Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

241–250 of 477 posts

Re: Twitter internal panel linked to account hijackings

#241
post #230

Earlier quoted context omitted.

I didnt even know I wanted to know this. My guess is between Jeff and Bill. They're the leading ones who can afford giving twice the money back ;)

I'd assume one closer to crypto, probably Elon Musk or Coinbase. Because the audience needs to know how to quickly send BTC. In addition, it's a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his. So, maybe some thought today Musk is having it and finally doing it for real! If there is a person to run such a campaign for real, it would be him - so it could even be pl…

> "Because the audience needs to know how to quickly send BTC."

Yep, I agree with this.While mine guess was purely on "amount of money available to give", your speculation seems more on point.

Re: Twitter internal panel linked to account hijackings

#242

Did the attackers have direct access to the database, or why does their internal admin dashboard allow employees to tweet on behalf of any account?

Perhaps the admin dashboard allows support staff to reset emails/passwords, and they simply logged in as the users to tweet.

Re: Twitter internal panel linked to account hijackings

#243

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

> I'd like to see a system where it is physically impossible for a customer service rep to discover any info about me until I authenticate and authorize it.

Isn't this the objective of Tim Berners-Lee Solid Project and their Personal Online Data storage (PODs) in the spec?

https://solidproject.org

Re: Twitter internal panel linked to account hijackings

#244

To me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisti…

I think there are three possible explanations here:

1- (Tinfoil hats please) This is a state owned attack, which is a retaliation from US Government to ruin Twitter's credibility and introduce social media regulations.

2- The hackers are gray hat hackers, who know that reporting this vulnerability will not make them any money and they want to get what they think they deserve, so they make it public and get some good amount of cash.

3- The hackers had realized they had a massive vulnerability in their hands by accident and did not know what to do with it.

I find second and third option plausible, which also reminds me of the npm hack, where a very, very popular library was compromised and installed on a huge amount of developer machines, but only thing they did was to try to get hold of some bitcoin accounts.

I do not condone any type of crime but in both cases, it feels like a huge opportunity was missed by both hackers.

Re: Twitter internal panel linked to account hijackings

#245

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

We use OpsGenie at work. I've used their support a couple of times. Every time they needed to look at our company's account settings I've had to approve it (using some sort of OpsGenie internal tool). I was pleasantly surprised. It's impossible to tell as a customer how hard it is to access my data without that internal authorization system, but it at least looks better than nothing.

Re: Twitter internal panel linked to account hijackings

#246
post #229

Why have employees have the ability to do anything with accounts except closing them?

Apparently admins could post only on behalf of bluechecks. I still can't think of a reason why they would need to create posts. Edit maybe, but create? Why? Of course with access to the database anything at all can be done, but this was apparently an explicit feature of the admin dashboard.

When I was working for a company with SOX compliancy, direct DB access was highly regulated and audited.

Re: Twitter internal panel linked to account hijackings

#247
post #62

So it was a social engineering attack against employees with high level access. This sentence still doesn’t make sense to me: “ Once we became aware of the incident, we immediately locked down the affected accounts and removed Tweets posted by the attackers.” The accounts were posting for hours after it seemed Twitter became aware what was going on.

Accounts of the employees. There was a statements somewhere else, that this might be close to the token system. Token have a validity which expires in hours.

All assumptions on my behalf bit it explains your question.

Re: Twitter internal panel linked to account hijackings

#248
post #95

Earlier quoted context omitted.

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

The most logical conclusion is that this probably wasn't about money. Plenty of better ways to make money than telling people to give you BTC. I'm expecting a huge data drop on wikileaks/pastebin/wherever of private DMs, images, who knows what else.

Joe Biden was one of the hacked accounts, Trump was not. It's like 2016 all over again.

Re: Twitter internal panel linked to account hijackings

#249
post #94

Anyone else unimpressed with Twitter's U2F/FIDO token support? They support a total of 1 (one) U2F token on an account :( The only other company I know that does that is AWS and one U2F token. Every other site I use allows multiples, usually at least 5 or more. I setup U2F on Twitter but then got rid of it after realizing they only allow one.

And you can't use your hardware key on the CLI either. Switched to using an authenticator app. What a nightmare.

Re: Twitter internal panel linked to account hijackings

#250
post #230

Earlier quoted context omitted.

I didnt even know I wanted to know this. My guess is between Jeff and Bill. They're the leading ones who can afford giving twice the money back ;)

I'd assume one closer to crypto, probably Elon Musk or Coinbase. Because the audience needs to know how to quickly send BTC. In addition, it's a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his. So, maybe some thought today Musk is having it and finally doing it for real! If there is a person to run such a campaign for real, it would be him - so it could even be pl…

[deleted]
Post reply on HN