Earlier quoted context omitted.
There is no guarantee though, i.e. the system could be well intentioned but if could be bypassed , it does not really protect. The only way to get some assurance is run vendor app in your environment in a secure network without the ability to phone home.
Obviously it can be bypassed in the sense that somebody has full administrator database access. The point about schemes like this is that instead of having to give 1000 support reps full access, you only give a few sysadmins full access. The likelihood of something going wrong with the data (through mistakes, willful abuse, extortion, whatever) goes drastically down. In fact, once you got such a permission system in…
Twitter internal panel linked to account hijackings
411–420 of 477 posts
Re: Twitter internal panel linked to account hijackings
#412Earlier quoted context omitted.
Make sure that even with a hacked SIM a malicious CSR can't access your account without your knowledge.
Also ensuring that a hacker can get the 2FA token directly from the owner by pretending to be customer service...
Re: Twitter internal panel linked to account hijackings
#413> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
I'm fairly sure most banks operate this way. For example, I think they can't even see your account balance until they have entered phone #, mother's maiden name, etc.
Re: Twitter internal panel linked to account hijackings
#414> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
Re: Twitter internal panel linked to account hijackings
#415Earlier quoted context omitted.
> I'd like to see a system where it is physically impossible for a customer service rep to discover any info about me until I authenticate and authorize it. Isn't this the objective of Tim Berners-Lee Solid Project and their Personal Online Data storage (PODs) in the spec? https://solidproject.org
No. POD is about who you share with, not what happens after you share.
Re: Twitter internal panel linked to account hijackings
#416> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
This was a big problem in the early days of online banking (early ‘00s). A fair number bank fraud losses were due to rogue internal employees at call centers creating or changing then selling off online banking passwords. Ran into this when I was with a startup that launched bank to bank email money transfers in Canada around 2001. Banks cleaned up their security pretty quickly though, adding deyailed audit trails fo…
Banks just don’t give support reps remote access to accounts.
Re: Twitter internal panel linked to account hijackings
#417> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
The problem is that customers don't remember basically anything. I don't know my telephone banking password for any bank. When I call, I get asked to tell them what my last transaction was, or my mother's maiden name and DOB (public info), or what town I last used my card. I've been wrong about the recent usage questions more often than I've been right, and they say "close enough". The technological measures have to…
It appeared that normally they not really check if it matches, but this time given the transfer amount they did. And it just so happened that the signature they had scanned in their system was the first one I ever made as a kid (30yrs ago) when I opened the account.
Finally after many retries they turned the monitor to show me the expected signature and let me practice it on a piece of paper, so it would pass some other approval stage.
With a 200 yard line waiting behind me, sweating profusely, I finally managed to reproduce something. The sale went through, luckily, and immediately after I ditched that bank account.
Re: Twitter internal panel linked to account hijackings
#418I wish they had used unique addresses for each tweet they sent out. It would have been fascinating to see which which account had the best conversion rate.
Oh wow that would have bee interesting. My guess would be Elon (or Kanye). I know one person who actually sent money to Elon – "it seemed like something he'd do". Seems likely Elon's followers have the highest rate of people who understand crypto, combined with the fact that he's more likely to do something like this than, say, Joe Biden.
Even worse, I'd say his followers probably have enough understanding of crypto to be able to send him money, but not enough understanding or skepticism to realize it's a scam.
Re: Twitter internal panel linked to account hijackings
#419Earlier quoted context omitted.
Right, because all these other parties would totally not think Twitter might be hacked? I'm truly baffled by this kind of hysteria.
As you say, it would probably not work on foreign governments, but would be very effective on the general population. They could have used that to cause political turmoil (hopefully not enough to change something like elections results?) or influence stock prices etc. This just looks so uninspired...
I can't think of any serious risk posed by 'the general population'. Maybe particular stocks would dip a bit?
Re: Twitter internal panel linked to account hijackings
#420Earlier quoted context omitted.
The rep can perform a password reset and/or change the sms/email pair and then attackers can do the rest and make the posts themselves.
One rep does password resets for scores of high value accounts?