Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

101–110 of 477 posts

Re: Twitter internal panel linked to account hijackings

#101

> Once we became aware of the incident, we immediately locked down the affected accounts and removed Tweets posted by the attackers. This must be some new meaning of the word 'immediately' that I wasn't previously aware of. It took them quite a while to get these accounts locked.

Or maybe it took them quite a while to "become aware of the incident" in the first place, but that's just as bad.

Re: Twitter internal panel linked to account hijackings

#102
post #17

> Hawley said "please reach out immediately to the Department of Justice and the Federal Bureau of Investigation and take any necessary measures to secure the site before this breach expands It's kind of bizarre when you have the highest levels of government doing their critical communication on a free social media service to the point where they are critically dependent on it, then begging for support when things go…

The next time we swing the other way: "Maybe government should embrace popular communication media instead of spending billions on custom IT infrastructure to post a message on a custom page that everyone screenshots and copies to their timeline anyway." (Also if they don't create an "official account", someone else will do it for them)

Kind of a false opposite you got there.

The government could put it's decisions and publications on a website, official, verified, more or less controlled by them. There's no reason that has to be done with consultant scams - oppositely, posting on Twitter doesn't guarantee consultants aren't raking in money for adding or removing periods or whatever.

Re: Twitter internal panel linked to account hijackings

#103
post #76

I find it hard to believe this was a Social Engineering based attack. Elon Musk’s account was accessed multiple times after their tweets being deleted and it seemed to last forever, account by account being taken over.

They social engineered access to a Twitter employees internal account, not the individual end users affected.

Re: Twitter internal panel linked to account hijackings

#104

RE: social engineering, as long as a human is involved somewhere, the system can be compromised. IT security is a very depressing field because of this fact. I also hope these incidents remind people of how little control you really have over your online identity. We're all just IDs in a database somewhere, waiting to be impersonated. Decentralization is the only solution for this IMO.

Honest question, how do I recover a lost identity?

The reason why this attack worked is primarily because of a recovery system. I agree this is a significant vector, but I can't see how decentralized solves this?

At the moment with blockchain wallets, once you've lost your private key, you're screwed. There is no recovery.

So, I'm all for decentralized but if it is truly my identity, I need a way back if I lose it. Not sure how to solve that vector even in a decentralized case.

Do I need to upload my identity to specific 'verifiers'?

Re: Twitter internal panel linked to account hijackings

#105
post #94

Anyone else unimpressed with Twitter's U2F/FIDO token support? They support a total of 1 (one) U2F token on an account :( The only other company I know that does that is AWS and one U2F token. Every other site I use allows multiples, usually at least 5 or more. I setup U2F on Twitter but then got rid of it after realizing they only allow one.

AWS has a simple workaround though as you can create as many users as you want, each with its own unique token. Combined with roles it’s straightforward to set up a backup user / device.

It makes sense technically to have a single token anyway. Otherwise you either need to include then identifier of the auth token (in addition to the secret) or have the verification step try out all N options.

Re: Twitter internal panel linked to account hijackings

#106
post #94

Anyone else unimpressed with Twitter's U2F/FIDO token support? They support a total of 1 (one) U2F token on an account :( The only other company I know that does that is AWS and one U2F token. Every other site I use allows multiples, usually at least 5 or more. I setup U2F on Twitter but then got rid of it after realizing they only allow one.

Isn't it kind of insane to lock your account into using a single U2F/FIDO key? Lost the physical key, lose the account?

Re: Twitter internal panel linked to account hijackings

#107
post #95

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

The most logical conclusion is that this probably wasn't about money. Plenty of better ways to make money than telling people to give you BTC. I'm expecting a huge data drop on wikileaks/pastebin/wherever of private DMs, images, who knows what else.

Re: Twitter internal panel linked to account hijackings

#108
post #90

FYI for anyone working at Twitter, the legacy JS disabled mobile site still displays the hacked bitcoin tweets. For example try this with JS disabled vs enabled (404): https://mobile.twitter.com/JoeBiden/status/12835123178466590...

Absolutely amazing. A friend and I just tested this and it's true. It makes me think this is a little more than the "rogue employee" story they're peddling.

Re: Twitter internal panel linked to account hijackings

#109
post #82

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

This makes a lot more sense. I can't imagine Twitter isn't using some sort of phsyical 2FA like yubikeys which are virtually Phish proof if implemented well. That being said, what was the employee's endgame here?

2fa won’t protect from a Trojan.

Re: Twitter internal panel linked to account hijackings

#110
With the info we have it looks like hackers changed the email id of the accounts and then used forgot password to reset the password. What’s concerning is that they were able to do it for accounts with 2FA enabled. I think disabling 2FA should be extremely privileged actions and should not accessible to most employees.
Post reply on HN