Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

91–100 of 477 posts

Re: Twitter internal panel linked to account hijackings

#91
post #82

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

This makes a lot more sense. I can't imagine Twitter isn't using some sort of phsyical 2FA like yubikeys which are virtually Phish proof if implemented well. That being said, what was the employee's endgame here?

> That being said, what was the employee's endgame here?

General disgruntlement maybe? Maybe they were simply pissed off and looking for a way to hurt the company.

Re: Twitter internal panel linked to account hijackings

#92
Heh. One response I just saw complained about Trump using Twitter, since a hacker could take over his account and say anything.

Thankfully, the only good thing about Trump's complete descent into batshit insanity, and our apparent acceptance of it as a country, is that he could tweet literally anything and no one would react.

Maybe in his first year as president? But now he could tweet that he was planning on a preemptive nuclear strike against Antifa headquarters in Antarctica and we'd all wait for the White House communications office to issue a correction about what he really meant.

Re: Twitter internal panel linked to account hijackings

#93
post #86

If it’s really a social engineering attack then I think it happened because everyone is working remotely and it is easier to perform social engineering attacks. Maybe this incident will have impact on their long term remote work plans.

I dunno why you're getting downvoted. I think this idea makes some sense.

If you're doing something shady to your employer, it seems to me that it would feel a lot safer to do so while working from your home office by yourself then when sitting right in the middle of an office pod with other coworkers.

Re: Twitter internal panel linked to account hijackings

#94
Anyone else unimpressed with Twitter's U2F/FIDO token support?

They support a total of 1 (one) U2F token on an account :( The only other company I know that does that is AWS and one U2F token. Every other site I use allows multiples, usually at least 5 or more.

I setup U2F on Twitter but then got rid of it after realizing they only allow one.

Re: Twitter internal panel linked to account hijackings

#95

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in this thread[1], how many people at Twitter have the power to take over these accounts unsupervised? Whatever the number is, this hack is probably an indication that it is too high.

[1] - https://news.ycombinator.com/item?id=23855328

Re: Twitter internal panel linked to account hijackings

#96
post #82

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

This makes a lot more sense. I can't imagine Twitter isn't using some sort of phsyical 2FA like yubikeys which are virtually Phish proof if implemented well. That being said, what was the employee's endgame here?

[deleted]

Re: Twitter internal panel linked to account hijackings

#97
post #36

Earlier quoted context omitted.

[flagged]

Please stop posting unsubstantive and/or flamebait comments. It's not what this site is for, it destroys what it is for, and we ban account that do it. At least the GP comment contained actual information, however little.

Thanks for reminding got carried away.

Re: Twitter internal panel linked to account hijackings

#98

Earlier quoted context omitted.

> (Also if they don't create an "official account", someone else will do it for them) What do you mean? How would anyone not affiliated with a given government agency convince human verifiers at Twitter that they're official?

Well, put it this way: why is Donald Trump listed on Twitter as @realDonaldTrump? If you don't snatch up your (organization's) name first, someone will surely do so for you. (Honestly not trying to incite anything by using him as an example; I just hardly use Twitter and he was the first to come to mind.)

They own the non “real” one too, he’s just too much of a tool to use it.

Re: Twitter internal panel linked to account hijackings

#99
To me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc.

If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisticated attack on multiple employees via social engineering, I have to think the attackers thought about it. And if they thought about it, they weren't just after 150k of BTC.

Re: Twitter internal panel linked to account hijackings

#100
If the details about how these accounts were taken over are true, that an employee changed email addresses of these accounts to email accounts controlled by the attackers, this is going to turn out to be a massive breach.

I'm thinking specifically of direct messages that could have been scooped up before they went public and started tweeting on these accounts.

Post reply on HN