Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

321–330 of 477 posts

Re: Twitter internal panel linked to account hijackings

#321
post #275

Earlier quoted context omitted.

I'm no lawyer either, but I imagine that the definition of authorisation is key here. If you're a sysadmin on a company email system, then you do technically have access to everyone's data on that system. However, you're generally limited by company policy that you are not permitted to access/modify that data without direct authorisation, say from the employee themselves or from HR. So, therefore, if you go and read…

But that's gross misconduct or some other fireable offense - a civil matter at best. The only item I can see here is fraud (impersonating the people whose accounts have been taken over), of which the mole would be complicit.

No, using a computer system in a manner other than explicitly authorized is a federal offence under the CFAA.

That's been exceptionally controversial, as it can turn contract breach into a federal criminal offence in the US.

Re: Twitter internal panel linked to account hijackings

#323
post #95

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

> The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack

If the attackers had a big short position in TWTR, they may have made a lot more money than they received from BTC.

Re: Twitter internal panel linked to account hijackings

#325
post #231

Didn't Twitter say that they don't shadow-ban? [1] From a leaked screenshot of the panel, though, it appears they have a search/trend blacklist. 1: https://www.washingtonexaminer.com/business/jack-dorseys-per... EDIT: thanks for the downvotes, twitter.

> EDIT: thanks for the downvotes It's against the site guidelines to do that, so please resist. https://news.ycombinator.com/newsguidelines.html

[deleted]

Re: Twitter internal panel linked to account hijackings

#327
post #323
post #95

Earlier quoted context omitted.

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

> The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack If the attackers had a big short position in TWTR, they may have made a lot more money than they received from BTC.

Shorts get caught. Easier to have Elon Musk tweet "I'll buy Hertz at $69 a share to make all their cars autonomous".

Re: Twitter internal panel linked to account hijackings

#328
post #311

Earlier quoted context omitted.

> If this turns out to be true, they'd be lucky not to go to prison. I’m not sure what you’d charge them with?

The CFAA makes it a federal crime to access a computer in excess of authorization. The employee was unlikely to be authorized to use Twitter's customers' accounts to collect money from their followers, so it sounds like an open and shut case. I know HN doesn't believe in laws, but the rest of the world does, and they're the ones with prosecutors.

But surely they didn't access the system and post these messages themselves.

They could argue, with the advent of remote working getting more and more predominant, that they simply left their computer unattended for a second while logged in.

Beyond that, they could argue they simply clicked on a link and something might have happened they aren't aware of. Or that they didn't know what running that one executable would do.

Re: Twitter internal panel linked to account hijackings

#329
post #323

Earlier quoted context omitted.

> The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack If the attackers had a big short position in TWTR, they may have made a lot more money than they received from BTC.

Shorts get caught. Easier to have Elon Musk tweet "I'll buy Hertz at $69 a share to make all their cars autonomous".

Shorts don't get caught, they'd blend right into the WSB crowd.

Also, if you had Elon tweet that, I am not sure if the price will go up or down like you expect. :)

Re: Twitter internal panel linked to account hijackings

#330
post #90

FYI for anyone working at Twitter, the legacy JS disabled mobile site still displays the hacked bitcoin tweets. For example try this with JS disabled vs enabled (404): https://mobile.twitter.com/JoeBiden/status/12835123178466590...

So, did you make Twitter aware of this?
Post reply on HN