Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

191–200 of 477 posts

Re: Twitter internal panel linked to account hijackings

#191
post #95

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

If they wanted to get as much money as possible without being caught what else could they have done?

If that was the case they could only deal with bitcoin. Blackmailing with bitcoin may be smarter but maybe they figured that would be investigated more or treated more harshly? They could have released fake financial tweets and shorted the market - but that still would be investigated much faster.

I'm sure the 100k or whatever they got isn't as much as it could be - but for a random dude who paid 10k to a disgruntled employee it is pretty good.

Re: Twitter internal panel linked to account hijackings

#192
post #110

With the info we have it looks like hackers changed the email id of the accounts and then used forgot password to reset the password. What’s concerning is that they were able to do it for accounts with 2FA enabled. I think disabling 2FA should be extremely privileged actions and should not accessible to most employees.

They apparently have another level of auth, used for at least Trump's account. And probably the CEO's considering past events.

Didn't Twitter buy "Moxie Marlinspike"'s company specifically to get him to fix their security? I guess they didn't really get much out of that. Now I'm starting to get nervous about the security of Signal.

Re: Twitter internal panel linked to account hijackings

#193
post #191
post #95

Earlier quoted context omitted.

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

If they wanted to get as much money as possible without being caught what else could they have done? If that was the case they could only deal with bitcoin. Blackmailing with bitcoin may be smarter but maybe they figured that would be investigated more or treated more harshly? They could have released fake financial tweets and shorted the market - but that still would be investigated much faster. I'm sure the 100k or…

Buy shares in a small publicly traded company. Pump/dump shares. One tweet from musk stating he was adding such and such to all Teslas would send the target company through the roof.

Re: Twitter internal panel linked to account hijackings

#194
post #134

Earlier quoted context omitted.

The most logical conclusion is that this probably wasn't about money. Plenty of better ways to make money than telling people to give you BTC. I'm expecting a huge data drop on wikileaks/pastebin/wherever of private DMs, images, who knows what else.

Plus there was no way they knew beforehand they'd only make 12BTC. People always overestimate the value of twitter and conversion rates when an actual action is required - even with targeted audiences like cryptocurrency people in this case. People seem to assume everyone takes tweets at face value and won't do a double take when it doesn't sound like something they would normally say. Even here there was plenty of p…

I’m surprised they pulled off that much.

Re: Twitter internal panel linked to account hijackings

#195
post #124

Earlier quoted context omitted.

Often, what people think is "good customer service" really means "allowing me to socially engineer you". I don't think there is any solution to this. "Decentralization" in this context seems equivalent to a centralized system that simply gives up on any ability to recover accounts. Whoever owns the authentication details of an account is the owner, period. If you lose the password or the account gets hacked and stole…

> The fact that politicians and important people use it in an official capacity is the problem that needs fixing. I don't disagree, but with what? It's easy to say this is 'wrong/broken', but I don't see a great fix other than people 'rolling their own solution' and that's not realistic.

I don't think a replacement is needed. If your communication is important to a lot of people, it shouldn't be just immediately jammed into 280 characters using your thumbs while sitting on the toilet or whatever.

Post it on congress.gov using some inefficient boring process or whatever the official communication method of your role is.

Re: Twitter internal panel linked to account hijackings

#196
post #124

Earlier quoted context omitted.

Often, what people think is "good customer service" really means "allowing me to socially engineer you". I don't think there is any solution to this. "Decentralization" in this context seems equivalent to a centralized system that simply gives up on any ability to recover accounts. Whoever owns the authentication details of an account is the owner, period. If you lose the password or the account gets hacked and stole…

> The fact that politicians and important people use it in an official capacity is the problem that needs fixing. I don't disagree, but with what? It's easy to say this is 'wrong/broken', but I don't see a great fix other than people 'rolling their own solution' and that's not realistic.

Pass regulation that puts in a place a federated messaging infrastructure, so that Twitter users can subscribe to messaging from Government official that sends out messages via an external system.

Re: Twitter internal panel linked to account hijackings

#197
post #191

Earlier quoted context omitted.

If they wanted to get as much money as possible without being caught what else could they have done? If that was the case they could only deal with bitcoin. Blackmailing with bitcoin may be smarter but maybe they figured that would be investigated more or treated more harshly? They could have released fake financial tweets and shorted the market - but that still would be investigated much faster. I'm sure the 100k or…

Buy shares in a small publicly traded company. Pump/dump shares. One tweet from musk stating he was adding such and such to all Teslas would send the target company through the roof.

The post you're replying to is suggesting that manipulating the market like that draws the attention of some very powerful organizations. It'll likely be investigated swiftly and they'll come down on you harshly when compared to the consequences of some Bitcoin scamming.

Re: Twitter internal panel linked to account hijackings

#198

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

If you have a system where customer service reps are strictly unable to access your data without some kind of cryptographic authentication, that defeats the purpose of customer service for 80% of customers (who suck at using computers and mostly just lose their passwords). If you’re in the other 20%, you might as well use some kind of decentralized cryptographic system with no customer service anyway. This is one of the chief complaints I see against Bitcoin on here - “what if I lose my password?” - the implicit dual to that being that someone else can access your account without your password, and you hope they’re not a bad actor.

Re: Twitter internal panel linked to account hijackings

#200
post #117

Earlier quoted context omitted.

They social engineered access to a Twitter employees internal account, not the individual end users affected.

I understand, but that sort of behaviour should have been thwarted quickly by their security team or policies setup against abuse.

Yep, for one, you shouldn’t be able to just hand over your credentials to other people and they can immediately start doing stuff in your systems.

Also, the ability to impersonate people (not just celebrities) should require at least manual approvals. Not sure why this ability even exists.

The original speculation (that it was an API vulnerability) is actually easier to stomach.

Post reply on HN