Twitter internal panel linked to account hijackings
371–380 of 477 posts
Re: Twitter internal panel linked to account hijackings
#372Earlier quoted context omitted.
It might also be that impersonating a government official is a serious crime. Sure, the hackers here have committed a crime, but this was more of an embarrassment for Twitter than anything else. If they had posted from Trump's account though...
It is also that many people will not think it is a hack . Trump does post all sorts of things . There is no tweet from his acc will surprise me that he actually posted it
Re: Twitter internal panel linked to account hijackings
#373This is starting to sound too elaborate for it to be a “hacker” under a basement showing off.
Re: Twitter internal panel linked to account hijackings
#374Earlier quoted context omitted.
The mechanism isn't relevant because the admin tool has a reset function. It is needed of course, because people loose their phones, keys and whatnot. No security mechanism is safe against an administrative reset for services like Twatter. SMS is seen as less safe because the transport layer is not encrypted. But there isn't much difference in the practical security of the average user.
> SMS is seen as less safe because the transport layer is not encrypted. Lack of encryption is only part of the problem. Lack of proper authentication is more important. Mobile networks are vulnerable to SS7 redirects, SIM-Jacking and plain old social engineering. The 2FA reset function is also a part of doing 2FA properly. Your reset needs to be at least as secure as the regular 2FA flow. Meaning that "just phoning…
Edit to the topic: As I said, the transport layer of SMS isn't safe, but I don't think it has practical merit. How often were SMS redirected or spied upon? In high profile cases? Even that would be difficult to determine, but the occurrence is probably very low.
And for a twitter account? Seriously? Depends on the account but assessment of threats is the first step of an honest security review. My reddit pwd has been 'reddit' for years. That wouldn't fly if I were Madonna and if I had any attachment to it.
Re: Twitter internal panel linked to account hijackings
#375FYI for anyone working at Twitter, the legacy JS disabled mobile site still displays the hacked bitcoin tweets. For example try this with JS disabled vs enabled (404): https://mobile.twitter.com/JoeBiden/status/12835123178466590...
Re: Twitter internal panel linked to account hijackings
#376Earlier quoted context omitted.
Weird that they didn't require any MFA from a second support // Admin account when dealing with account security settings for prominent accounts. That's not that hard to set up and makes these sort of things harder to pull off. Not to mention severe rate limitation on internal accounts. How many prominent accounts does one support person need to reset password or email per day? Not that many, I'd wager.
Imagine the potential damage if an attacker tweeted something on behalf of the US President (let's say Biden in 2022), that China or Iran or Russia ships could be sunk at any moment if they didn't withdraw (due to some ongoing real incident)... The other side might fire on US ships before the tweet could be corrected. Twitter is a disaster waiting to happen.
Re: Twitter internal panel linked to account hijackings
#377Earlier quoted context omitted.
It is also that many people will not think it is a hack . Trump does post all sorts of things . There is no tweet from his acc will surprise me that he actually posted it
So if people are less likely to think it is a hack, then they're more likely to send bitcoin in response to a tweet from his account. They'd hack Trump's twitter first if they could.
Re: Twitter internal panel linked to account hijackings
#378Earlier quoted context omitted.
Having access to some is not the same as having access to all . Rate limiting , or restricting to ones I am managing and approval processes are pretty easy . It does not like Twitter is doing any of that .
They accessed maybe 30 accounts? that's less than 4 per 8hr working shift I imagine a support person does more than in an average day. And while we might have seen all the tweets at the same time, they might have been changing emails and passwords over few hours. Remember twitter has so many users they probably get tens of thousands support requests per day. Even if you have monitoring, I don't think volume was enoug…
Re: Twitter internal panel linked to account hijackings
#379Re: Twitter internal panel linked to account hijackings
#380> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…