Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

171–180 of 477 posts

Re: Twitter internal panel linked to account hijackings

#172

Earlier quoted context omitted.

Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…

I’m not saying there isn’t one, but curious what you think is the imprisonable offense?

I’m not a lawyer, but I’d guess something related to wire fraud: https://www.justice.gov/archives/jm/criminal-resource-manual...

Re: Twitter internal panel linked to account hijackings

#173

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

The term "social engineering hack" is doubtful. This is the social engineering hack: "I am very important Twitter board member, give me an access to the internal tool." To gain access by bribe, coerce or persuade the frustrated low paid worker is not.

Re: Twitter internal panel linked to account hijackings

#174

Earlier quoted context omitted.

Honest question, how do I recover a lost identity? The reason why this attack worked is primarily because of a recovery system. I agree this is a significant vector, but I can't see how decentralized solves this? At the moment with blockchain wallets, once you've lost your private key, you're screwed. There is no recovery. So, I'm all for decentralized but if it is truly my identity, I need a way back if I lose it. N…

You need to stop thinking identity singular, and identity as valuable. Have many and treat them as disposable. Of course you can't do this on the 2020 web that consists of four websites filled with screenshots of each other, but that's just one of the many reasons to burn those websites to the ground and resist any attempts to remake them. And it turns out your parents were right about not using your real name on the…

But that's not really identity then right? That just becomes my hnews/reddit username that's unverified.

I read @elonmusk because I trust it's him and I'm interested in what he says. Personally, I genuinely like Starship + Starlink updates... I ignore most the other stuff. But still, I want to see those awesome rocket tweets!

So, I want to know what he says.

He can change his username because it got hacked/whatever... but then I personally have to see what he changed it to... how do I know that he is the one who changed it? how do i know it's not some rando dude impersonating him?

Re: Twitter internal panel linked to account hijackings

#177
> "We used a rep that literally done all the work for us"

This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no technical countermeasures.

I'd like to see a system where it is physically impossible for a customer service rep to discover any info about me until I authenticate and authorize it. Or to at least offer me the option to lock my account such that I need to authenticate and authorize before any access is given to the customer service rep.

Does anyone know of customer service panels at big companies or government departments where this is the case? I.e., it is literally impossible for a rep to browse random customer information even if they are willing to break the rules? If it's been done somewhere, it would be interesting to hear how it was implemented.

Re: Twitter internal panel linked to account hijackings

#178
post #95

Earlier quoted context omitted.

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

The most reasonable explanation might be that they’re lying to sound cool. Bribery is a thing, but any twitter employee would know that their employment (and future career prospects) would be terminated. On the other hand, $1M in BTC might do the trick. Interesting thought experiment...

There’s bribery but I think blackmail is even likelier. This is such a huge breach that no one should think they could get away with leaking their credentials or opening a backdoor. Plus Twitter employees are really well paid. Now some life-ruining online behavior material is another type of a motivator.

Re: Twitter internal panel linked to account hijackings

#179
post #171

Wait a second...they were hacked in a way that makes it so we can't trust any tweets. Does it make sense, then, for them to use tweets to report their progress on addressing this?

Why not? They're not updating HN with those but media and shareholders.

Re: Twitter internal panel linked to account hijackings

#180
post #120
post #113

Earlier quoted context omitted.

Based on what we know, it does sound like the attackers had full access to the accounts. That's a really interesting point about direct messages. It makes it all the more interesting that Obama and Biden and were both targets with the upcoming election. Wonder if those will start showing up on WikiLeaks again.

Does anybody on Hacker news seriously believe that the account of Biden or Obama actually send messages privately on Twitter? They most certainly don't. I have no idea why that fact is not obvious to some. Trump had two liked tweets for all of time back from like, 2012. Around 2017 or so a group realized this and bought or otherwise messed with the site the liked tweets linked to and made them have pictures making jo…

There's no need for them to actually have any messages.

With a highly public hack like this one can simply manufacture messages afterwards and claim they came from the hack. Most people would believe it.

Post reply on HN