Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

341–350 of 477 posts

Re: Twitter internal panel linked to account hijackings

#341

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

Each place is different, I guess.

When I worked at Apple Retail, there was an internal iCloud dashboard you could log into and see _metadata_ about customer accounts. You couldn’t see anything juicy, for Find My iPhone/Friends it was just the name of people would could see your location, not locations themselves. Number of documents, not access to actual documents.

But nothing was visible to you until you verified the customer through security questions, last four digits, etc.

Re: Twitter internal panel linked to account hijackings

#342
post #76

I find it hard to believe this was a Social Engineering based attack. Elon Musk’s account was accessed multiple times after their tweets being deleted and it seemed to last forever, account by account being taken over.

The account was fully hijacked, email and password changed, 2FA was disabled. At that point the account basically belonged to someone else. I don’t think they realized the scope and angle of the attack.

Re: Twitter internal panel linked to account hijackings

#343
post #339

Earlier quoted context omitted.

Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right. Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do. So a random customer service rep couldn't access my account without my phone in their hand, even if they managed t…

> Then after that I have to read off my 2FA code. Whats the point of this step

Make sure that even with a hacked SIM a malicious CSR can't access your account without your knowledge.

Re: Twitter internal panel linked to account hijackings

#344

Earlier quoted context omitted.

The CFAA makes it a federal crime to access a computer in excess of authorization. The employee was unlikely to be authorized to use Twitter's customers' accounts to collect money from their followers, so it sounds like an open and shut case. I know HN doesn't believe in laws, but the rest of the world does, and they're the ones with prosecutors.

But surely they didn't access the system and post these messages themselves. They could argue, with the advent of remote working getting more and more predominant, that they simply left their computer unattended for a second while logged in. Beyond that, they could argue they simply clicked on a link and something might have happened they aren't aware of. Or that they didn't know what running that one executable woul…

[deleted]

Re: Twitter internal panel linked to account hijackings

#345
post #323

Earlier quoted context omitted.

> The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack If the attackers had a big short position in TWTR, they may have made a lot more money than they received from BTC.

Shorts get caught. Easier to have Elon Musk tweet "I'll buy Hertz at $69 a share to make all their cars autonomous".

Is this really true though? If you ramp up multiple short positions under a few weeks from a lot of different accounts, how would you tell? I'm assuming TWTR is a pretty busy stock.

Re: Twitter internal panel linked to account hijackings

#346

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

We should be a bit skeptical of any claims by the hackers until there is more evidence.

Re: Twitter internal panel linked to account hijackings

#347
post #311

Earlier quoted context omitted.

> If this turns out to be true, they'd be lucky not to go to prison. I’m not sure what you’d charge them with?

The CFAA makes it a federal crime to access a computer in excess of authorization. The employee was unlikely to be authorized to use Twitter's customers' accounts to collect money from their followers, so it sounds like an open and shut case. I know HN doesn't believe in laws, but the rest of the world does, and they're the ones with prosecutors.

1st 2 sentences: good comment! +1

Parting shot: unnecessary, obnoxious. -1

Net: 0

Re: Twitter internal panel linked to account hijackings

#348
post #339

Earlier quoted context omitted.

> Then after that I have to read off my 2FA code. Whats the point of this step

Make sure that even with a hacked SIM a malicious CSR can't access your account without your knowledge.

Also ensuring that a hacker can get the 2FA token directly from the owner by pretending to be customer service...

Re: Twitter internal panel linked to account hijackings

#349

Earlier quoted context omitted.

The CFAA makes it a federal crime to access a computer in excess of authorization. The employee was unlikely to be authorized to use Twitter's customers' accounts to collect money from their followers, so it sounds like an open and shut case. I know HN doesn't believe in laws, but the rest of the world does, and they're the ones with prosecutors.

But surely they didn't access the system and post these messages themselves. They could argue, with the advent of remote working getting more and more predominant, that they simply left their computer unattended for a second while logged in. Beyond that, they could argue they simply clicked on a link and something might have happened they aren't aware of. Or that they didn't know what running that one executable woul…

Vaguely plausible excuses will not dissuade prosecutors in possession of contrary evidence.

Re: Twitter internal panel linked to account hijackings

#350

Is nobody bothered by the shadow-banning? "Trends blacklist" and "Search blacklist"? Talk about transparency...

It's been pretty much standard practice on many social media for years.

My problem with it is how it's not acknowledged.

Post reply on HN