Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

161–170 of 477 posts

Re: Twitter internal panel linked to account hijackings

#161

RE: social engineering, as long as a human is involved somewhere, the system can be compromised. IT security is a very depressing field because of this fact. I also hope these incidents remind people of how little control you really have over your online identity. We're all just IDs in a database somewhere, waiting to be impersonated. Decentralization is the only solution for this IMO.

Honest question, how do I recover a lost identity? The reason why this attack worked is primarily because of a recovery system. I agree this is a significant vector, but I can't see how decentralized solves this? At the moment with blockchain wallets, once you've lost your private key, you're screwed. There is no recovery. So, I'm all for decentralized but if it is truly my identity, I need a way back if I lose it. N…

What about having a revocation key? Or something similar.

Re: Twitter internal panel linked to account hijackings

#162
post #62

So it was a social engineering attack against employees with high level access. This sentence still doesn’t make sense to me: “ Once we became aware of the incident, we immediately locked down the affected accounts and removed Tweets posted by the attackers.” The accounts were posting for hours after it seemed Twitter became aware what was going on.

> The accounts were posting for hours after it seemed Twitter became aware what was going on. Oddly, it was just Elon Musk's account that had multiple tweets over a long period of time. The other accounts did just one.

No, many accounts, including Kanye continued to post follow-up comments with the same content as other accounts.

Re: Twitter internal panel linked to account hijackings

#163
post #154

Earlier quoted context omitted.

Honest question, how do I recover a lost identity? The reason why this attack worked is primarily because of a recovery system. I agree this is a significant vector, but I can't see how decentralized solves this? At the moment with blockchain wallets, once you've lost your private key, you're screwed. There is no recovery. So, I'm all for decentralized but if it is truly my identity, I need a way back if I lose it. N…

The most natural solution for most people is to give shards of your key to various friends/family that you trust not to collude and reconstitute your key (or be socially engineered -- make them talk with you on video chat or something). Require 5 out of the 9 shards to reconstitute it. Obviously you can scale up your security according to the value of your account and your threat model.

That's a great method for preventing loss as opposed to allowing recovery.

We need to keep the conversation in recovery because eventually it'll happen. Your 5/9 people could have n+1 unwilling parties where n is the losable amount.

It is unrealistic to say it will _never_ happen.

When my identity is lost... is it lost for good? how do i recover?

If it's lost for good, and i make a new 'identity' then what is my 'identity'... is it just... my reddit username?

Re: Twitter internal panel linked to account hijackings

#164
post #90

FYI for anyone working at Twitter, the legacy JS disabled mobile site still displays the hacked bitcoin tweets. For example try this with JS disabled vs enabled (404): https://mobile.twitter.com/JoeBiden/status/12835123178466590...

Wow. This does the job for me:

curl 'https://mobile.twitter.com/JoeBiden/status/12835123178466590... -H 'cookie: m5=off;'

Re: Twitter internal panel linked to account hijackings

#165
post #86

If it’s really a social engineering attack then I think it happened because everyone is working remotely and it is easier to perform social engineering attacks. Maybe this incident will have impact on their long term remote work plans.

I agree, also remote employees might not have the same layers of security as they do if they were in the office. For example, there could be a firewall that blocks malicious code at the office or someone is logging into the VPN on their home computer that is infected with malware.

I don’t work at Twitter, but at my company, Duo restricts us from sensitive web apps while on personal devices.

Re: Twitter internal panel linked to account hijackings

#166

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

Here[0] are the supposed pics of the admin panel the hackers accessed. Assuming their legit, it seems like Twitter has some blacklist features. Can't find any info detailing how they exactly work, but it seems an admin can blacklist a user from the trending page or from search results. Pretty interesting. Oddly enough, posting the screenshots resulted in some users getting their account suspended or Twitter pulling t…

Very interesting! Where’d you find this?

Re: Twitter internal panel linked to account hijackings

#167
post #90

FYI for anyone working at Twitter, the legacy JS disabled mobile site still displays the hacked bitcoin tweets. For example try this with JS disabled vs enabled (404): https://mobile.twitter.com/JoeBiden/status/12835123178466590...

Absolutely amazing. A friend and I just tested this and it's true. It makes me think this is a little more than the "rogue employee" story they're peddling.

Repro'd with:

    curl -fSsL https://mobile.twitter.com/JoeBiden/status/1283512317846659073 | grep -i bitcoin

Re: Twitter internal panel linked to account hijackings

#169
post #125

Earlier quoted context omitted.

Absolutely amazing. A friend and I just tested this and it's true. It makes me think this is a little more than the "rogue employee" story they're peddling.

I’m not sure. It could be as simple as quick hack to hide the deletions that was not deployed to the legacy site.

Seems like a huge liability. They are still disseminating these messages under the identities of major public figures, 8 hours after they became aware of it.

Re: Twitter internal panel linked to account hijackings

#170
post #98

Earlier quoted context omitted.

Well, put it this way: why is Donald Trump listed on Twitter as @realDonaldTrump? If you don't snatch up your (organization's) name first, someone will surely do so for you. (Honestly not trying to incite anything by using him as an example; I just hardly use Twitter and he was the first to come to mind.)

They own the non “real” one too, he’s just too much of a tool to use it.

Probably acquired later and didn't want to lose his followers.
Post reply on HN