Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

201–210 of 477 posts

Re: Twitter internal panel linked to account hijackings

#201
post #134

Earlier quoted context omitted.

Plus there was no way they knew beforehand they'd only make 12BTC. People always overestimate the value of twitter and conversion rates when an actual action is required - even with targeted audiences like cryptocurrency people in this case. People seem to assume everyone takes tweets at face value and won't do a double take when it doesn't sound like something they would normally say. Even here there was plenty of p…

I’m surprised they pulled off that much.

I can't help but make the obvious observation here. It's bitcoin... The space has a prior for people who are willing to rush head first into something they don't understand in order to attempt to make a quick buck. I'm surprised it was only 12 BTC.

Re: Twitter internal panel linked to account hijackings

#202
post #134

Earlier quoted context omitted.

Plus there was no way they knew beforehand they'd only make 12BTC. People always overestimate the value of twitter and conversion rates when an actual action is required - even with targeted audiences like cryptocurrency people in this case. People seem to assume everyone takes tweets at face value and won't do a double take when it doesn't sound like something they would normally say. Even here there was plenty of p…

I’m surprised they pulled off that much.

I could go for 12 BTC right about now

Re: Twitter internal panel linked to account hijackings

#203
post #74

Earlier quoted context omitted.

In the early days of the internet the FBI was kind enough to call my employer and inform us that we had left open an anonymous FTP server, and it was serving up Disney movies. Those were good times.

FBI warned a non-profit 8 hours before news broke that the US had bombed an Iranian general. Indeed, they saved many lives.

Are there any articles where someone could read about this? What was the non profit?

Re: Twitter internal panel linked to account hijackings

#204
post #74

Earlier quoted context omitted.

In the early days of the internet the FBI was kind enough to call my employer and inform us that we had left open an anonymous FTP server, and it was serving up Disney movies. Those were good times.

FBI warned a non-profit 8 hours before news broke that the US had bombed an Iranian general. Indeed, they saved many lives.

Do you have links to that story?

Re: Twitter internal panel linked to account hijackings

#205

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

Here[0] are the supposed pics of the admin panel the hackers accessed. Assuming their legit, it seems like Twitter has some blacklist features. Can't find any info detailing how they exactly work, but it seems an admin can blacklist a user from the trending page or from search results. Pretty interesting. Oddly enough, posting the screenshots resulted in some users getting their account suspended or Twitter pulling t…

> Twitter has some blacklist

You can't use the b-word.

Re: Twitter internal panel linked to account hijackings

#206

Earlier quoted context omitted.

Here[0] are the supposed pics of the admin panel the hackers accessed. Assuming their legit, it seems like Twitter has some blacklist features. Can't find any info detailing how they exactly work, but it seems an admin can blacklist a user from the trending page or from search results. Pretty interesting. Oddly enough, posting the screenshots resulted in some users getting their account suspended or Twitter pulling t…

This could end up being a big deal in the days to come if legitimate. Twitter has made strong public statements that they don't have shadow banning tools[0]. Apparently sworn statements have been made about this. [0]: https://blog.twitter.com/en_us/topics/company/2018/Setting-t...

> You are always able to see the tweets from accounts you follow (although you may have to do more work to find them, like go directly to their profile).

This doesn't seem to contradict what's shown in the screenshot (which only shows blocking from the search and trends page).

Re: Twitter internal panel linked to account hijackings

#207

I wish they had used unique addresses for each tweet they sent out. It would have been fascinating to see which which account had the best conversion rate.

Oh wow that would have bee interesting. My guess would be Elon (or Kanye).

I know one person who actually sent money to Elon – "it seemed like something he'd do". Seems likely Elon's followers have the highest rate of people who understand crypto, combined with the fact that he's more likely to do something like this than, say, Joe Biden.

Re: Twitter internal panel linked to account hijackings

#208

I wish they had used unique addresses for each tweet they sent out. It would have been fascinating to see which which account had the best conversion rate.

I didnt even know I wanted to know this. My guess is between Jeff and Bill. They're the leading ones who can afford giving twice the money back ;)

Re: Twitter internal panel linked to account hijackings

#209
post #11

Twitter is removing those because it's of their own internal backend, not because they're necessarily connected to the hack. Huge leap from Mboard on this

Why would a screenshot of their tools warrant a content takedown? People have posted far worse things that have been allowed to stay up. It's not like there's any personal information visible in the screenshots.

Re: Twitter internal panel linked to account hijackings

#210
post #94

Anyone else unimpressed with Twitter's U2F/FIDO token support? They support a total of 1 (one) U2F token on an account :( The only other company I know that does that is AWS and one U2F token. Every other site I use allows multiples, usually at least 5 or more. I setup U2F on Twitter but then got rid of it after realizing they only allow one.

the entirety of AWS seems to be half assed in general as you've described: the U2F functionality is completely useless because if you lose/break your single U2F key then you're completely screwed and they still have no support for ed25519 keys (which were added to OpenSSH in 2013), unlike every other cloud service I have to have an RSA key just for AWS (particuraly annoying as I have all my other ssh keys stored in a…

Oh don't worry, Azure also demands an RSA key for bringing up VMs, too.

> if they didn't validate the damn key type then it would probably just work out of the box

Yep. So incredibly frustrating.

Post reply on HN