Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

351–360 of 477 posts

Re: Twitter internal panel linked to account hijackings

#351

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right. Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do. So a random customer service rep couldn't access my account without my phone in their hand, even if they managed t…

What happens when you forget your code and lose your phone ?

Re: Twitter internal panel linked to account hijackings

#352
post #311

Earlier quoted context omitted.

Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…

> If this turns out to be true, they'd be lucky not to go to prison. I’m not sure what you’d charge them with?

CFAA, but if that doesn't work try out conspiracy, wire fraud, possibly money laundering.

Re: Twitter internal panel linked to account hijackings

#353

Earlier quoted context omitted.

> The fact that politicians and important people use it in an official capacity is the problem that needs fixing. I don't disagree, but with what? It's easy to say this is 'wrong/broken', but I don't see a great fix other than people 'rolling their own solution' and that's not realistic.

Pass regulation that puts in a place a federated messaging infrastructure, so that Twitter users can subscribe to messaging from Government official that sends out messages via an external system.

Like... email?

Re: Twitter internal panel linked to account hijackings

#354

This is why the concept of a blast radius exists. It is so important to critically examine and limit the blast radius of administrative actions. This is both from a vulnerability perspective as well as honest human mistakes. For certain actions like taking over an account and impersonation there should be rate limits all around. Overriding them requires a break glass process where multiple people may have to approve…

Twitter can probably afford to have all account actions to verified accounts be behind break-glass procedures and hire dedicated people to do nothing but watch and audit that.

Re: Twitter internal panel linked to account hijackings

#355
post #285
post #230

Earlier quoted context omitted.

I'd assume one closer to crypto, probably Elon Musk or Coinbase. Because the audience needs to know how to quickly send BTC. In addition, it's a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his. So, maybe some thought today Musk is having it and finally doing it for real! If there is a person to run such a campaign for real, it would be him - so it could even be pl…

> a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his. How does twitter allow this spam?

They don't, but the spammers have become more sophisticated over time. They use Cyrillic letters that look like Latin letters, they hack old unused accounts (sometimes verified ones), they post the spam as a second-level answer, they use images instead of tweeting text, they have started adding noise and various transforms to the images to make them harder to automatically classify as spam, and they probably have many more tricks up their sleeves. Fighting against spam is hard.

Re: Twitter internal panel linked to account hijackings

#356

Earlier quoted context omitted.

Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right. Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do. So a random customer service rep couldn't access my account without my phone in their hand, even if they managed t…

What happens when you forget your code and lose your phone ?

Presumably the process for that is much more involved and fewer people have the power to do it. And if it requires the approval of two higher up people to do then that lowers the risk even further.

Re: Twitter internal panel linked to account hijackings

#357

Earlier quoted context omitted.

> selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. Can't it just be that they're not that knowledgeable about stuff outside their domain? The things you mentioned require knowledge of stocks and politics. If I, personally, woke up tomorrow with access to a Twitter backdoor and the desire to exploit it, I wouldn't know how to do any of those things, because I also don't kno…

It would be pretty easy. You could just post on reddit or 4chan and ask "If you could make anyone on Twitter post anything, what's the most you could earn?" And people who know a lot about a lot of things would give you ideas. It's just not smart to use the hack for just this. Example: Contact Trump's kids. Demonstrate your power. Tell them you'll make Joe Biden tweet "8 year old girl nude hair" at a time of their ch…

5 million BTC is about US$45 billion.

Re: Twitter internal panel linked to account hijackings

#359

Earlier quoted context omitted.

Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…

It would surprise me if a lot of Twitter support people had access to tools that allowed them to post tweets as another user. That's not functionality that should be available to a Twitter support person.

They way I understand it based on the article is that they were only able to change the email address, then used that to reset the password and log in.

Re: Twitter internal panel linked to account hijackings

#360

Earlier quoted context omitted.

What happens when you forget your code and lose your phone ?

Presumably the process for that is much more involved and fewer people have the power to do it. And if it requires the approval of two higher up people to do then that lowers the risk even further.

And hopefully audited.
Post reply on HN