Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

151–160 of 477 posts

Re: Twitter internal panel linked to account hijackings

#151
post #41
post #34

Earlier quoted context omitted.

I'm starting to think web facing site admin is a bad idea. Assuming that's what this is, I don't know. But I'm surprised it's still a thing.

Is there a better solution? How do you airgap administration of a web facing service?

IP restrict the admin console at the application or (better) firewall layer. This means you need to VPN in to use it offsite. Put MFA on your VPN. None of this will save you from a malicious internal actor.

Re: Twitter internal panel linked to account hijackings

#152
post #41

Earlier quoted context omitted.

Is there a better solution? How do you airgap administration of a web facing service?

It's painful (although I suppose all airgap solutions are) but remote access protocols like RDP or SSH tunneling to a jump host which has access to the administration portal is one common(?) solution.

The point is, that's not an airgap; RDP and ssh tunneling are transititive and we're all logging on from home right now.

Re: Twitter internal panel linked to account hijackings

#154

RE: social engineering, as long as a human is involved somewhere, the system can be compromised. IT security is a very depressing field because of this fact. I also hope these incidents remind people of how little control you really have over your online identity. We're all just IDs in a database somewhere, waiting to be impersonated. Decentralization is the only solution for this IMO.

Honest question, how do I recover a lost identity? The reason why this attack worked is primarily because of a recovery system. I agree this is a significant vector, but I can't see how decentralized solves this? At the moment with blockchain wallets, once you've lost your private key, you're screwed. There is no recovery. So, I'm all for decentralized but if it is truly my identity, I need a way back if I lose it. N…

The most natural solution for most people is to give shards of your key to various friends/family that you trust not to collude and reconstitute your key (or be socially engineered -- make them talk with you on video chat or something). Require 5 out of the 9 shards to reconstitute it.

Obviously you can scale up your security according to the value of your account and your threat model.

Re: Twitter internal panel linked to account hijackings

#155
post #67

Earlier quoted context omitted.

Isn't the whole point of Terms of Service to protect against being sued in the event of these kind of instances?

hopefully not enforceable

Anyone dumb enough to give money to a "double your bitcoins" scan deserves what they get, even if it is apparently endorsed by celebrities

Re: Twitter internal panel linked to account hijackings

#156

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

Here[0] are the supposed pics of the admin panel the hackers accessed. Assuming their legit, it seems like Twitter has some blacklist features. Can't find any info detailing how they exactly work, but it seems an admin can blacklist a user from the trending page or from search results. Pretty interesting. Oddly enough, posting the screenshots resulted in some users getting their account suspended or Twitter pulling t…

This could end up being a big deal in the days to come if legitimate. Twitter has made strong public statements that they don't have shadow banning tools[0].

Apparently sworn statements have been made about this.

[0]: https://blog.twitter.com/en_us/topics/company/2018/Setting-t...

Re: Twitter internal panel linked to account hijackings

#157
post #95

Earlier quoted context omitted.

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…

I’m not saying there isn’t one, but curious what you think is the imprisonable offense?

Re: Twitter internal panel linked to account hijackings

#158

I suspected some sort of internal tool was used to target prominent users but I’m still curious why there were thousands of unverified accounts tweeting the same scam. Searching for that bitcoin address pulled up tons of accounts tweeting it shortly before that term was blocked. Are there really that many trolls out there, or was a very large set of accounts hacked?

I’m sure a lot of mere twitter mortals were enjoying a sweet schadenfreude moment.

Re: Twitter internal panel linked to account hijackings

#159

I suspected some sort of internal tool was used to target prominent users but I’m still curious why there were thousands of unverified accounts tweeting the same scam. Searching for that bitcoin address pulled up tons of accounts tweeting it shortly before that term was blocked. Are there really that many trolls out there, or was a very large set of accounts hacked?

Could some of those just be ordinary people who fell for the scam, or bots that retweet top accounts?

Re: Twitter internal panel linked to account hijackings

#160
post #110

With the info we have it looks like hackers changed the email id of the accounts and then used forgot password to reset the password. What’s concerning is that they were able to do it for accounts with 2FA enabled. I think disabling 2FA should be extremely privileged actions and should not accessible to most employees.

They apparently have another level of auth, used for at least Trump's account. And probably the CEO's considering past events.
Post reply on HN