Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

261–270 of 477 posts

Re: Twitter internal panel linked to account hijackings

#262

Earlier quoted context omitted.

Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…

I’m not saying there isn’t one, but curious what you think is the imprisonable offense?

This is likely a violation of the Computer Fraud and Abuse Act of 1986 (CFAA) which allows for federal prison sentences.

Re: Twitter internal panel linked to account hijackings

#263
post #70

Earlier quoted context omitted.

Which shows that Twitter probably doesn't properly employ 2FA and two-person-principle when dealing with high-profile accounts. Otherwise, social engineering would have been almost impossible.

If it’s SMS the attacker could have social engineered (big cell service co) to get access to the employee’s phone # and get a SIM. I’m guessing someone re-used a hacked password and SMS 2FA is to blame. Maybe it’s not even that sophisticated.

I have a little thingie that generates time based codes, similar to wee-calculators banks use but w/o the pin, that's on top of a private key.

SMS is fine for end user access but companies can do better, even RSA/Google authenticator are a lot better option than SMS

Re: Twitter internal panel linked to account hijackings

#264

To me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisti…

> selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc.

Can't it just be that they're not that knowledgeable about stuff outside their domain? The things you mentioned require knowledge of stocks and politics. If I, personally, woke up tomorrow with access to a Twitter backdoor and the desire to exploit it, I wouldn't know how to do any of those things, because I also don't know anything about stocks or politics.

Re: Twitter internal panel linked to account hijackings

#265
If this is the true story. Is it a standard practice on social networks to give to an administrator the right to post anything in your name without any distinguishable marker? There is a enormous trust issue here. I expect an administrator to be able to moderate a post or disable an account, not to impersonate it from a admin dashboard.

Re: Twitter internal panel linked to account hijackings

#266

I wish they had used unique addresses for each tweet they sent out. It would have been fascinating to see which which account had the best conversion rate.

I didnt even know I wanted to know this. My guess is between Jeff and Bill. They're the leading ones who can afford giving twice the money back ;)

I think you’re wrong, everyone knows that Bezos would never do a “I have decided to give back to my community” of any kind. :P

Re: Twitter internal panel linked to account hijackings

#267
post #134

Earlier quoted context omitted.

Plus there was no way they knew beforehand they'd only make 12BTC. People always overestimate the value of twitter and conversion rates when an actual action is required - even with targeted audiences like cryptocurrency people in this case. People seem to assume everyone takes tweets at face value and won't do a double take when it doesn't sound like something they would normally say. Even here there was plenty of p…

12 BTC could be retirement level money in some countries.

Not really, when you factor in inflation, unless you're planning on living in abject poverty your whole life or not planning on living very long.

e.g., Vietnam is a livable place and GDP per capita is ~$2600. That'd get you a very modest living. GDP/capita is also up 2x from 10 years ago and 10x from 20 years ago. You could maybe squeak out 20 years with very modest living and few unplanned expenses and assuming the economy and thus cost of living doesn't grow tremendously (like it likely will).

Somalia would give you a little more value for your money. But I think if someone suddenly had that much money in Somalia, they'd probably be getting out of Somalia or hoping nobody found out.

Re: Twitter internal panel linked to account hijackings

#268
post #234

Earlier quoted context omitted.

I can't help but make the obvious observation here. It's bitcoin... The space has a prior for people who are willing to rush head first into something they don't understand in order to attempt to make a quick buck. I'm surprised it was only 12 BTC.

They used several different BTC addresses and even some Monero and other crypto ones. It's not just 12 BTC.

I hope Twitter's report includes a list of all the attacker's tweets.

Re: Twitter internal panel linked to account hijackings

#269

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right.

Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do.

So a random customer service rep couldn't access my account without my phone in their hand, even if they managed to clone my SIM to get past the text message check.

Re: Twitter internal panel linked to account hijackings

#270

Earlier quoted context omitted.

The most logical conclusion is that this probably wasn't about money. Plenty of better ways to make money than telling people to give you BTC. I'm expecting a huge data drop on wikileaks/pastebin/wherever of private DMs, images, who knows what else.

Joe Biden was one of the hacked accounts, Trump was not. It's like 2016 all over again.

I’m guessing after the last time Trump was hacked internally, some new control went in place specific for his account.
Post reply on HN