Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

301–310 of 477 posts

Re: Twitter internal panel linked to account hijackings

#301

Earlier quoted context omitted.

Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…

It would surprise me if a lot of Twitter support people had access to tools that allowed them to post tweets as another user. That's not functionality that should be available to a Twitter support person.

No, that's easy.

People's accounts get hacked all the time. To help them recover is often a manual process, because the true owner of the account can become unclear. To be able to do that a support worker must be able to change the email address on an account, undo 2FA settings and make other changes because hackers will typically change the email address and add 2FA of their own phone as the first step in an account takeover.

Re: Twitter internal panel linked to account hijackings

#302
post #126

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

This. It would be unbelievable if Twitter's internal system doesn't require VPN/BeyondCorp or 2FA before doing anything sensitive.

Why?

The tool in question is likely used by low level support/abuse control workers. The huge pressure put on social media firms by liberals in recent years to crack down on "abuse", "hate" etc means they need a vast army of people to review complaints about harassment, "fake news", account hijacking etc. Those employees aren't all sitting in expensive San Francisco on a corp VPN, are they? They're probably going to be in places like India.

From the mention of BeyondCorp, it feels like there are a lot of Googlers in this thread who aren't really familiar with how Google handled the same problem, or at least, used to. For example back when Orkut was big there were huge numbers of people in Brazil who had the power to censor content, ban users, handle victims of phishing and so on. It was the only way to scale the moderation users and governments there demanded.

An ideal user admin tool is very fine grained. But once account hijacking entered the picture, it gets hard to truly restrict takeover permissions to a tiny number of people, because accounts are constantly being taken over by third parties and need to be reset back to the true owner via manual intervention. Attempts to automatically handle that are very hard, I know from experience. Hackers like to abuse any system put in place to stop them taking over accounts (like 2FA) to stop the true owner taking it back once captured.

Re: Twitter internal panel linked to account hijackings

#303
post #265

If this is the true story. Is it a standard practice on social networks to give to an administrator the right to post anything in your name without any distinguishable marker? There is a enormous trust issue here. I expect an administrator to be able to moderate a post or disable an account, not to impersonate it from a admin dashboard.

From reading HN comments, it is more likely that the attacker changed the account email from the admin panel and took over the account (even accounts with 2FA enabled), which seem more likely to me.

To prevent this kind of mess, Twitter should add more restrictions do disable 2FA on an account (multiple admin authorizations, email notification, add delay before the action is performed) and also change the account state to unverified and add to the feed a "email changed" or "identity changed" status. I also think that changing the email should not be immediate and that the old email should be notified of the change.

Re: Twitter internal panel linked to account hijackings

#305

Earlier quoted context omitted.

We use OpsGenie at work. I've used their support a couple of times. Every time they needed to look at our company's account settings I've had to approve it (using some sort of OpsGenie internal tool). I was pleasantly surprised. It's impossible to tell as a customer how hard it is to access my data without that internal authorization system, but it at least looks better than nothing.

There is no guarantee though, i.e. the system could be well intentioned but if could be bypassed , it does not really protect. The only way to get some assurance is run vendor app in your environment in a secure network without the ability to phone home.

Obviously it can be bypassed in the sense that somebody has full administrator database access.

The point about schemes like this is that instead of having to give 1000 support reps full access, you only give a few sysadmins full access. The likelihood of something going wrong with the data (through mistakes, willful abuse, extortion, whatever) goes drastically down.

In fact, once you got such a permission system in place, it becomes very attractive for the organization to use it. I mean, customers love it, they spontaneously write comments about it on Hacker News.

Even if you begin adopting it only for security theater (i.e. everybody still actually has full access), eventually some principled engineer brings up the idea to maybe remove full access for everybody cause now they have the access-granting system anyway, and this time they'll make a convincing case because the "move fast and break things" people have way fewer practical objections.

Re: Twitter internal panel linked to account hijackings

#306

Earlier quoted context omitted.

I think there are three possible explanations here: 1- (Tinfoil hats please) This is a state owned attack, which is a retaliation from US Government to ruin Twitter's credibility and introduce social media regulations. 2- The hackers are gray hat hackers, who know that reporting this vulnerability will not make them any money and they want to get what they think they deserve, so they make it public and get some good…

Regarding #1, my thinking was this is China or their allied nations (North Korea, Iran etc). The US has taken extremely forceful steps on China in the last couple of days. This could be their response; discrediting a huge piece of the American crown jewels (big tech companies) and making it a laughing stock. Just the massive blast radius of the hack reminded me of the NK Sony hack and release of documents. Big up you…

I would expect state actors to have gone for a lot more damage than "make Twitter look stupid". Also, all the high-profile state actor hacks I'm aware of were a lot more clandestine - it was months before they were discovered. State actors are highly professional, they're in it for the long haul, and they do serious damage.

The "massive blast radius" of this hack lies more in the damage it could have done, rather than the damage it actually did. This amateur execution makes me think it was some small-time cyber criminal who happened to have the bright idea of bribing a Twitter employee, but didn't have the know-how/creativity/patience to reap its full benefits.

Re: Twitter internal panel linked to account hijackings

#307

RE: social engineering, as long as a human is involved somewhere, the system can be compromised. IT security is a very depressing field because of this fact. I also hope these incidents remind people of how little control you really have over your online identity. We're all just IDs in a database somewhere, waiting to be impersonated. Decentralization is the only solution for this IMO.

Honest question, how do I recover a lost identity? The reason why this attack worked is primarily because of a recovery system. I agree this is a significant vector, but I can't see how decentralized solves this? At the moment with blockchain wallets, once you've lost your private key, you're screwed. There is no recovery. So, I'm all for decentralized but if it is truly my identity, I need a way back if I lose it. N…

Is there an indication that this was done through a recovery system rather on many individual accounts than a compromised admin account?

Re: Twitter internal panel linked to account hijackings

#309

Earlier quoted context omitted.

The most reasonable explanation might be that they’re lying to sound cool. Bribery is a thing, but any twitter employee would know that their employment (and future career prospects) would be terminated. On the other hand, $1M in BTC might do the trick. Interesting thought experiment...

There’s bribery but I think blackmail is even likelier. This is such a huge breach that no one should think they could get away with leaking their credentials or opening a backdoor. Plus Twitter employees are really well paid. Now some life-ruining online behavior material is another type of a motivator.

Are twitter support contractors in third world countries really well paid?

Re: Twitter internal panel linked to account hijackings

#310

Earlier quoted context omitted.

It would surprise me if a lot of Twitter support people had access to tools that allowed them to post tweets as another user. That's not functionality that should be available to a Twitter support person.

No, that's easy. People's accounts get hacked all the time. To help them recover is often a manual process, because the true owner of the account can become unclear. To be able to do that a support worker must be able to change the email address on an account, undo 2FA settings and make other changes because hackers will typically change the email address and add 2FA of their own phone as the first step in an account…

But why would the support worker need to be able to post a tweet?
Post reply on HN