Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

231–240 of 477 posts

Re: Twitter internal panel linked to account hijackings

#231

Didn't Twitter say that they don't shadow-ban? [1] From a leaked screenshot of the panel, though, it appears they have a search/trend blacklist. 1: https://www.washingtonexaminer.com/business/jack-dorseys-per... EDIT: thanks for the downvotes, twitter.

> EDIT: thanks for the downvotes

It's against the site guidelines to do that, so please resist.

https://news.ycombinator.com/newsguidelines.html

Re: Twitter internal panel linked to account hijackings

#233
post #62

So it was a social engineering attack against employees with high level access. This sentence still doesn’t make sense to me: “ Once we became aware of the incident, we immediately locked down the affected accounts and removed Tweets posted by the attackers.” The accounts were posting for hours after it seemed Twitter became aware what was going on.

The tweets are still live as of right now with JS disabled. https://news.ycombinator.com/item?id=23855452

Re: Twitter internal panel linked to account hijackings

#234

Earlier quoted context omitted.

I’m surprised they pulled off that much.

I can't help but make the obvious observation here. It's bitcoin... The space has a prior for people who are willing to rush head first into something they don't understand in order to attempt to make a quick buck. I'm surprised it was only 12 BTC.

They used several different BTC addresses and even some Monero and other crypto ones. It's not just 12 BTC.

Re: Twitter internal panel linked to account hijackings

#235

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

I don’t know the details but whenever I call Hover for support, they have to email me a code that I have to read to them to unlock access to my account. If you have 2FA enabled you need to give them that code too. I’m not sure if they are just verifying but it sounds like they actually can’t do anything without the codes.

Re: Twitter internal panel linked to account hijackings

#236

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

(This comment was merged from https://news.ycombinator.com/item?id=23855208, which explains why it links to the current thread.)

Re: Twitter internal panel linked to account hijackings

#237
post #86

If it’s really a social engineering attack then I think it happened because everyone is working remotely and it is easier to perform social engineering attacks. Maybe this incident will have impact on their long term remote work plans.

I wouldn't be too surprised to learn that some people that are working from home are actually working from a coffee shop (in countries where they have re-opened obviously) or other public places with little to none protection against social engineering attack.

Re: Twitter internal panel linked to account hijackings

#238

Earlier quoted context omitted.

I’m not saying there isn’t one, but curious what you think is the imprisonable offense?

It seems to generally be a crime to access a computer system you aren't supposed to, regardless of how you came by the login info (phishing, guessing passwords, etc).

But the disgruntled employee may have had legitimate access to the system, even if this specific act was illegitimate

Re: Twitter internal panel linked to account hijackings

#239
post #150
post #87

Earlier quoted context omitted.

A simple official website is enough for hosting a list of short statements.

If the goal is to simply publish statements, the press already exists for that. The value of a platform like Twitter is in the network and communication. Twitter already has politicians and official accounts from around the world, and millions of users. I don't know how a particular state-owned platform could replicate that... and let's not get into the technical acumen that government contracts lead to. Remember the…

An RSS feed is not expensive. As one example it'd be great to have RSS feeds for e.g. the US Forest Service or Bureau of Land Management about camping/hiking conditions, wildfires, etc.

Re: Twitter internal panel linked to account hijackings

#240

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

This is something I argue with coworkers et al to no end: differential privileges are targets for privilege escalation!

From their perspective, they want the ability to ban/kick/etc as special powers; but from my perspective that feature is an exploitation target that's vulnerable to any unknown bugs, and probably in twitter's case, social exploitation.

I would _much rather_ see all users be equally powerful and find some means by which the services can be designed such that everyone can be comfortable and safe.

Post reply on HN