Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

71–80 of 477 posts

Re: Twitter internal panel linked to account hijackings

#71
post #60

>We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools. I wonder the size of the population of employees that have access to these internal tools. How many people can independently fire off a Tweet from Jeff Bezos or Elon Musk and erase billions from the stock market? How many people can seize the a…

Judging by Trump was one of the few that wasn't hacked, presumably there are some extra controls in place for that account.

Re: Twitter internal panel linked to account hijackings

#72
post #62

So it was a social engineering attack against employees with high level access. This sentence still doesn’t make sense to me: “ Once we became aware of the incident, we immediately locked down the affected accounts and removed Tweets posted by the attackers.” The accounts were posting for hours after it seemed Twitter became aware what was going on.

> The accounts were posting for hours after it seemed Twitter became aware what was going on.

Oddly, it was just Elon Musk's account that had multiple tweets over a long period of time. The other accounts did just one.

Re: Twitter internal panel linked to account hijackings

#73

Earlier quoted context omitted.

The next time we swing the other way: "Maybe government should embrace popular communication media instead of spending billions on custom IT infrastructure to post a message on a custom page that everyone screenshots and copies to their timeline anyway." (Also if they don't create an "official account", someone else will do it for them)

> (Also if they don't create an "official account", someone else will do it for them) What do you mean? How would anyone not affiliated with a given government agency convince human verifiers at Twitter that they're official?

Once a public official leaves office twitter should remove all followers to zero.

Re: Twitter internal panel linked to account hijackings

#74

Earlier quoted context omitted.

The FBI is very commonly involved in cyber crimes and the other departments have a role to play as well. Calling the FBI during a major security incident is not unusual at all, I’ve done it a number of times.

In the early days of the internet the FBI was kind enough to call my employer and inform us that we had left open an anonymous FTP server, and it was serving up Disney movies. Those were good times.

FBI warned a non-profit 8 hours before news broke that the US had bombed an Iranian general. Indeed, they saved many lives.

Re: Twitter internal panel linked to account hijackings

#77

Earlier quoted context omitted.

It's painful (although I suppose all airgap solutions are) but remote access protocols like RDP or SSH tunneling to a jump host which has access to the administration portal is one common(?) solution.

That's only safer from attacks that bypass the public admin portal authentication. Any social engineering attack that steals credentials directly won't be impacted.

It’s another layer of defense. Someone has to not only know your credentials but also know how to use them to get to the jump host, and from the jump host know what to do next (although unless it’s ephemeral, there are probably enough bread crumbs to find the proper url).

Re: Twitter internal panel linked to account hijackings

#79
> Once we became aware of the incident, we immediately locked down the affected accounts and removed Tweets posted by the attackers.

This must be some new meaning of the word 'immediately' that I wasn't previously aware of. It took them quite a while to get these accounts locked.

Re: Twitter internal panel linked to account hijackings

#80

To me, it seems a little weird they can tweet on behalf of a user. Especially a user with 2FA on their account. Curious as to what types of changes might come out of this going forward

More likely a password reset to take over the account. After that an attacker can just tweet from any standard client.
Post reply on HN