Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

181–190 of 477 posts

Re: Twitter internal panel linked to account hijackings

#181

Earlier quoted context omitted.

Here[0] are the supposed pics of the admin panel the hackers accessed. Assuming their legit, it seems like Twitter has some blacklist features. Can't find any info detailing how they exactly work, but it seems an admin can blacklist a user from the trending page or from search results. Pretty interesting. Oddly enough, posting the screenshots resulted in some users getting their account suspended or Twitter pulling t…

This could end up being a big deal in the days to come if legitimate. Twitter has made strong public statements that they don't have shadow banning tools[0]. Apparently sworn statements have been made about this. [0]: https://blog.twitter.com/en_us/topics/company/2018/Setting-t...

To be fair, the linked article states that they do not shadow ban, not that they don’t have the capability/tools to shadow ban.

Also what do people consider as a shadow ban?

- Removing the tweets from people’s feeds, and only showing them if you browse/go to the offending users profile ? (Personally I don’t think this counts as a shadow ban)

- The offending user is the only person who can see their tweets, even if other users look at their profile (This is shadow banning imo)

Re: Twitter internal panel linked to account hijackings

#182
post #40

According to some images, Twitter low level employees can see email address of all accounts (and I guess phone numbers). I know some celebrities have their real email address and phone numbers on those accounts. Isn't that something bad?

The management of individual accounts is generally performed by low-level employees at companies like this. It's operational work that is thought to scale poorly and the costs of it are looked upon unfavorably by public market investors. Hence, there is constant pressure to push it to as low of a level as possible.

Perhaps a higher tier of user support personnel handles verified accounts (or accounts somehow flagged for extra review in a non-public fashion), but I'd still be surprised if anyone particularly high-level is doing the grunt work of using this tool.

Re: Twitter internal panel linked to account hijackings

#183

Earlier quoted context omitted.

Honest question, how do I recover a lost identity? The reason why this attack worked is primarily because of a recovery system. I agree this is a significant vector, but I can't see how decentralized solves this? At the moment with blockchain wallets, once you've lost your private key, you're screwed. There is no recovery. So, I'm all for decentralized but if it is truly my identity, I need a way back if I lose it. N…

What about having a revocation key? Or something similar.

What if I lose that key? lose the laptop? data source gets corrupt.

Give enough people using the system, it's not if, it's when. So how do I recover?

Re: Twitter internal panel linked to account hijackings

#184

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

How does a single rep coordinate the mass amount of posts across verified (and non verified?) accounts? That is an insane amount of access for 'a rep'. They can just copy and paste the same message across that level of accounts?

Re: Twitter internal panel linked to account hijackings

#185

Earlier quoted context omitted.

You need to stop thinking identity singular, and identity as valuable. Have many and treat them as disposable. Of course you can't do this on the 2020 web that consists of four websites filled with screenshots of each other, but that's just one of the many reasons to burn those websites to the ground and resist any attempts to remake them. And it turns out your parents were right about not using your real name on the…

But that's not really identity then right? That just becomes my hnews/reddit username that's unverified. I read @elonmusk because I trust it's him and I'm interested in what he says. Personally, I genuinely like Starship + Starlink updates... I ignore most the other stuff. But still, I want to see those awesome rocket tweets! So, I want to know what he says. He can change his username because it got hacked/whatever..…

Your hnews username is an identity. A small, weak, and reasonably disposable one, that you can have many of. Why do you want to use your God damn real name on the Internet unless you are a public person already? What do you have to gain? Hate mail, Death threats and calls for your firing? I've always wanted more of those. You do not WANT to be verified. Verified is a euphemism for doxxed.

You could trust it was Elon because it's published on his own website instead of on the worst thing to happen to human communication since writing was invented (I.e., Twitter)

For other cases we can evaluate merit based on previous performance and character of published material instead of "identity". I do not care who is behind a pseudonymous blog if the blog is good.

Re: Twitter internal panel linked to account hijackings

#186
post #124

RE: social engineering, as long as a human is involved somewhere, the system can be compromised. IT security is a very depressing field because of this fact. I also hope these incidents remind people of how little control you really have over your online identity. We're all just IDs in a database somewhere, waiting to be impersonated. Decentralization is the only solution for this IMO.

Often, what people think is "good customer service" really means "allowing me to socially engineer you". I don't think there is any solution to this. "Decentralization" in this context seems equivalent to a centralized system that simply gives up on any ability to recover accounts. Whoever owns the authentication details of an account is the owner, period. If you lose the password or the account gets hacked and stole…

> The fact that politicians and important people use it in an official capacity is the problem that needs fixing.

I don't disagree, but with what?

It's easy to say this is 'wrong/broken', but I don't see a great fix other than people 'rolling their own solution' and that's not realistic.

Re: Twitter internal panel linked to account hijackings

#187
post #120

Earlier quoted context omitted.

Does anybody on Hacker news seriously believe that the account of Biden or Obama actually send messages privately on Twitter? They most certainly don't. I have no idea why that fact is not obvious to some. Trump had two liked tweets for all of time back from like, 2012. Around 2017 or so a group realized this and bought or otherwise messed with the site the liked tweets linked to and made them have pictures making jo…

I definitely don't think Obama/Biden/others would DM. But Elon? Some of these bitcoin exchanges? Maybe. How about accounts that were accessed (if any) that never blasted out the bitcoin tweet, but had their messages harvested?

Elon definitely DMs.

Re: Twitter internal panel linked to account hijackings

#188

“Trends Blacklist” & “Search Blacklist” are interesting buttons. Manipulation much ?

The worst part is the racist use of the word black to describe a list of things to be excluded. Twitter should really use the less offensive term 'shitlist.'

Re: Twitter internal panel linked to account hijackings

#189
post #82

Earlier quoted context omitted.

This makes a lot more sense. I can't imagine Twitter isn't using some sort of phsyical 2FA like yubikeys which are virtually Phish proof if implemented well. That being said, what was the employee's endgame here?

> That being said, what was the employee's endgame here? General disgruntlement maybe? Maybe they were simply pissed off and looking for a way to hurt the company.

And go to prison?

Re: Twitter internal panel linked to account hijackings

#190

Its pretty amazing that realdonaldtrump@ was not a part of this. I guess the controls on that account are at an even higher level than elon musk/obama.

It might also be that impersonating a government official is a serious crime.

Sure, the hackers here have committed a crime, but this was more of an embarrassment for Twitter than anything else. If they had posted from Trump's account though...

Post reply on HN