Earlier quoted context omitted.
Based on what we know, it does sound like the attackers had full access to the accounts. That's a really interesting point about direct messages. It makes it all the more interesting that Obama and Biden and were both targets with the upcoming election. Wonder if those will start showing up on WikiLeaks again.
Does anybody on Hacker news seriously believe that the account of Biden or Obama actually send messages privately on Twitter? They most certainly don't. I have no idea why that fact is not obvious to some. Trump had two liked tweets for all of time back from like, 2012. Around 2017 or so a group realized this and bought or otherwise messed with the site the liked tweets linked to and made them have pictures making jo…
Twitter internal panel linked to account hijackings
131–140 of 477 posts
Re: Twitter internal panel linked to account hijackings
#132Anyone else unimpressed with Twitter's U2F/FIDO token support? They support a total of 1 (one) U2F token on an account :( The only other company I know that does that is AWS and one U2F token. Every other site I use allows multiples, usually at least 5 or more. I setup U2F on Twitter but then got rid of it after realizing they only allow one.
the entirety of AWS seems to be half assed in general as you've described: the U2F functionality is completely useless because if you lose/break your single U2F key then you're completely screwed and they still have no support for ed25519 keys (which were added to OpenSSH in 2013), unlike every other cloud service I have to have an RSA key just for AWS (particuraly annoying as I have all my other ssh keys stored in a…
That thought makes it so much for frustrating. ed25519 is the future anyway, it’s hilarious how many cling to RSA (I’ve got nothing against RSA but at some point we’ll have to switch anyway)
Re: Twitter internal panel linked to account hijackings
#133To me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisti…
Re: Twitter internal panel linked to account hijackings
#134Earlier quoted context omitted.
This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…
The most logical conclusion is that this probably wasn't about money. Plenty of better ways to make money than telling people to give you BTC. I'm expecting a huge data drop on wikileaks/pastebin/wherever of private DMs, images, who knows what else.
People seem to assume everyone takes tweets at face value and won't do a double take when it doesn't sound like something they would normally say.
Even here there was plenty of people on HN who were claiming outlandish possibilities while it was happening.
Re: Twitter internal panel linked to account hijackings
#135> Hawley said "please reach out immediately to the Department of Justice and the Federal Bureau of Investigation and take any necessary measures to secure the site before this breach expands It's kind of bizarre when you have the highest levels of government doing their critical communication on a free social media service to the point where they are critically dependent on it, then begging for support when things go…
> Maybe you shouldn't use a free service that is not under your control or any proper regulatory or quality constraints for your most important messaging to the public then?
What are you referring to exactly? I thought the govt had their own IT and websites across the board, and only used things like twitter to aid in communicating to the public.
Re: Twitter internal panel linked to account hijackings
#136> Hawley said "please reach out immediately to the Department of Justice and the Federal Bureau of Investigation and take any necessary measures to secure the site before this breach expands It's kind of bizarre when you have the highest levels of government doing their critical communication on a free social media service to the point where they are critically dependent on it, then begging for support when things go…
The FBI is very commonly involved in cyber crimes and the other departments have a role to play as well. Calling the FBI during a major security incident is not unusual at all, I’ve done it a number of times.
Re: Twitter internal panel linked to account hijackings
#137Re: Twitter internal panel linked to account hijackings
#138Earlier quoted context omitted.
Based on what we know, it does sound like the attackers had full access to the accounts. That's a really interesting point about direct messages. It makes it all the more interesting that Obama and Biden and were both targets with the upcoming election. Wonder if those will start showing up on WikiLeaks again.
Does anybody on Hacker news seriously believe that the account of Biden or Obama actually send messages privately on Twitter? They most certainly don't. I have no idea why that fact is not obvious to some. Trump had two liked tweets for all of time back from like, 2012. Around 2017 or so a group realized this and bought or otherwise messed with the site the liked tweets linked to and made them have pictures making jo…
But Elon? Some of these bitcoin exchanges? Maybe. How about accounts that were accessed (if any) that never blasted out the bitcoin tweet, but had their messages harvested?
Re: Twitter internal panel linked to account hijackings
#139Earlier quoted context omitted.
Based on what we know, it does sound like the attackers had full access to the accounts. That's a really interesting point about direct messages. It makes it all the more interesting that Obama and Biden and were both targets with the upcoming election. Wonder if those will start showing up on WikiLeaks again.
Does anybody on Hacker news seriously believe that the account of Biden or Obama actually send messages privately on Twitter? They most certainly don't. I have no idea why that fact is not obvious to some. Trump had two liked tweets for all of time back from like, 2012. Around 2017 or so a group realized this and bought or otherwise messed with the site the liked tweets linked to and made them have pictures making jo…
Also, I really hope there’s a set of users whose accounts cannot have new devices connected without special authorization, and if so, you’d have Biden, Obama and Trump on that list.
Edit: 5 minutes after posting, I saw Obama and Biden were on the list of people hit, and I missed it in the early reports. Unbelievable.
Re: Twitter internal panel linked to account hijackings
#140The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…
This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…
On the other hand, $1M in BTC might do the trick. Interesting thought experiment...