> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right. Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do. So a random customer service rep couldn't access my account without my phone in their hand, even if they managed t…
Twitter internal panel linked to account hijackings
351–360 of 477 posts
Re: Twitter internal panel linked to account hijackings
#352Earlier quoted context omitted.
Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…
> If this turns out to be true, they'd be lucky not to go to prison. I’m not sure what you’d charge them with?
Re: Twitter internal panel linked to account hijackings
#353Earlier quoted context omitted.
> The fact that politicians and important people use it in an official capacity is the problem that needs fixing. I don't disagree, but with what? It's easy to say this is 'wrong/broken', but I don't see a great fix other than people 'rolling their own solution' and that's not realistic.
Pass regulation that puts in a place a federated messaging infrastructure, so that Twitter users can subscribe to messaging from Government official that sends out messages via an external system.
Re: Twitter internal panel linked to account hijackings
#354This is why the concept of a blast radius exists. It is so important to critically examine and limit the blast radius of administrative actions. This is both from a vulnerability perspective as well as honest human mistakes. For certain actions like taking over an account and impersonation there should be rate limits all around. Overriding them requires a break glass process where multiple people may have to approve…
Re: Twitter internal panel linked to account hijackings
#355Earlier quoted context omitted.
I'd assume one closer to crypto, probably Elon Musk or Coinbase. Because the audience needs to know how to quickly send BTC. In addition, it's a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his. So, maybe some thought today Musk is having it and finally doing it for real! If there is a person to run such a campaign for real, it would be him - so it could even be pl…
> a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his. How does twitter allow this spam?
Re: Twitter internal panel linked to account hijackings
#356Earlier quoted context omitted.
Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right. Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do. So a random customer service rep couldn't access my account without my phone in their hand, even if they managed t…
What happens when you forget your code and lose your phone ?
Re: Twitter internal panel linked to account hijackings
#357Earlier quoted context omitted.
> selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. Can't it just be that they're not that knowledgeable about stuff outside their domain? The things you mentioned require knowledge of stocks and politics. If I, personally, woke up tomorrow with access to a Twitter backdoor and the desire to exploit it, I wouldn't know how to do any of those things, because I also don't kno…
It would be pretty easy. You could just post on reddit or 4chan and ask "If you could make anyone on Twitter post anything, what's the most you could earn?" And people who know a lot about a lot of things would give you ideas. It's just not smart to use the hack for just this. Example: Contact Trump's kids. Demonstrate your power. Tell them you'll make Joe Biden tweet "8 year old girl nude hair" at a time of their ch…
Re: Twitter internal panel linked to account hijackings
#358Re: Twitter internal panel linked to account hijackings
#359Earlier quoted context omitted.
Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…
It would surprise me if a lot of Twitter support people had access to tools that allowed them to post tweets as another user. That's not functionality that should be available to a Twitter support person.
Re: Twitter internal panel linked to account hijackings
#360Earlier quoted context omitted.
What happens when you forget your code and lose your phone ?
Presumably the process for that is much more involved and fewer people have the power to do it. And if it requires the approval of two higher up people to do then that lowers the risk even further.