RE: social engineering, as long as a human is involved somewhere, the system can be compromised. IT security is a very depressing field because of this fact. I also hope these incidents remind people of how little control you really have over your online identity. We're all just IDs in a database somewhere, waiting to be impersonated. Decentralization is the only solution for this IMO.
Honest question, how do I recover a lost identity? The reason why this attack worked is primarily because of a recovery system. I agree this is a significant vector, but I can't see how decentralized solves this? At the moment with blockchain wallets, once you've lost your private key, you're screwed. There is no recovery. So, I'm all for decentralized but if it is truly my identity, I need a way back if I lose it. N…
Twitter internal panel linked to account hijackings
161–170 of 477 posts
Re: Twitter internal panel linked to account hijackings
#162So it was a social engineering attack against employees with high level access. This sentence still doesn’t make sense to me: “ Once we became aware of the incident, we immediately locked down the affected accounts and removed Tweets posted by the attackers.” The accounts were posting for hours after it seemed Twitter became aware what was going on.
> The accounts were posting for hours after it seemed Twitter became aware what was going on. Oddly, it was just Elon Musk's account that had multiple tweets over a long period of time. The other accounts did just one.
Re: Twitter internal panel linked to account hijackings
#163Earlier quoted context omitted.
Honest question, how do I recover a lost identity? The reason why this attack worked is primarily because of a recovery system. I agree this is a significant vector, but I can't see how decentralized solves this? At the moment with blockchain wallets, once you've lost your private key, you're screwed. There is no recovery. So, I'm all for decentralized but if it is truly my identity, I need a way back if I lose it. N…
The most natural solution for most people is to give shards of your key to various friends/family that you trust not to collude and reconstitute your key (or be socially engineered -- make them talk with you on video chat or something). Require 5 out of the 9 shards to reconstitute it. Obviously you can scale up your security according to the value of your account and your threat model.
We need to keep the conversation in recovery because eventually it'll happen. Your 5/9 people could have n+1 unwilling parties where n is the losable amount.
It is unrealistic to say it will _never_ happen.
When my identity is lost... is it lost for good? how do i recover?
If it's lost for good, and i make a new 'identity' then what is my 'identity'... is it just... my reddit username?
Re: Twitter internal panel linked to account hijackings
#164FYI for anyone working at Twitter, the legacy JS disabled mobile site still displays the hacked bitcoin tweets. For example try this with JS disabled vs enabled (404): https://mobile.twitter.com/JoeBiden/status/12835123178466590...
curl 'https://mobile.twitter.com/JoeBiden/status/12835123178466590... -H 'cookie: m5=off;'
Re: Twitter internal panel linked to account hijackings
#165If it’s really a social engineering attack then I think it happened because everyone is working remotely and it is easier to perform social engineering attacks. Maybe this incident will have impact on their long term remote work plans.
I agree, also remote employees might not have the same layers of security as they do if they were in the office. For example, there could be a firewall that blocks malicious code at the office or someone is logging into the VPN on their home computer that is infected with malware.
Re: Twitter internal panel linked to account hijackings
#166The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…
Here[0] are the supposed pics of the admin panel the hackers accessed. Assuming their legit, it seems like Twitter has some blacklist features. Can't find any info detailing how they exactly work, but it seems an admin can blacklist a user from the trending page or from search results. Pretty interesting. Oddly enough, posting the screenshots resulted in some users getting their account suspended or Twitter pulling t…
Re: Twitter internal panel linked to account hijackings
#167FYI for anyone working at Twitter, the legacy JS disabled mobile site still displays the hacked bitcoin tweets. For example try this with JS disabled vs enabled (404): https://mobile.twitter.com/JoeBiden/status/12835123178466590...
Absolutely amazing. A friend and I just tested this and it's true. It makes me think this is a little more than the "rogue employee" story they're peddling.
curl -fSsL https://mobile.twitter.com/JoeBiden/status/1283512317846659073 | grep -i bitcoinRe: Twitter internal panel linked to account hijackings
#168Re: Twitter internal panel linked to account hijackings
#169Earlier quoted context omitted.
Absolutely amazing. A friend and I just tested this and it's true. It makes me think this is a little more than the "rogue employee" story they're peddling.
I’m not sure. It could be as simple as quick hack to hide the deletions that was not deployed to the legacy site.
Re: Twitter internal panel linked to account hijackings
#170Earlier quoted context omitted.
Well, put it this way: why is Donald Trump listed on Twitter as @realDonaldTrump? If you don't snatch up your (organization's) name first, someone will surely do so for you. (Honestly not trying to incite anything by using him as an example; I just hardly use Twitter and he was the first to come to mind.)
They own the non “real” one too, he’s just too much of a tool to use it.