Earlier quoted context omitted.
I'm starting to think web facing site admin is a bad idea. Assuming that's what this is, I don't know. But I'm surprised it's still a thing.
Is there a better solution? How do you airgap administration of a web facing service?
Twitter internal panel linked to account hijackings
151–160 of 477 posts
Re: Twitter internal panel linked to account hijackings
#152Earlier quoted context omitted.
Is there a better solution? How do you airgap administration of a web facing service?
It's painful (although I suppose all airgap solutions are) but remote access protocols like RDP or SSH tunneling to a jump host which has access to the administration portal is one common(?) solution.
Re: Twitter internal panel linked to account hijackings
#153It would have been fascinating to see which which account had the best conversion rate.
Re: Twitter internal panel linked to account hijackings
#154RE: social engineering, as long as a human is involved somewhere, the system can be compromised. IT security is a very depressing field because of this fact. I also hope these incidents remind people of how little control you really have over your online identity. We're all just IDs in a database somewhere, waiting to be impersonated. Decentralization is the only solution for this IMO.
Honest question, how do I recover a lost identity? The reason why this attack worked is primarily because of a recovery system. I agree this is a significant vector, but I can't see how decentralized solves this? At the moment with blockchain wallets, once you've lost your private key, you're screwed. There is no recovery. So, I'm all for decentralized but if it is truly my identity, I need a way back if I lose it. N…
Obviously you can scale up your security according to the value of your account and your threat model.
Re: Twitter internal panel linked to account hijackings
#155Earlier quoted context omitted.
Isn't the whole point of Terms of Service to protect against being sued in the event of these kind of instances?
hopefully not enforceable
Re: Twitter internal panel linked to account hijackings
#156The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…
Here[0] are the supposed pics of the admin panel the hackers accessed. Assuming their legit, it seems like Twitter has some blacklist features. Can't find any info detailing how they exactly work, but it seems an admin can blacklist a user from the trending page or from search results. Pretty interesting. Oddly enough, posting the screenshots resulted in some users getting their account suspended or Twitter pulling t…
Apparently sworn statements have been made about this.
[0]: https://blog.twitter.com/en_us/topics/company/2018/Setting-t...
Re: Twitter internal panel linked to account hijackings
#157Earlier quoted context omitted.
This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…
Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…
Re: Twitter internal panel linked to account hijackings
#158I suspected some sort of internal tool was used to target prominent users but I’m still curious why there were thousands of unverified accounts tweeting the same scam. Searching for that bitcoin address pulled up tons of accounts tweeting it shortly before that term was blocked. Are there really that many trolls out there, or was a very large set of accounts hacked?
Re: Twitter internal panel linked to account hijackings
#159I suspected some sort of internal tool was used to target prominent users but I’m still curious why there were thousands of unverified accounts tweeting the same scam. Searching for that bitcoin address pulled up tons of accounts tweeting it shortly before that term was blocked. Are there really that many trolls out there, or was a very large set of accounts hacked?
Re: Twitter internal panel linked to account hijackings
#160With the info we have it looks like hackers changed the email id of the accounts and then used forgot password to reset the password. What’s concerning is that they were able to do it for accounts with 2FA enabled. I think disabling 2FA should be extremely privileged actions and should not accessible to most employees.