Earlier quoted context omitted.
The most logical conclusion is that this probably wasn't about money. Plenty of better ways to make money than telling people to give you BTC. I'm expecting a huge data drop on wikileaks/pastebin/wherever of private DMs, images, who knows what else.
Plus there was no way they knew beforehand they'd only make 12BTC. People always overestimate the value of twitter and conversion rates when an actual action is required - even with targeted audiences like cryptocurrency people in this case. People seem to assume everyone takes tweets at face value and won't do a double take when it doesn't sound like something they would normally say. Even here there was plenty of p…
Twitter internal panel linked to account hijackings
251–260 of 477 posts
Re: Twitter internal panel linked to account hijackings
#252Wait a second...they were hacked in a way that makes it so we can't trust any tweets. Does it make sense, then, for them to use tweets to report their progress on addressing this?
Because Jack Dorsey is a real human and a powerful real human and he hasn't done that, we don't have to envision the cyberpunk PURDAH identity scenario for proof from him and we don't have to think this is a secondary Moab run. At least now that it's been up for a few minutes.
Re: Twitter internal panel linked to account hijackings
#253The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…
This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…
Re: Twitter internal panel linked to account hijackings
#254Earlier quoted context omitted.
This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…
The most reasonable explanation might be that they’re lying to sound cool. Bribery is a thing, but any twitter employee would know that their employment (and future career prospects) would be terminated. On the other hand, $1M in BTC might do the trick. Interesting thought experiment...
And you're also making the assumption that the accomplice thought about it rationally. All the attacker has to do is find someone who doesn't realize that they will get caught.
Re: Twitter internal panel linked to account hijackings
#255Earlier quoted context omitted.
How would a VPN help in this case though? They social-engineered some employees to gain privileged access to the admin UI. If a VPN was in the way they'd do the same thing to get access to the VPN first.
I've seen some solutions where the VPN only works on the company machine. In this case, the social engineered employee would at least have to hand over their laptop.
Re: Twitter internal panel linked to account hijackings
#256Earlier quoted context omitted.
It seems to generally be a crime to access a computer system you aren't supposed to, regardless of how you came by the login info (phishing, guessing passwords, etc).
But the disgruntled employee may have had legitimate access to the system, even if this specific act was illegitimate
If you're a sysadmin on a company email system, then you do technically have access to everyone's data on that system.
However, you're generally limited by company policy that you are not permitted to access/modify that data without direct authorisation, say from the employee themselves or from HR.
So, therefore, if you go and read the email of your boss, you're still in breach because you didn't have the authorisation.
Re: Twitter internal panel linked to account hijackings
#257> Hawley said "please reach out immediately to the Department of Justice and the Federal Bureau of Investigation and take any necessary measures to secure the site before this breach expands It's kind of bizarre when you have the highest levels of government doing their critical communication on a free social media service to the point where they are critically dependent on it, then begging for support when things go…
No, I think they should use best-in-class media and Twitter is exemplary for that. Twitter is only dangerous for this because it is very effective at being a communication medium.
Yeah no one is going to fall for the 5th ColdFusion site with an admin backend left open on sqolkla7.info.gov.us/press-releases but that's because no one is reading that site.
Re: Twitter internal panel linked to account hijackings
#258Earlier quoted context omitted.
This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…
If they wanted to get as much money as possible without being caught what else could they have done? If that was the case they could only deal with bitcoin. Blackmailing with bitcoin may be smarter but maybe they figured that would be investigated more or treated more harshly? They could have released fake financial tweets and shorted the market - but that still would be investigated much faster. I'm sure the 100k or…
In their minds, they are thinking at least 200 Million followers at least 10% success rate. So 2 Million in BTC or several millions of untraceable wealth.
BTC hackers aren't exactly known for smartness in other areas
Re: Twitter internal panel linked to account hijackings
#259To me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisti…
I think there are three possible explanations here: 1- (Tinfoil hats please) This is a state owned attack, which is a retaliation from US Government to ruin Twitter's credibility and introduce social media regulations. 2- The hackers are gray hat hackers, who know that reporting this vulnerability will not make them any money and they want to get what they think they deserve, so they make it public and get some good…
the obvious qui bono is not twitter. and twitters biggest opponent at the moment is?
the pound of salt for that is just that once clandestine motives are introduced theres no bottom to the subversion one would introduce to make attribution difficult.
Re: Twitter internal panel linked to account hijackings
#260To me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisti…
They were probably thinking several millions of dollars of untraceable money.
BTC crowd isn't exactly known for their product-market fit, conversion rates of ads and other esoteric analysis