Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

271–280 of 477 posts

Re: Twitter internal panel linked to account hijackings

#271
post #126

Earlier quoted context omitted.

This. It would be unbelievable if Twitter's internal system doesn't require VPN/BeyondCorp or 2FA before doing anything sensitive.

If the employee re-used a hacked password and had 2FA via SMS it wouldn’t be hard.

authentication cannot be protected against rouge actors, but such broad write access and no approval over so many rapid writes to customer data which is supposed to be tamper proof is just poor opsec.

Such social media platforms have to be tamper proof even from the CTO, the reddit incident proved that years ago.

This is going to hurt their credibility hard in the run up to the election.

Re: Twitter internal panel linked to account hijackings

#272

Earlier quoted context omitted.

I’m surprised they pulled off that much.

I can't help but make the obvious observation here. It's bitcoin... The space has a prior for people who are willing to rush head first into something they don't understand in order to attempt to make a quick buck. I'm surprised it was only 12 BTC.

But there's also a precedent of scams like this being posted on twitter, esp. from accounts impersonating e.g. Elon Musk. Just because it's tweeted by an official account doesn't suddenly make it less scammy - sure some people clearly fell for it, but I reckon most people using twitter with an interest in cryptocurrency would immediately recognise these tweets as a scam, regardless of the source

Re: Twitter internal panel linked to account hijackings

#273

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

We use OpsGenie at work. I've used their support a couple of times. Every time they needed to look at our company's account settings I've had to approve it (using some sort of OpsGenie internal tool). I was pleasantly surprised. It's impossible to tell as a customer how hard it is to access my data without that internal authorization system, but it at least looks better than nothing.

There is no guarantee though, i.e. the system could be well intentioned but if could be bypassed , it does not really protect.

The only way to get some assurance is run vendor app in your environment in a secure network without the ability to phone home.

Re: Twitter internal panel linked to account hijackings

#274

To me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisti…

> selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. Can't it just be that they're not that knowledgeable about stuff outside their domain? The things you mentioned require knowledge of stocks and politics. If I, personally, woke up tomorrow with access to a Twitter backdoor and the desire to exploit it, I wouldn't know how to do any of those things, because I also don't kno…

It would be pretty easy. You could just post on reddit or 4chan and ask "If you could make anyone on Twitter post anything, what's the most you could earn?" And people who know a lot about a lot of things would give you ideas. It's just not smart to use the hack for just this.

Example: Contact Trump's kids. Demonstrate your power. Tell them you'll make Joe Biden tweet "8 year old girl nude hair" at a time of their choosing, in exchange for 5 million BTC held in escrow. This doesn't require anything more than knowing that Trump is rich and corrupt and that Biden is his opponent.

A variation of this is that you demonstrate the power to rich public figures and tell them that unless they pay you X, you'll do it to them to make them look bad. Then you don't even need to use your exploit.

I think this was probably worth tens of millions, and they blew it on 100k.

Re: Twitter internal panel linked to account hijackings

#275

Earlier quoted context omitted.

But the disgruntled employee may have had legitimate access to the system, even if this specific act was illegitimate

I'm no lawyer either, but I imagine that the definition of authorisation is key here. If you're a sysadmin on a company email system, then you do technically have access to everyone's data on that system. However, you're generally limited by company policy that you are not permitted to access/modify that data without direct authorisation, say from the employee themselves or from HR. So, therefore, if you go and read…

But that's gross misconduct or some other fireable offense - a civil matter at best.

The only item I can see here is fraud (impersonating the people whose accounts have been taken over), of which the mole would be complicit.

Re: Twitter internal panel linked to account hijackings

#276
post #230

Earlier quoted context omitted.

I didnt even know I wanted to know this. My guess is between Jeff and Bill. They're the leading ones who can afford giving twice the money back ;)

I'd assume one closer to crypto, probably Elon Musk or Coinbase. Because the audience needs to know how to quickly send BTC. In addition, it's a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his. So, maybe some thought today Musk is having it and finally doing it for real! If there is a person to run such a campaign for real, it would be him - so it could even be pl…

That they target Elon Musk followers already suggests that it's a rich vein for scammers.

Re: Twitter internal panel linked to account hijackings

#277
post #265

If this is the true story. Is it a standard practice on social networks to give to an administrator the right to post anything in your name without any distinguishable marker? There is a enormous trust issue here. I expect an administrator to be able to moderate a post or disable an account, not to impersonate it from a admin dashboard.

Admins have direct access to the database. A similar controversy happened on Reddit a while back.

Re: Twitter internal panel linked to account hijackings

#278

Earlier quoted context omitted.

Buy shares in a small publicly traded company. Pump/dump shares. One tweet from musk stating he was adding such and such to all Teslas would send the target company through the roof.

US federal agencies actually investigate market activity around big events like 9/11. Very likely to be caught doing that unless you have some way of shuffling money in and out of the market anonymously.

Though I was the one who suggested this would be easily catchable - Tesla is probably the one company where you could get away with this. There is no shortage of random Robin Hood users making pretty big plays on it constantly.

Re: Twitter internal panel linked to account hijackings

#279
post #265

If this is the true story. Is it a standard practice on social networks to give to an administrator the right to post anything in your name without any distinguishable marker? There is a enormous trust issue here. I expect an administrator to be able to moderate a post or disable an account, not to impersonate it from a admin dashboard.

Admins have direct access to the database. A similar controversy happened on Reddit a while back.

Not the same , he modified SQL dB directly and he was the CTO and one of primary architects of the system.

This is admin UI given to operations staff , far more trivial to have writes protected ,I cannot imagine anyone need to write to customer data that often in this kind of app.

Re: Twitter internal panel linked to account hijackings

#280
post #263

Earlier quoted context omitted.

If it’s SMS the attacker could have social engineered (big cell service co) to get access to the employee’s phone # and get a SIM. I’m guessing someone re-used a hacked password and SMS 2FA is to blame. Maybe it’s not even that sophisticated.

I have a little thingie that generates time based codes, similar to wee-calculators banks use but w/o the pin, that's on top of a private key. SMS is fine for end user access but companies can do better, even RSA/Google authenticator are a lot better option than SMS

Most tech companies like google and Facebook use hardware keys like Yubikey. TOTP and definitely sms are not as secure as hardware keys
Post reply on HN