Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

411–420 of 477 posts

Re: Twitter internal panel linked to account hijackings

#411

Earlier quoted context omitted.

There is no guarantee though, i.e. the system could be well intentioned but if could be bypassed , it does not really protect. The only way to get some assurance is run vendor app in your environment in a secure network without the ability to phone home.

Obviously it can be bypassed in the sense that somebody has full administrator database access. The point about schemes like this is that instead of having to give 1000 support reps full access, you only give a few sysadmins full access. The likelihood of something going wrong with the data (through mistakes, willful abuse, extortion, whatever) goes drastically down. In fact, once you got such a permission system in…

That's a very 90s view. The modern view is that only robots are sysadmins, and those robots are indirectly controlled. Some humans have superpowers in some systems, but not in the whole system.

Re: Twitter internal panel linked to account hijackings

#412

Earlier quoted context omitted.

Make sure that even with a hacked SIM a malicious CSR can't access your account without your knowledge.

Also ensuring that a hacker can get the 2FA token directly from the owner by pretending to be customer service...

In this case it sounds like the user is calling ETrade, so unless the user calls a wrong number that just so happens to be a hacker it's unlikely this would be an issue.

Re: Twitter internal panel linked to account hijackings

#413

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

I'm fairly sure most banks operate this way. For example, I think they can't even see your account balance until they have entered phone #, mother's maiden name, etc.

So anyone who gets access to your Facebook profile can see all your bank data.

Re: Twitter internal panel linked to account hijackings

#414

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

This was a big problem in the early days of online banking (early ‘00s). A fair number bank fraud losses were due to rogue internal employees at call centers creating or changing then selling off online banking passwords. Ran into this when I was with a startup that launched bank to bank email money transfers in Canada around 2001. Banks cleaned up their security pretty quickly though, adding deyailed audit trails for one, and variety of other security controls around their own employee access (like double sign-offs). There is a general principle that banks have understood for as long as there have been banks... not all threat actors are outside threat actors.

Re: Twitter internal panel linked to account hijackings

#415
post #409
post #243

Earlier quoted context omitted.

> I'd like to see a system where it is physically impossible for a customer service rep to discover any info about me until I authenticate and authorize it. Isn't this the objective of Tim Berners-Lee Solid Project and their Personal Online Data storage (PODs) in the spec? https://solidproject.org

No. POD is about who you share with, not what happens after you share.

Thought it was who you share what with, so including the auth/authz as parent asked. After sharing happened all bets are off.

Re: Twitter internal panel linked to account hijackings

#416

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

This was a big problem in the early days of online banking (early ‘00s). A fair number bank fraud losses were due to rogue internal employees at call centers creating or changing then selling off online banking passwords. Ran into this when I was with a startup that launched bank to bank email money transfers in Canada around 2001. Banks cleaned up their security pretty quickly though, adding deyailed audit trails fo…

In this case I suspect that there is an audit trail. It will lead to a Twitter insider who was “working from home” and had remote access to the tool, but had already left the country.

Banks just don’t give support reps remote access to accounts.

Re: Twitter internal panel linked to account hijackings

#417
post #395

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

The problem is that customers don't remember basically anything. I don't know my telephone banking password for any bank. When I call, I get asked to tell them what my last transaction was, or my mother's maiden name and DOB (public info), or what town I last used my card. I've been wrong about the recent usage questions more often than I've been right, and they say "close enough". The technological measures have to…

When I bought my house a couple years ago, I had to put my signature to make a big and urgent money transfer. The bank however didn't accept my signature for some reason, though I had been using it every time with them.

It appeared that normally they not really check if it matches, but this time given the transfer amount they did. And it just so happened that the signature they had scanned in their system was the first one I ever made as a kid (30yrs ago) when I opened the account.

Finally after many retries they turned the monitor to show me the expected signature and let me practice it on a piece of paper, so it would pass some other approval stage.

With a 200 yard line waiting behind me, sweating profusely, I finally managed to reproduce something. The sale went through, luckily, and immediately after I ditched that bank account.

Re: Twitter internal panel linked to account hijackings

#418

I wish they had used unique addresses for each tweet they sent out. It would have been fascinating to see which which account had the best conversion rate.

Oh wow that would have bee interesting. My guess would be Elon (or Kanye). I know one person who actually sent money to Elon – "it seemed like something he'd do". Seems likely Elon's followers have the highest rate of people who understand crypto, combined with the fact that he's more likely to do something like this than, say, Joe Biden.

> Seems likely Elon's followers have the highest rate of people who understand crypto

Even worse, I'd say his followers probably have enough understanding of crypto to be able to send him money, but not enough understanding or skepticism to realize it's a scam.

Re: Twitter internal panel linked to account hijackings

#419
post #393
post #376

Earlier quoted context omitted.

Right, because all these other parties would totally not think Twitter might be hacked? I'm truly baffled by this kind of hysteria.

As you say, it would probably not work on foreign governments, but would be very effective on the general population. They could have used that to cause political turmoil (hopefully not enough to change something like elections results?) or influence stock prices etc. This just looks so uninspired...

> As you say, it would probably not work on foreign governments, but would be very effective on the general population

I can't think of any serious risk posed by 'the general population'. Maybe particular stocks would dip a bit?

Re: Twitter internal panel linked to account hijackings

#420

Earlier quoted context omitted.

The rep can perform a password reset and/or change the sms/email pair and then attackers can do the rest and make the posts themselves.

One rep does password resets for scores of high value accounts?

Before this incident, protections against that were probably "a good idea at some point, but not near the top of the backlog right now"
Post reply on HN