Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

291–300 of 477 posts

Re: Twitter internal panel linked to account hijackings

#291
post #120
post #113

Earlier quoted context omitted.

Based on what we know, it does sound like the attackers had full access to the accounts. That's a really interesting point about direct messages. It makes it all the more interesting that Obama and Biden and were both targets with the upcoming election. Wonder if those will start showing up on WikiLeaks again.

Does anybody on Hacker news seriously believe that the account of Biden or Obama actually send messages privately on Twitter? They most certainly don't. I have no idea why that fact is not obvious to some. Trump had two liked tweets for all of time back from like, 2012. Around 2017 or so a group realized this and bought or otherwise messed with the site the liked tweets linked to and made them have pictures making jo…

It is not required for them to send , people could have sent to them sensitive stuff.

A potential whistleblower , somebody having dirt on opposition .

It could be worse , even if you didn’t respond the fact that someone let’s say a foreign government or a spy or terrorist reached out to you can played in media they way your opponents want it

Re: Twitter internal panel linked to account hijackings

#292
post #285
post #230

Earlier quoted context omitted.

I'd assume one closer to crypto, probably Elon Musk or Coinbase. Because the audience needs to know how to quickly send BTC. In addition, it's a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his. So, maybe some thought today Musk is having it and finally doing it for real! If there is a person to run such a campaign for real, it would be him - so it could even be pl…

> a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his. How does twitter allow this spam?

That's a good question - there was a time, not too long ago where every single tweet of Musk was spammed with BTC giveaways.

Re: Twitter internal panel linked to account hijackings

#293

Its pretty amazing that realdonaldtrump@ was not a part of this. I guess the controls on that account are at an even higher level than elon musk/obama.

It might also be that impersonating a government official is a serious crime. Sure, the hackers here have committed a crime, but this was more of an embarrassment for Twitter than anything else. If they had posted from Trump's account though...

It is also that many people will not think it is a hack . Trump does post all sorts of things . There is no tweet from his acc will surprise me that he actually posted it

Re: Twitter internal panel linked to account hijackings

#294

Earlier quoted context omitted.

Immoral. Actively overriding what's really trending with what they prefer to trend. Assuming this leak is real.

Practically every "trending" algorithm involves some degree of manual tweaking. Otherwise, they end up prone to identifying uninteresting trends (like the current day of the week, or other time-sensitive trends like "lunch" showing up around local noon), or are easily manipulated by groups of users. Besides, one of the features of Twitter's Trends is a prose description of what the keyword references -- there's no wa…

“Jews” was trending for hours yesterday with top results displaying anti-Semitic tweets. Just saying.

Re: Twitter internal panel linked to account hijackings

#295
post #95

Earlier quoted context omitted.

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…

Weird that they didn't require any MFA from a second support // Admin account when dealing with account security settings for prominent accounts. That's not that hard to set up and makes these sort of things harder to pull off. Not to mention severe rate limitation on internal accounts. How many prominent accounts does one support person need to reset password or email per day? Not that many, I'd wager.

Re: Twitter internal panel linked to account hijackings

#296
post #265

If this is the true story. Is it a standard practice on social networks to give to an administrator the right to post anything in your name without any distinguishable marker? There is a enormous trust issue here. I expect an administrator to be able to moderate a post or disable an account, not to impersonate it from a admin dashboard.

[deleted]

Re: Twitter internal panel linked to account hijackings

#297

Earlier quoted context omitted.

The management of individual accounts is generally performed by low-level employees at companies like this. It's operational work that is thought to scale poorly and the costs of it are looked upon unfavorably by public market investors. Hence, there is constant pressure to push it to as low of a level as possible. Perhaps a higher tier of user support personnel handles verified accounts (or accounts somehow flagged…

Having access to some is not the same as having access to all . Rate limiting , or restricting to ones I am managing and approval processes are pretty easy . It does not like Twitter is doing any of that .

They accessed maybe 30 accounts? that's less than 4 per 8hr working shift

I imagine a support person does more than in an average day.

And while we might have seen all the tweets at the same time, they might have been changing emails and passwords over few hours.

Remember twitter has so many users they probably get tens of thousands support requests per day.

Even if you have monitoring, I don't think volume was enough to pick it up.

Re: Twitter internal panel linked to account hijackings

#298

Earlier quoted context omitted.

Why not? They're not updating HN with those but media and shareholders.

Because for all we know , it is not them posting this tweet and is the attackers . How can you trust it is them when the attack clearly showed any account can be manipulated. This kind of compromised messaging is not unknown while being attacked , when browserstack got hacked few years back, the attackers send official email to all customers whose emails they got in the leak saying the company was shutting down.

[deleted]

Re: Twitter internal panel linked to account hijackings

#299
post #90

FYI for anyone working at Twitter, the legacy JS disabled mobile site still displays the hacked bitcoin tweets. For example try this with JS disabled vs enabled (404): https://mobile.twitter.com/JoeBiden/status/12835123178466590...

4 hours later... Still live. (Wow, that site's quite the blast from the past.)

FFS Twitter, get your act together.

Re: Twitter internal panel linked to account hijackings

#300
post #134

Earlier quoted context omitted.

Plus there was no way they knew beforehand they'd only make 12BTC. People always overestimate the value of twitter and conversion rates when an actual action is required - even with targeted audiences like cryptocurrency people in this case. People seem to assume everyone takes tweets at face value and won't do a double take when it doesn't sound like something they would normally say. Even here there was plenty of p…

I’m surprised they pulled off that much.

They may not have: It's normally for various cons to pay themselves to some extent to add legitimacy to their actions and generate more attention.
Post reply on HN