Twitter internal panel linked to account hijackings
281–290 of 477 posts
Re: Twitter internal panel linked to account hijackings
#282Anyone else unimpressed with Twitter's U2F/FIDO token support? They support a total of 1 (one) U2F token on an account :( The only other company I know that does that is AWS and one U2F token. Every other site I use allows multiples, usually at least 5 or more. I setup U2F on Twitter but then got rid of it after realizing they only allow one.
the entirety of AWS seems to be half assed in general as you've described: the U2F functionality is completely useless because if you lose/break your single U2F key then you're completely screwed and they still have no support for ed25519 keys (which were added to OpenSSH in 2013), unlike every other cloud service I have to have an RSA key just for AWS (particuraly annoying as I have all my other ssh keys stored in a…
Re: Twitter internal panel linked to account hijackings
#283Earlier quoted context omitted.
This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…
Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…
Re: Twitter internal panel linked to account hijackings
#284According to some images, Twitter low level employees can see email address of all accounts (and I guess phone numbers). I know some celebrities have their real email address and phone numbers on those accounts. Isn't that something bad?
The management of individual accounts is generally performed by low-level employees at companies like this. It's operational work that is thought to scale poorly and the costs of it are looked upon unfavorably by public market investors. Hence, there is constant pressure to push it to as low of a level as possible. Perhaps a higher tier of user support personnel handles verified accounts (or accounts somehow flagged…
Re: Twitter internal panel linked to account hijackings
#285Earlier quoted context omitted.
I didnt even know I wanted to know this. My guess is between Jeff and Bill. They're the leading ones who can afford giving twice the money back ;)
I'd assume one closer to crypto, probably Elon Musk or Coinbase. Because the audience needs to know how to quickly send BTC. In addition, it's a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his. So, maybe some thought today Musk is having it and finally doing it for real! If there is a person to run such a campaign for real, it would be him - so it could even be pl…
How does twitter allow this spam?
Re: Twitter internal panel linked to account hijackings
#286To me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisti…
I think there are three possible explanations here: 1- (Tinfoil hats please) This is a state owned attack, which is a retaliation from US Government to ruin Twitter's credibility and introduce social media regulations. 2- The hackers are gray hat hackers, who know that reporting this vulnerability will not make them any money and they want to get what they think they deserve, so they make it public and get some good…
Just the massive blast radius of the hack reminded me of the NK Sony hack and release of documents. Big up yours to Hollywood from Kim Jong.
Re: Twitter internal panel linked to account hijackings
#287Wait a second...they were hacked in a way that makes it so we can't trust any tweets. Does it make sense, then, for them to use tweets to report their progress on addressing this?
Why not? They're not updating HN with those but media and shareholders.
This kind of compromised messaging is not unknown while being attacked , when browserstack got hacked few years back, the attackers send official email to all customers whose emails they got in the leak saying the company was shutting down.
Re: Twitter internal panel linked to account hijackings
#288Did the attackers have direct access to the database, or why does their internal admin dashboard allow employees to tweet on behalf of any account?
Perhaps the admin dashboard allows support staff to reset emails/passwords, and they simply logged in as the users to tweet.
Re: Twitter internal panel linked to account hijackings
#289Earlier quoted context omitted.
But that's not really identity then right? That just becomes my hnews/reddit username that's unverified. I read @elonmusk because I trust it's him and I'm interested in what he says. Personally, I genuinely like Starship + Starlink updates... I ignore most the other stuff. But still, I want to see those awesome rocket tweets! So, I want to know what he says. He can change his username because it got hacked/whatever..…
Your hnews username is an identity. A small, weak, and reasonably disposable one, that you can have many of. Why do you want to use your God damn real name on the Internet unless you are a public person already? What do you have to gain? Hate mail, Death threats and calls for your firing? I've always wanted more of those. You do not WANT to be verified. Verified is a euphemism for doxxed. You could trust it was Elon…
Re: Twitter internal panel linked to account hijackings
#290The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…
This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…
I don't think there is something super nefarious involved. Probably some unpaid intern in a third world country where Twitter outsources tech support.