Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

331–340 of 477 posts

Re: Twitter internal panel linked to account hijackings

#331
post #110

With the info we have it looks like hackers changed the email id of the accounts and then used forgot password to reset the password. What’s concerning is that they were able to do it for accounts with 2FA enabled. I think disabling 2FA should be extremely privileged actions and should not accessible to most employees.

They apparently have another level of auth, used for at least Trump's account. And probably the CEO's considering past events.

Yep. After the one employee deleted Trumps account. This is why I thought it might have been an internal tool; why wouldn’t they hack “THE” account?

Re: Twitter internal panel linked to account hijackings

#332
post #315
post #267

Earlier quoted context omitted.

Not really, when you factor in inflation, unless you're planning on living in abject poverty your whole life or not planning on living very long. e.g., Vietnam is a livable place and GDP per capita is ~$2600. That'd get you a very modest living. GDP/capita is also up 2x from 10 years ago and 10x from 20 years ago. You could maybe squeak out 20 years with very modest living and few unplanned expenses and assuming the…

I could easily survive and be happy on 12 BTC for the rest of my life and I live in one of the most expensive countries in the world.

$110k for the rest of your life? $500/month for 18 years? That wouldn’t cover health insurance plus rent (even though I’m sharing rent with a partner) here in Berlin, and Berlin is cheap compared to the UK or the bits of the USA I’ve visited.

Re: Twitter internal panel linked to account hijackings

#333

Earlier quoted context omitted.

The CFAA makes it a federal crime to access a computer in excess of authorization. The employee was unlikely to be authorized to use Twitter's customers' accounts to collect money from their followers, so it sounds like an open and shut case. I know HN doesn't believe in laws, but the rest of the world does, and they're the ones with prosecutors.

But surely they didn't access the system and post these messages themselves. They could argue, with the advent of remote working getting more and more predominant, that they simply left their computer unattended for a second while logged in. Beyond that, they could argue they simply clicked on a link and something might have happened they aren't aware of. Or that they didn't know what running that one executable woul…

They don’t sound like a criminal mastermind, it’s very likely they left some trace either locally or in Twitter’s system that will contradict that story.

Re: Twitter internal panel linked to account hijackings

#335

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

This is also why you want to have people in IT that can defer judgement if someone posts, does or says something that you do not like. Criminal behavior is another matter of course.

But you would need to educate people with access about the importance of impartial management of user data.

Banks had a culture enforcing neutrality and most importantly discretion. That is not true for modern payment processors like paypal or mastercard though.

You certainly don't want Twitter activists in such a role, regardless of political affiliation.

Re: Twitter internal panel linked to account hijackings

#336

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right. Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do. So a random customer service rep couldn't access my account without my phone in their hand, even if they managed t…

I’m not sure habituating people to getting asked for 2FA codes is a good idea. Seems like it’s just going to make people more susceptible to social engineering attacks.

Re: Twitter internal panel linked to account hijackings

#337
post #263

Earlier quoted context omitted.

I have a little thingie that generates time based codes, similar to wee-calculators banks use but w/o the pin, that's on top of a private key. SMS is fine for end user access but companies can do better, even RSA/Google authenticator are a lot better option than SMS

Most tech companies like google and Facebook use hardware keys like Yubikey. TOTP and definitely sms are not as secure as hardware keys

The mechanism isn't relevant because the admin tool has a reset function. It is needed of course, because people loose their phones, keys and whatnot. No security mechanism is safe against an administrative reset for services like Twatter.

SMS is seen as less safe because the transport layer is not encrypted. But there isn't much difference in the practical security of the average user.

Re: Twitter internal panel linked to account hijackings

#338
post #275

Earlier quoted context omitted.

But that's gross misconduct or some other fireable offense - a civil matter at best. The only item I can see here is fraud (impersonating the people whose accounts have been taken over), of which the mole would be complicit.

No, using a computer system in a manner other than explicitly authorized is a federal offence under the CFAA. That's been exceptionally controversial, as it can turn contract breach into a federal criminal offence in the US.

> That's been exceptionally controversial, as it can turn contract breach into a federal criminal offence in the US.

Doesn't something similar happen with employer-provided accommodation and burglary laws?

Re: Twitter internal panel linked to account hijackings

#339

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right. Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do. So a random customer service rep couldn't access my account without my phone in their hand, even if they managed t…

> Then after that I have to read off my 2FA code.

Whats the point of this step

Re: Twitter internal panel linked to account hijackings

#340

Earlier quoted context omitted.

Or maybe it took them quite a while to "become aware of the incident" in the first place, but that's just as bad.

They spent an hour or two deleting tweets on Elon Musk's account, with new tweets appearing soon after. So it seemed like they were aware of his account being compromised but did not immediately [successfully] lock his account.

It’s possible they didn’t understand the scope of the issue for a good amount of time. Elon’s account was the first to drop and was famous in the past for being faked for crypto scams. It’s entirely possible that they assumed it was a single account hijack and avoided notifying the correct people until it was too late. They might not have realized that the account info was changed as well until it was too late.
Post reply on HN