Earlier quoted context omitted.
The rep can perform a password reset and/or change the sms/email pair and then attackers can do the rest and make the posts themselves.
One rep does password resets for scores of high value accounts?
Twitter internal panel linked to account hijackings
401–410 of 477 posts
Re: Twitter internal panel linked to account hijackings
#402> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
Re: Twitter internal panel linked to account hijackings
#403Earlier quoted context omitted.
This is why IMO Google has almost no customer service. Their weakest attack vector would be people. Imagine paying your infosec employees hundreds of thousands a year to protect your clients data. Next to them (in terms of data access) is your customer service team at $30,000 per head. Which team is easier to crack?
You don't think part of the reason they don't have customer service is that the # of people they'd have to employ is huge?
Re: Twitter internal panel linked to account hijackings
#404> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
This is why IMO Google has almost no customer service. Their weakest attack vector would be people. Imagine paying your infosec employees hundreds of thousands a year to protect your clients data. Next to them (in terms of data access) is your customer service team at $30,000 per head. Which team is easier to crack?
Re: Twitter internal panel linked to account hijackings
#405Earlier quoted context omitted.
Here[0] are the supposed pics of the admin panel the hackers accessed. Assuming their legit, it seems like Twitter has some blacklist features. Can't find any info detailing how they exactly work, but it seems an admin can blacklist a user from the trending page or from search results. Pretty interesting. Oddly enough, posting the screenshots resulted in some users getting their account suspended or Twitter pulling t…
This could end up being a big deal in the days to come if legitimate. Twitter has made strong public statements that they don't have shadow banning tools[0]. Apparently sworn statements have been made about this. [0]: https://blog.twitter.com/en_us/topics/company/2018/Setting-t...
Re: Twitter internal panel linked to account hijackings
#406Earlier quoted context omitted.
Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right. Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do. So a random customer service rep couldn't access my account without my phone in their hand, even if they managed t…
What happens when you forget your code and lose your phone ?
Re: Twitter internal panel linked to account hijackings
#407> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
From what I have seen, it is common to have additional restrictions on accessing high profile individuals and specific groups data. There is also a ton of auditing around this stuff.
It is more primitive than what you described, but things are heading in that direction. It is a somewhat harder problem space because many parties need access to a customer's records in that domain.
Ultimately, the only reason things are even this far along in health insurance is the regulatory environment. It'd be nice to have stronger privacy laws that compel companies to build good controls.
Re: Twitter internal panel linked to account hijackings
#408Why have employees have the ability to do anything with accounts except closing them?
Apparently admins could post only on behalf of bluechecks. I still can't think of a reason why they would need to create posts. Edit maybe, but create? Why? Of course with access to the database anything at all can be done, but this was apparently an explicit feature of the admin dashboard.
Re: Twitter internal panel linked to account hijackings
#409> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
> I'd like to see a system where it is physically impossible for a customer service rep to discover any info about me until I authenticate and authorize it. Isn't this the objective of Tim Berners-Lee Solid Project and their Personal Online Data storage (PODs) in the spec? https://solidproject.org