Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

81–90 of 477 posts

Re: Twitter internal panel linked to account hijackings

#81

Didnt @jack testify before congress that twitter didnt blacklist accounts?

What does that have to do with this?

In the screenshots of the admin panel, it looks like they have blacklists of things that shouldn't show up in searches or on trending. It's not clear if it's accounts, or some other criteria that's blacklisted though.

Re: Twitter internal panel linked to account hijackings

#82

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

This makes a lot more sense. I can't imagine Twitter isn't using some sort of phsyical 2FA like yubikeys which are virtually Phish proof if implemented well.

That being said, what was the employee's endgame here?

Re: Twitter internal panel linked to account hijackings

#83

To me, it seems a little weird they can tweet on behalf of a user. Especially a user with 2FA on their account. Curious as to what types of changes might come out of this going forward

There's always someone, usually many people, with abilities like this for any service that's automated enough. Even for banks, as much as they might try to separate portions and mitigate access. The solution is not making it impossible, it's making it easy to find out if it was done and being very careful who you put in those roles. That's just the nature of the world.

Re: Twitter internal panel linked to account hijackings

#85

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

If true, then what Twitter officially posted makes more sense.

Without this bit of information from Vice it would make what Twitter officially posted downright scary and not add any comfort factor to what the heck is really going on.

Re: Twitter internal panel linked to account hijackings

#87
post #35
post #17

> Hawley said "please reach out immediately to the Department of Justice and the Federal Bureau of Investigation and take any necessary measures to secure the site before this breach expands It's kind of bizarre when you have the highest levels of government doing their critical communication on a free social media service to the point where they are critically dependent on it, then begging for support when things go…

>Maybe you shouldn't use a free service that is not under your control or any proper regulatory or quality constraints for your most important messaging to the public then? But we hate it when governments spend money on things. And no one would trust a word that came from any service the government controlled or regulated.

A simple official website is enough for hosting a list of short statements.

Re: Twitter internal panel linked to account hijackings

#88
post #17

> Hawley said "please reach out immediately to the Department of Justice and the Federal Bureau of Investigation and take any necessary measures to secure the site before this breach expands It's kind of bizarre when you have the highest levels of government doing their critical communication on a free social media service to the point where they are critically dependent on it, then begging for support when things go…

The next time we swing the other way: "Maybe government should embrace popular communication media instead of spending billions on custom IT infrastructure to post a message on a custom page that everyone screenshots and copies to their timeline anyway." (Also if they don't create an "official account", someone else will do it for them)

> Also if they don't create an "official account", someone else will do it for them

Yes, but this account will still not have the same legitimacy. Right now, if Trump tweeted a declaration of war, it would have been reasonable to assume that it was real, because, for all we know, it's an official channel. Previously at lot of people would've at least checked back with the official channel before taking it for granted.

And, to make matters worse, having Twitter as an official channel now gives everyone at Twitter the possibility to make official announcements - hardly a good state of affairs.

Re: Twitter internal panel linked to account hijackings

#89
post #82

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

This makes a lot more sense. I can't imagine Twitter isn't using some sort of phsyical 2FA like yubikeys which are virtually Phish proof if implemented well. That being said, what was the employee's endgame here?

avoid some other blackmail
Post reply on HN