Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

391–400 of 477 posts

Re: Twitter internal panel linked to account hijackings

#391
post #275

Earlier quoted context omitted.

I'm no lawyer either, but I imagine that the definition of authorisation is key here. If you're a sysadmin on a company email system, then you do technically have access to everyone's data on that system. However, you're generally limited by company policy that you are not permitted to access/modify that data without direct authorisation, say from the employee themselves or from HR. So, therefore, if you go and read…

But that's gross misconduct or some other fireable offense - a civil matter at best. The only item I can see here is fraud (impersonating the people whose accounts have been taken over), of which the mole would be complicit.

Terry Childs...

Re: Twitter internal panel linked to account hijackings

#393
post #376

Earlier quoted context omitted.

Imagine the potential damage if an attacker tweeted something on behalf of the US President (let's say Biden in 2022), that China or Iran or Russia ships could be sunk at any moment if they didn't withdraw (due to some ongoing real incident)... The other side might fire on US ships before the tweet could be corrected. Twitter is a disaster waiting to happen.

Right, because all these other parties would totally not think Twitter might be hacked? I'm truly baffled by this kind of hysteria.

As you say, it would probably not work on foreign governments, but would be very effective on the general population. They could have used that to cause political turmoil (hopefully not enough to change something like elections results?) or influence stock prices etc. This just looks so uninspired...

Re: Twitter internal panel linked to account hijackings

#394
post #382

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

AT&T claims my security PIN will prevent agents and in store associates from accessing my account. The store rep said there’s no way for him to help me doing anything until we called a special hotline to give my PIN and approval. Doesn’t mean there isn’t a way around it for some reps with special access. If you don’t have a PIN someone can go and open up multiple new accounts separate from your primary account in you…

Wrong! Pin is designed as legal shield against you - it was initially designed because children of parents, disgrunted employees and angry spouses would show up with a phone and wanted access or make changes on that phone account and mere possesion of said phone “authorize” them. Now the terms of service clearly state pin is extra layer to protect your data from oursiders, be it your child or spouse. Meanwhile employees have full or near full access. I know this because my sister is a store manager. They would daily print list of accounts overdue and prepare list for followuos - should would check everyone in computer, their history of payments even zip code where they live and make decision whether to bother them with phonecall now or push it for another day. The only access they dont have is your credit card info. They cant even see the last four, since its separate third party company responsible for payments.

Re: Twitter internal panel linked to account hijackings

#395

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

The problem is that customers don't remember basically anything. I don't know my telephone banking password for any bank. When I call, I get asked to tell them what my last transaction was, or my mother's maiden name and DOB (public info), or what town I last used my card. I've been wrong about the recent usage questions more often than I've been right, and they say "close enough".

The technological measures have to account for human behaviour. Otherwise you just end up with almost everyone not being able to access almost everything almost all of the time. People are forgetful, irrational, stubborn and stupid. So are institutions. Put them together and you have a social engineering dream world (literally our current world).

Re: Twitter internal panel linked to account hijackings

#396
post #380

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

I work in banking. You’d be amazed at how serious the information and enterprise architecture is around PII and confidential data.

[deleted]

Re: Twitter internal panel linked to account hijackings

#397
post #383

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

This is why IMO Google has almost no customer service. Their weakest attack vector would be people. Imagine paying your infosec employees hundreds of thousands a year to protect your clients data. Next to them (in terms of data access) is your customer service team at $30,000 per head. Which team is easier to crack?

You don't think part of the reason they don't have customer service is that the # of people they'd have to employ is huge?

Re: Twitter internal panel linked to account hijackings

#398

Earlier quoted context omitted.

Make sure that even with a hacked SIM a malicious CSR can't access your account without your knowledge.

Also ensuring that a hacker can get the 2FA token directly from the owner by pretending to be customer service...

Seriously who designed a system that habituates people to giving out 2fa codes over the phone?? That's explicitly a weakness of the 2fa system, nobody should ever read out or forward their 2fa code.

Re: Twitter internal panel linked to account hijackings

#399

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

> Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no technical countermeasures.

Yup. Doubly so for sysadmins, many of which have abhorrent data security practices.

My personal solution is to use cover names, disposable phone numbers, and unique email addresses (the + trick is insufficient) for most services. My assumption is that the data is eventually either going to leak, or be used to threaten or harm me in some way.

If none of the PII overlaps with me, it becomes a lot harder for such an event to affect me.

The only downside is that sometimes you get companies (Airbnb, Instacart, some others) that have CSRs that demand a government photo ID to do certain tasks. Of course I don’t have any documents for these cover names, so usually the workaround is to just abandon that account, make another, and re-place the order or transaction in a way that doesn’t flag it for manual review/intervention.

Works pretty well for me most of the time.

Re: Twitter internal panel linked to account hijackings

#400

To me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisti…

I think there are three possible explanations here: 1- (Tinfoil hats please) This is a state owned attack, which is a retaliation from US Government to ruin Twitter's credibility and introduce social media regulations. 2- The hackers are gray hat hackers, who know that reporting this vulnerability will not make them any money and they want to get what they think they deserve, so they make it public and get some good…

Could also be a #4 that additional data has been exfiltrated that hasn't come to light yet (the DMs of said accounts perhaps?).
Post reply on HN