Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

251–260 of 477 posts

Re: Twitter internal panel linked to account hijackings

#251
post #134

Earlier quoted context omitted.

The most logical conclusion is that this probably wasn't about money. Plenty of better ways to make money than telling people to give you BTC. I'm expecting a huge data drop on wikileaks/pastebin/wherever of private DMs, images, who knows what else.

Plus there was no way they knew beforehand they'd only make 12BTC. People always overestimate the value of twitter and conversion rates when an actual action is required - even with targeted audiences like cryptocurrency people in this case. People seem to assume everyone takes tweets at face value and won't do a double take when it doesn't sound like something they would normally say. Even here there was plenty of p…

12 BTC could be retirement level money in some countries.

Re: Twitter internal panel linked to account hijackings

#252
post #171

Wait a second...they were hacked in a way that makes it so we can't trust any tweets. Does it make sense, then, for them to use tweets to report their progress on addressing this?

They have easy access to out-of-band signalling. Jack Dorsey can literally call up a news channel and say "They've got everything. Don't believe anything from Twitter.com" and you'd know it in fifteen minutes because it would be pushed out to everything after a Twitter SRE pulled the Red Lever that reactivates the failwhale.

Because Jack Dorsey is a real human and a powerful real human and he hasn't done that, we don't have to envision the cyberpunk PURDAH identity scenario for proof from him and we don't have to think this is a secondary Moab run. At least now that it's been up for a few minutes.

Re: Twitter internal panel linked to account hijackings

#253
post #95

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

I think it's unlikely someone working on "mass" tasks like account recovery is highly paid.

Re: Twitter internal panel linked to account hijackings

#254
post #95

Earlier quoted context omitted.

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

The most reasonable explanation might be that they’re lying to sound cool. Bribery is a thing, but any twitter employee would know that their employment (and future career prospects) would be terminated. On the other hand, $1M in BTC might do the trick. Interesting thought experiment...

You're thinking of an engineer, not a low paid worker in the tech company equivalent of a call center working on repetitive tasks for low pay in India or some other country where labor is cheap.

And you're also making the assumption that the accomplice thought about it rationally. All the attacker has to do is find someone who doesn't realize that they will get caught.

Re: Twitter internal panel linked to account hijackings

#255

Earlier quoted context omitted.

How would a VPN help in this case though? They social-engineered some employees to gain privileged access to the admin UI. If a VPN was in the way they'd do the same thing to get access to the VPN first.

I've seen some solutions where the VPN only works on the company machine. In this case, the social engineered employee would at least have to hand over their laptop.

[deleted]

Re: Twitter internal panel linked to account hijackings

#256

Earlier quoted context omitted.

It seems to generally be a crime to access a computer system you aren't supposed to, regardless of how you came by the login info (phishing, guessing passwords, etc).

But the disgruntled employee may have had legitimate access to the system, even if this specific act was illegitimate

I'm no lawyer either, but I imagine that the definition of authorisation is key here.

If you're a sysadmin on a company email system, then you do technically have access to everyone's data on that system.

However, you're generally limited by company policy that you are not permitted to access/modify that data without direct authorisation, say from the employee themselves or from HR.

So, therefore, if you go and read the email of your boss, you're still in breach because you didn't have the authorisation.

Re: Twitter internal panel linked to account hijackings

#257
post #17

> Hawley said "please reach out immediately to the Department of Justice and the Federal Bureau of Investigation and take any necessary measures to secure the site before this breach expands It's kind of bizarre when you have the highest levels of government doing their critical communication on a free social media service to the point where they are critically dependent on it, then begging for support when things go…

> Maybe you shouldn't use a free service that is not under your control or any proper regulatory or quality constraints for your most important messaging to the public then?

No, I think they should use best-in-class media and Twitter is exemplary for that. Twitter is only dangerous for this because it is very effective at being a communication medium.

Yeah no one is going to fall for the 5th ColdFusion site with an admin backend left open on sqolkla7.info.gov.us/press-releases but that's because no one is reading that site.

Re: Twitter internal panel linked to account hijackings

#258
post #191
post #95

Earlier quoted context omitted.

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

If they wanted to get as much money as possible without being caught what else could they have done? If that was the case they could only deal with bitcoin. Blackmailing with bitcoin may be smarter but maybe they figured that would be investigated more or treated more harshly? They could have released fake financial tweets and shorted the market - but that still would be investigated much faster. I'm sure the 100k or…

Geez every poster is assuming that the hackers knew they would only get 12BTC.

In their minds, they are thinking at least 200 Million followers at least 10% success rate. So 2 Million in BTC or several millions of untraceable wealth.

BTC hackers aren't exactly known for smartness in other areas

Re: Twitter internal panel linked to account hijackings

#259

To me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisti…

I think there are three possible explanations here: 1- (Tinfoil hats please) This is a state owned attack, which is a retaliation from US Government to ruin Twitter's credibility and introduce social media regulations. 2- The hackers are gray hat hackers, who know that reporting this vulnerability will not make them any money and they want to get what they think they deserve, so they make it public and get some good…

nothing but pure speculation, but i came to conclusion #1 more or less independently.

the obvious qui bono is not twitter. and twitters biggest opponent at the moment is?

the pound of salt for that is just that once clandestine motives are introduced theres no bottom to the subversion one would introduce to make attribution difficult.

Re: Twitter internal panel linked to account hijackings

#260

To me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisti…

Geez, why would you assume that the hackers knew that they would get only $150K.

They were probably thinking several millions of dollars of untraceable money.

BTC crowd isn't exactly known for their product-market fit, conversion rates of ads and other esoteric analysis

Post reply on HN