“Trends Blacklist” & “Search Blacklist” are interesting buttons. Manipulation much ?
The worst part is the racist use of the word black to describe a list of things to be excluded. Twitter should really use the less offensive term 'shitlist.'
Twitter internal panel linked to account hijackings
211–220 of 477 posts
Re: Twitter internal panel linked to account hijackings
#212> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
How does a single rep coordinate the mass amount of posts across verified (and non verified?) accounts? That is an insane amount of access for 'a rep'. They can just copy and paste the same message across that level of accounts?
Re: Twitter internal panel linked to account hijackings
#213Earlier quoted context omitted.
> That being said, what was the employee's endgame here? General disgruntlement maybe? Maybe they were simply pissed off and looking for a way to hurt the company.
And go to prison?
Sometimes people behave very irrationally. In the most sensational cases that manifests as violence, but I think it might also manifest as acts of sabotage.
Re: Twitter internal panel linked to account hijackings
#214I’d be surprised if Twitter didn’t have some internal tool like this but I’d expect it to only be accessible over a VPN that few had access to.
How would a VPN help in this case though? They social-engineered some employees to gain privileged access to the admin UI. If a VPN was in the way they'd do the same thing to get access to the VPN first.
Re: Twitter internal panel linked to account hijackings
#215Its pretty amazing that realdonaldtrump@ was not a part of this. I guess the controls on that account are at an even higher level than elon musk/obama.
Re: Twitter internal panel linked to account hijackings
#216Earlier quoted context omitted.
Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…
I’m not saying there isn’t one, but curious what you think is the imprisonable offense?
Re: Twitter internal panel linked to account hijackings
#217Earlier quoted context omitted.
What does that have to do with this?
In the screenshots of the admin panel, it looks like they have blacklists of things that shouldn't show up in searches or on trending. It's not clear if it's accounts, or some other criteria that's blacklisted though.
Does confirm past claims that they shadowban accounts (which does hide them from search, among other things) at the very least, even if the exact criteria are unknown.
Re: Twitter internal panel linked to account hijackings
#218“Trends Blacklist” & “Search Blacklist” are interesting buttons. Manipulation much ?
Any social network which doesn't want to become 8chan needs moderation and bans. Why are you surprised about this existing?
Re: Twitter internal panel linked to account hijackings
#219> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
Re: Twitter internal panel linked to account hijackings
#220This is why the concept of a blast radius exists. It is so important to critically examine and limit the blast radius of administrative actions. This is both from a vulnerability perspective as well as honest human mistakes. For certain actions like taking over an account and impersonation there should be rate limits all around. Overriding them requires a break glass process where multiple people may have to approve…