Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

111–120 of 477 posts

Re: Twitter internal panel linked to account hijackings

#111
post #105
post #94

Anyone else unimpressed with Twitter's U2F/FIDO token support? They support a total of 1 (one) U2F token on an account :( The only other company I know that does that is AWS and one U2F token. Every other site I use allows multiples, usually at least 5 or more. I setup U2F on Twitter but then got rid of it after realizing they only allow one.

AWS has a simple workaround though as you can create as many users as you want, each with its own unique token. Combined with roles it’s straightforward to set up a backup user / device. It makes sense technically to have a single token anyway. Otherwise you either need to include then identifier of the auth token (in addition to the secret) or have the verification step try out all N options.

> It makes sense technically to have a single token anyway. Otherwise you either need to include then identifier of the auth token (in addition to the secret) or have the verification step try out all N options.

I'm not sure if that is true. Most sites support multiple tokens. Off the top of my head I can think of Google, Facebook, Github, Gitlab, and more that support multiple. So it seems like the normal method is to support multiple.

One one site I have over 5 auth tokens configured. And tested with four of them connected to my PC at the same time. I could tap on any one of them to authenticate. This is on a Windows 10 PC.

Re: Twitter internal panel linked to account hijackings

#112

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

Here[0] are the supposed pics of the admin panel the hackers accessed. Assuming their legit, it seems like Twitter has some blacklist features. Can't find any info detailing how they exactly work, but it seems an admin can blacklist a user from the trending page or from search results. Pretty interesting.

Oddly enough, posting the screenshots resulted in some users getting their account suspended or Twitter pulling the picture down.

[0]: https://video-images.vice.com/test-uploads/_uncategorized/15...

Re: Twitter internal panel linked to account hijackings

#113

If the details about how these accounts were taken over are true, that an employee changed email addresses of these accounts to email accounts controlled by the attackers, this is going to turn out to be a massive breach. I'm thinking specifically of direct messages that could have been scooped up before they went public and started tweeting on these accounts.

Based on what we know, it does sound like the attackers had full access to the accounts. That's a really interesting point about direct messages. It makes it all the more interesting that Obama and Biden and were both targets with the upcoming election. Wonder if those will start showing up on WikiLeaks again.

Re: Twitter internal panel linked to account hijackings

#114

> Once we became aware of the incident, we immediately locked down the affected accounts and removed Tweets posted by the attackers. This must be some new meaning of the word 'immediately' that I wasn't previously aware of. It took them quite a while to get these accounts locked.

Or maybe it took them quite a while to "become aware of the incident" in the first place, but that's just as bad.

They spent an hour or two deleting tweets on Elon Musk's account, with new tweets appearing soon after. So it seemed like they were aware of his account being compromised but did not immediately [successfully] lock his account.

Re: Twitter internal panel linked to account hijackings

#115

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

I actually highly doubt this is true. Collusion doesn't seem likely, especially with jail time very probable.

Some of the scuttlebutt says that these guys are tied to multiple crypto hacks.

But my personal opinion is that this is just a 20-something trying to make a mark for themselves. We'll see within a week or two.

Re: Twitter internal panel linked to account hijackings

#117
post #76

I find it hard to believe this was a Social Engineering based attack. Elon Musk’s account was accessed multiple times after their tweets being deleted and it seemed to last forever, account by account being taken over.

They social engineered access to a Twitter employees internal account, not the individual end users affected.

I understand, but that sort of behaviour should have been thwarted quickly by their security team or policies setup against abuse.

Re: Twitter internal panel linked to account hijackings

#118
post #94

Anyone else unimpressed with Twitter's U2F/FIDO token support? They support a total of 1 (one) U2F token on an account :( The only other company I know that does that is AWS and one U2F token. Every other site I use allows multiples, usually at least 5 or more. I setup U2F on Twitter but then got rid of it after realizing they only allow one.

the entirety of AWS seems to be half assed in general

as you've described: the U2F functionality is completely useless because if you lose/break your single U2F key then you're completely screwed

and they still have no support for ed25519 keys (which were added to OpenSSH in 2013), unlike every other cloud service

I have to have an RSA key just for AWS (particuraly annoying as I have all my other ssh keys stored in a hardware token)

if they didn't validate the damn key type then it would probably just work out of the box

Re: Twitter internal panel linked to account hijackings

#119
post #86

If it’s really a social engineering attack then I think it happened because everyone is working remotely and it is easier to perform social engineering attacks. Maybe this incident will have impact on their long term remote work plans.

It might make it harder to stop once it's in progress since you can't physically remove the employee from their workstation.

Re: Twitter internal panel linked to account hijackings

#120
post #113

If the details about how these accounts were taken over are true, that an employee changed email addresses of these accounts to email accounts controlled by the attackers, this is going to turn out to be a massive breach. I'm thinking specifically of direct messages that could have been scooped up before they went public and started tweeting on these accounts.

Based on what we know, it does sound like the attackers had full access to the accounts. That's a really interesting point about direct messages. It makes it all the more interesting that Obama and Biden and were both targets with the upcoming election. Wonder if those will start showing up on WikiLeaks again.

Does anybody on Hacker news seriously believe that the account of Biden or Obama actually send messages privately on Twitter?

They most certainly don't. I have no idea why that fact is not obvious to some.

Trump had two liked tweets for all of time back from like, 2012. Around 2017 or so a group realized this and bought or otherwise messed with the site the liked tweets linked to and made them have pictures making jokes about trump. It took more than a year for anybody to give a shit enough to take down. They don't use the site for anything more than direct statements/retweets.

Post reply on HN