Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

311–320 of 477 posts

Re: Twitter internal panel linked to account hijackings

#311
post #95

Earlier quoted context omitted.

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…

> If this turns out to be true, they'd be lucky not to go to prison.

I’m not sure what you’d charge them with?

Re: Twitter internal panel linked to account hijackings

#312

Earlier quoted context omitted.

No, that's easy. People's accounts get hacked all the time. To help them recover is often a manual process, because the true owner of the account can become unclear. To be able to do that a support worker must be able to change the email address on an account, undo 2FA settings and make other changes because hackers will typically change the email address and add 2FA of their own phone as the first step in an account…

But why would the support worker need to be able to post a tweet?

If you can change the owner of an account you don't need a special interface to post a tweet.

Re: Twitter internal panel linked to account hijackings

#313
post #95

Earlier quoted context omitted.

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

The most logical conclusion is that this probably wasn't about money. Plenty of better ways to make money than telling people to give you BTC. I'm expecting a huge data drop on wikileaks/pastebin/wherever of private DMs, images, who knows what else.

I am struggling to think of any better system than BTC.

Almost anything else I can think of would require either (a) substansal amount of starting cash (for example trying to crash Tesla's stock price), or (b) be almost impossible to pull off without getting caught (blackmail, or again stock manipulation if you do it in a big enough way to make some decent money).

In terms of risk/reward, assuming someone found some easy trick and wanted to cash out ASAP, this feels like the best option.

Re: Twitter internal panel linked to account hijackings

#314

Earlier quoted context omitted.

How would a VPN help in this case though? They social-engineered some employees to gain privileged access to the admin UI. If a VPN was in the way they'd do the same thing to get access to the VPN first.

I've seen some solutions where the VPN only works on the company machine. In this case, the social engineered employee would at least have to hand over their laptop.

That's indeed often the case, how it works is that the machine itself has a client certificate it uses to authenticate with the VPN.

There's no reason that certificate can't be used directly for the HTTPS connection to the admin UI, providing the same security benefits without actually requiring a VPN.

Furthermore depending on how "deep" the social engineering attack goes, a local user with administrator privileges can typically export those certificates unless they are stored on a hardware module (either a smartcard or an internal TPM/secure element).

Re: Twitter internal panel linked to account hijackings

#315
post #267

Earlier quoted context omitted.

12 BTC could be retirement level money in some countries.

Not really, when you factor in inflation, unless you're planning on living in abject poverty your whole life or not planning on living very long. e.g., Vietnam is a livable place and GDP per capita is ~$2600. That'd get you a very modest living. GDP/capita is also up 2x from 10 years ago and 10x from 20 years ago. You could maybe squeak out 20 years with very modest living and few unplanned expenses and assuming the…

I could easily survive and be happy on 12 BTC for the rest of my life and I live in one of the most expensive countries in the world.

Re: Twitter internal panel linked to account hijackings

#316
post #82

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

This makes a lot more sense. I can't imagine Twitter isn't using some sort of phsyical 2FA like yubikeys which are virtually Phish proof if implemented well. That being said, what was the employee's endgame here?

Possibly politically motivated?

Especially if the real motivation is not the BTC scam, but the access to who knows how many DMs for possibly blackmail/propaganda down the line. (And not necessarily just DMs from the known compromised accounts, either.)

Re: Twitter internal panel linked to account hijackings

#317

To me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisti…

I think there are three possible explanations here: 1- (Tinfoil hats please) This is a state owned attack, which is a retaliation from US Government to ruin Twitter's credibility and introduce social media regulations. 2- The hackers are gray hat hackers, who know that reporting this vulnerability will not make them any money and they want to get what they think they deserve, so they make it public and get some good…

[deleted]

Re: Twitter internal panel linked to account hijackings

#318

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

USD, the WD-40 of social engineering

That's a great turn of phrase!

Re: Twitter internal panel linked to account hijackings

#319
post #311

Earlier quoted context omitted.

Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…

> If this turns out to be true, they'd be lucky not to go to prison. I’m not sure what you’d charge them with?

Fraud, theft, aiding and abetting, surely some digital wiretapping laws

Re: Twitter internal panel linked to account hijackings

#320
post #311

Earlier quoted context omitted.

Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…

> If this turns out to be true, they'd be lucky not to go to prison. I’m not sure what you’d charge them with?

The CFAA makes it a federal crime to access a computer in excess of authorization. The employee was unlikely to be authorized to use Twitter's customers' accounts to collect money from their followers, so it sounds like an open and shut case.

I know HN doesn't believe in laws, but the rest of the world does, and they're the ones with prosecutors.

Post reply on HN