With the info we have it looks like hackers changed the email id of the accounts and then used forgot password to reset the password. What’s concerning is that they were able to do it for accounts with 2FA enabled. I think disabling 2FA should be extremely privileged actions and should not accessible to most employees.
They apparently have another level of auth, used for at least Trump's account. And probably the CEO's considering past events.
Twitter internal panel linked to account hijackings
331–340 of 477 posts
Re: Twitter internal panel linked to account hijackings
#332Earlier quoted context omitted.
Not really, when you factor in inflation, unless you're planning on living in abject poverty your whole life or not planning on living very long. e.g., Vietnam is a livable place and GDP per capita is ~$2600. That'd get you a very modest living. GDP/capita is also up 2x from 10 years ago and 10x from 20 years ago. You could maybe squeak out 20 years with very modest living and few unplanned expenses and assuming the…
I could easily survive and be happy on 12 BTC for the rest of my life and I live in one of the most expensive countries in the world.
Re: Twitter internal panel linked to account hijackings
#333Earlier quoted context omitted.
The CFAA makes it a federal crime to access a computer in excess of authorization. The employee was unlikely to be authorized to use Twitter's customers' accounts to collect money from their followers, so it sounds like an open and shut case. I know HN doesn't believe in laws, but the rest of the world does, and they're the ones with prosecutors.
But surely they didn't access the system and post these messages themselves. They could argue, with the advent of remote working getting more and more predominant, that they simply left their computer unattended for a second while logged in. Beyond that, they could argue they simply clicked on a link and something might have happened they aren't aware of. Or that they didn't know what running that one executable woul…
Re: Twitter internal panel linked to account hijackings
#334Re: Twitter internal panel linked to account hijackings
#335> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
But you would need to educate people with access about the importance of impartial management of user data.
Banks had a culture enforcing neutrality and most importantly discretion. That is not true for modern payment processors like paypal or mastercard though.
You certainly don't want Twitter activists in such a role, regardless of political affiliation.
Re: Twitter internal panel linked to account hijackings
#336> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right. Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do. So a random customer service rep couldn't access my account without my phone in their hand, even if they managed t…
Re: Twitter internal panel linked to account hijackings
#337Earlier quoted context omitted.
I have a little thingie that generates time based codes, similar to wee-calculators banks use but w/o the pin, that's on top of a private key. SMS is fine for end user access but companies can do better, even RSA/Google authenticator are a lot better option than SMS
Most tech companies like google and Facebook use hardware keys like Yubikey. TOTP and definitely sms are not as secure as hardware keys
SMS is seen as less safe because the transport layer is not encrypted. But there isn't much difference in the practical security of the average user.
Re: Twitter internal panel linked to account hijackings
#338Earlier quoted context omitted.
But that's gross misconduct or some other fireable offense - a civil matter at best. The only item I can see here is fraud (impersonating the people whose accounts have been taken over), of which the mole would be complicit.
No, using a computer system in a manner other than explicitly authorized is a federal offence under the CFAA. That's been exceptionally controversial, as it can turn contract breach into a federal criminal offence in the US.
Doesn't something similar happen with employer-provided accommodation and burglary laws?
Re: Twitter internal panel linked to account hijackings
#339> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right. Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do. So a random customer service rep couldn't access my account without my phone in their hand, even if they managed t…
Whats the point of this step
Re: Twitter internal panel linked to account hijackings
#340Earlier quoted context omitted.
Or maybe it took them quite a while to "become aware of the incident" in the first place, but that's just as bad.
They spent an hour or two deleting tweets on Elon Musk's account, with new tweets appearing soon after. So it seemed like they were aware of his account being compromised but did not immediately [successfully] lock his account.