Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

141–150 of 477 posts

Re: Twitter internal panel linked to account hijackings

#141
post #50

Twitter confirmed that the attack used internal tools, and thinks the attacker used social engineering on employees: https://twitter.com/TwitterSupport/status/128359184496275046...

article has been updated as well to include:

>"We used a rep that literally done all the work for us," one of the sources told Motherboard. The second source added they paid the Twitter insider. …

Re: Twitter internal panel linked to account hijackings

#142
post #86

If it’s really a social engineering attack then I think it happened because everyone is working remotely and it is easier to perform social engineering attacks. Maybe this incident will have impact on their long term remote work plans.

I agree, also remote employees might not have the same layers of security as they do if they were in the office. For example, there could be a firewall that blocks malicious code at the office or someone is logging into the VPN on their home computer that is infected with malware.

Re: Twitter internal panel linked to account hijackings

#143

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

USD, the WD-40 of social engineering

Re: Twitter internal panel linked to account hijackings

#144
post #94

Anyone else unimpressed with Twitter's U2F/FIDO token support? They support a total of 1 (one) U2F token on an account :( The only other company I know that does that is AWS and one U2F token. Every other site I use allows multiples, usually at least 5 or more. I setup U2F on Twitter but then got rid of it after realizing they only allow one.

Isn't it kind of insane to lock your account into using a single U2F/FIDO key? Lost the physical key, lose the account?

Twitter doesn't let you disable SMS verification so that's their answer. :/

Re: Twitter internal panel linked to account hijackings

#145
post #70

Earlier quoted context omitted.

Which shows that Twitter probably doesn't properly employ 2FA and two-person-principle when dealing with high-profile accounts. Otherwise, social engineering would have been almost impossible.

If it’s SMS the attacker could have social engineered (big cell service co) to get access to the employee’s phone # and get a SIM. I’m guessing someone re-used a hacked password and SMS 2FA is to blame. Maybe it’s not even that sophisticated.

They should be using things like yubikey though, not phones

Re: Twitter internal panel linked to account hijackings

#146

RE: social engineering, as long as a human is involved somewhere, the system can be compromised. IT security is a very depressing field because of this fact. I also hope these incidents remind people of how little control you really have over your online identity. We're all just IDs in a database somewhere, waiting to be impersonated. Decentralization is the only solution for this IMO.

Honest question, how do I recover a lost identity? The reason why this attack worked is primarily because of a recovery system. I agree this is a significant vector, but I can't see how decentralized solves this? At the moment with blockchain wallets, once you've lost your private key, you're screwed. There is no recovery. So, I'm all for decentralized but if it is truly my identity, I need a way back if I lose it. N…

You need to stop thinking identity singular, and identity as valuable. Have many and treat them as disposable. Of course you can't do this on the 2020 web that consists of four websites filled with screenshots of each other, but that's just one of the many reasons to burn those websites to the ground and resist any attempts to remake them. And it turns out your parents were right about not using your real name on the Internet. Social media and their consequences have been a disaster for the human race.

Re: Twitter internal panel linked to account hijackings

#147

Earlier quoted context omitted.

If it’s SMS the attacker could have social engineered (big cell service co) to get access to the employee’s phone # and get a SIM. I’m guessing someone re-used a hacked password and SMS 2FA is to blame. Maybe it’s not even that sophisticated.

They should be using things like yubikey though, not phones

Definitely, TOTP at least.

Re: Twitter internal panel linked to account hijackings

#148
post #70

Earlier quoted context omitted.

Which shows that Twitter probably doesn't properly employ 2FA and two-person-principle when dealing with high-profile accounts. Otherwise, social engineering would have been almost impossible.

If it’s SMS the attacker could have social engineered (big cell service co) to get access to the employee’s phone # and get a SIM. I’m guessing someone re-used a hacked password and SMS 2FA is to blame. Maybe it’s not even that sophisticated.

That seems unlikely. The scale of the attack and the profile of the accounts just doesn't seem to me that would be the case.

I'd like to think it's a bit harder to intercept a former President's text messages.

Re: Twitter internal panel linked to account hijackings

#149
This is why the concept of a blast radius exists.

It is so important to critically examine and limit the blast radius of administrative actions. This is both from a vulnerability perspective as well as honest human mistakes.

For certain actions like taking over an account and impersonation there should be rate limits all around. Overriding them requires a break glass process where multiple people may have to approve (or even just acknowledge that it is happening).

Social engineering happens. It can happen to the best of us who hold the keys to the kingdom. The goal is that no one individual can completely break all the barriers. They need a bit of help, time, or both.

Re: Twitter internal panel linked to account hijackings

#150
post #87
post #35

Earlier quoted context omitted.

>Maybe you shouldn't use a free service that is not under your control or any proper regulatory or quality constraints for your most important messaging to the public then? But we hate it when governments spend money on things. And no one would trust a word that came from any service the government controlled or regulated.

A simple official website is enough for hosting a list of short statements.

If the goal is to simply publish statements, the press already exists for that. The value of a platform like Twitter is in the network and communication. Twitter already has politicians and official accounts from around the world, and millions of users. I don't know how a particular state-owned platform could replicate that... and let's not get into the technical acumen that government contracts lead to. Remember the debacle that was the Obamacare website right after launch.

And on top of all of that, people will still complain that their tax dollars are being used rather than existing public platforms (Twitter, Facebook, etc.) Whichever administration puts it up, the next administration of the opposing party will call it waste and propaganda and burn it down.

Post reply on HN