you airgap administration of a web facing service?

It's painful (although I suppose all airgap solutions are) but remote access protocols like RDP or SSH tunneling to a jump host which has access to the administration portal is one common(?) solution.

That's only safer from attacks that bypass the public admin portal authentication. Any social engineering attack that steals credentials directly won't be impacted.

Re: Twitter internal panel linked to account hijackings

#68
The Vice article (https://news.ycombinator.com/item?id=23853786) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering":

> we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take over accounts; not sure on the specifics here at the moment

https://twitter.com/jason_koebler/status/1283594885292077056

Re: Twitter internal panel linked to account hijackings

#70
post #50

Twitter confirmed that the attack used internal tools, and thinks the attacker used social engineering on employees: https://twitter.com/TwitterSupport/status/128359184496275046...

Which shows that Twitter probably doesn't properly employ 2FA and two-person-principle when dealing with high-profile accounts. Otherwise, social engineering would have been almost impossible.
Post reply on HN