Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

361–370 of 477 posts

Re: Twitter internal panel linked to account hijackings

#361

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

> Does anyone know of customer service panels at big companies or government departments where this is the case? I.e., it is literally impossible for a rep to browse random customer information even if they are willing to break the rules?

Yes - no names for obvious reasons but where I work (trust me you've heard of them/probably use them and they are a huge tech company) it is very hard to get access to anything even slightly customer related. You need to go through multiple levels of review and approval (often your manager, their manager, and then directors/VPs) with genuine business justifications that actually looked at (no "asdf" here) to get access, and then it is usually only permitted for a window of months at most before it is auto-revoked. Then once you have access, every actual time you look at the data you need to provide justification (e.g. a ticket number that is actually checked to make sure it is open, not reused over and over, and not just 1234567890 etc and so on), and every single action you do with the data is tracked and audited so there is a complete 100% paper trail of who looked at what, when they did it, and why they were doing it, with traceability through to the tickets/bugs/etc for why there were even doing this in the first place. Abnormal things (e.g. systematic/repeated/etc) raises flags that do terrible things to your career. Each system/data source needs its own independent approval process.

There is no "god mode".

It is not uncommon for people to wait weeks for approvals to go through to access their own data to validate a bug fix etc. I think these safeguards are worthwhile - many would see them as a hindrance.

At past places, I implemented a call-centre UI once. We made it so that the service rep would initially not see anything about the customer, so the "Please can you confirm 3rd letter of your memorable word" or whatever meant that the service rep literally had a text box to type that letter in which had to match before they could proceed - they didn't see the whole world on screen and wait to see if the user got it right. I am not sure how common this is - when I do this from the customer side these days often the answer is immediately acknowledged by the rep without any kind of delay or typing noises so I am guessing they have my entire record on their screen and are just waiting for me to say the right things before continuing the call :(

Re: Twitter internal panel linked to account hijackings

#362

Earlier quoted context omitted.

> selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. Can't it just be that they're not that knowledgeable about stuff outside their domain? The things you mentioned require knowledge of stocks and politics. If I, personally, woke up tomorrow with access to a Twitter backdoor and the desire to exploit it, I wouldn't know how to do any of those things, because I also don't kno…

It would be pretty easy. You could just post on reddit or 4chan and ask "If you could make anyone on Twitter post anything, what's the most you could earn?" And people who know a lot about a lot of things would give you ideas. It's just not smart to use the hack for just this. Example: Contact Trump's kids. Demonstrate your power. Tell them you'll make Joe Biden tweet "8 year old girl nude hair" at a time of their ch…

> Example: Contact Trump's kids. Demonstrate your power. Tell them you'll make Joe Biden tweet "8 year old girl nude hair" at a time of their choosing, in exchange for 5 million BTC held in escrow. This doesn't require anything more than knowing that Trump is rich and corrupt and that Biden is his opponent.

And then you get tracked down and killed by a three-letter agency. I think people underestimate how risk-free receiving small amounts of btc from random schmucks is, and how risk-averse these hackers may be.

Re: Twitter internal panel linked to account hijackings

#363
post #285
post #230

Earlier quoted context omitted.

I'd assume one closer to crypto, probably Elon Musk or Coinbase. Because the audience needs to know how to quickly send BTC. In addition, it's a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his. So, maybe some thought today Musk is having it and finally doing it for real! If there is a person to run such a campaign for real, it would be him - so it could even be pl…

> a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his. How does twitter allow this spam?

Shocking that they don't take even basic precautions like image hashing to cut down on this.

Re: Twitter internal panel linked to account hijackings

#364

Earlier quoted context omitted.

Most tech companies like google and Facebook use hardware keys like Yubikey. TOTP and definitely sms are not as secure as hardware keys

The mechanism isn't relevant because the admin tool has a reset function. It is needed of course, because people loose their phones, keys and whatnot. No security mechanism is safe against an administrative reset for services like Twatter. SMS is seen as less safe because the transport layer is not encrypted. But there isn't much difference in the practical security of the average user.

> SMS is seen as less safe because the transport layer is not encrypted.

Lack of encryption is only part of the problem. Lack of proper authentication is more important. Mobile networks are vulnerable to SS7 redirects, SIM-Jacking and plain old social engineering.

The 2FA reset function is also a part of doing 2FA properly. Your reset needs to be at least as secure as the regular 2FA flow. Meaning that "just phoning support" isn't an option. Yes, resets will be cumbersome and might involve stuff like physical presence, showing a government ID and maybe being vouched for by a third party. Most companies fail badly at this.

Re: Twitter internal panel linked to account hijackings

#365
post #295

Earlier quoted context omitted.

Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…

Weird that they didn't require any MFA from a second support // Admin account when dealing with account security settings for prominent accounts. That's not that hard to set up and makes these sort of things harder to pull off. Not to mention severe rate limitation on internal accounts. How many prominent accounts does one support person need to reset password or email per day? Not that many, I'd wager.

Imagine the potential damage if an attacker tweeted something on behalf of the US President (let's say Biden in 2022), that China or Iran or Russia ships could be sunk at any moment if they didn't withdraw (due to some ongoing real incident)... The other side might fire on US ships before the tweet could be corrected.

Twitter is a disaster waiting to happen.

Re: Twitter internal panel linked to account hijackings

#366

Earlier quoted context omitted.

Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…

It would surprise me if a lot of Twitter support people had access to tools that allowed them to post tweets as another user. That's not functionality that should be available to a Twitter support person.

Having worked at large tech companies - it would not surprise me at all if many did. ...at least through unofficial channels or not-entirely-secure processes.

Re: Twitter internal panel linked to account hijackings

#367

Earlier quoted context omitted.

Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…

I’m not saying there isn’t one, but curious what you think is the imprisonable offense?

Impersonating a member of the military?

Re: Twitter internal panel linked to account hijackings

#368
post #134

Earlier quoted context omitted.

Plus there was no way they knew beforehand they'd only make 12BTC. People always overestimate the value of twitter and conversion rates when an actual action is required - even with targeted audiences like cryptocurrency people in this case. People seem to assume everyone takes tweets at face value and won't do a double take when it doesn't sound like something they would normally say. Even here there was plenty of p…

12 BTC could be retirement level money in some countries.

Seems more likely that they expected to get more.

Re: Twitter internal panel linked to account hijackings

#369
post #134

Earlier quoted context omitted.

Plus there was no way they knew beforehand they'd only make 12BTC. People always overestimate the value of twitter and conversion rates when an actual action is required - even with targeted audiences like cryptocurrency people in this case. People seem to assume everyone takes tweets at face value and won't do a double take when it doesn't sound like something they would normally say. Even here there was plenty of p…

I’m surprised they pulled off that much.

I'm surprised they didn't get more.

Poorly executed, frankly. The tweet just wreaked of spam.

Re: Twitter internal panel linked to account hijackings

#370

Earlier quoted context omitted.

The most logical conclusion is that this probably wasn't about money. Plenty of better ways to make money than telling people to give you BTC. I'm expecting a huge data drop on wikileaks/pastebin/wherever of private DMs, images, who knows what else.

I am struggling to think of any better system than BTC. Almost anything else I can think of would require either (a) substansal amount of starting cash (for example trying to crash Tesla's stock price), or (b) be almost impossible to pull off without getting caught (blackmail, or again stock manipulation if you do it in a big enough way to make some decent money). In terms of risk/reward, assuming someone found some…

I don’t think it would take very much starting cash at all to make money off a Tesla crash. Options can be pretty cheap for moonshots.

Alternatively, is it possible they bought options on twitter itself? It’s down 4% in after-hours (which is less than I expected, but still enough delta to make some cash).

Post reply on HN