Earlier quoted context omitted.
Imagine the potential damage if an attacker tweeted something on behalf of the US President (let's say Biden in 2022), that China or Iran or Russia ships could be sunk at any moment if they didn't withdraw (due to some ongoing real incident)... The other side might fire on US ships before the tweet could be corrected. Twitter is a disaster waiting to happen.
Right, because all these other parties would totally not think Twitter might be hacked? I'm truly baffled by this kind of hysteria.
Twitter internal panel linked to account hijackings
421–430 of 477 posts
Re: Twitter internal panel linked to account hijackings
#422> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
> Does anyone know of customer service panels at big companies or government departments where this is the case? I.e., it is literally impossible for a rep to browse random customer information even if they are willing to break the rules? Yes - no names for obvious reasons but where I work (trust me you've heard of them/probably use them and they are a huge tech company) it is very hard to get access to anything even…
Re: Twitter internal panel linked to account hijackings
#423> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
Re: Twitter internal panel linked to account hijackings
#424> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
The problem is that customers don't remember basically anything. I don't know my telephone banking password for any bank. When I call, I get asked to tell them what my last transaction was, or my mother's maiden name and DOB (public info), or what town I last used my card. I've been wrong about the recent usage questions more often than I've been right, and they say "close enough". The technological measures have to…
If you added up all the costs of the people at the lowest extremes (by various metrics), I'd venture to guess that we could increase our prosperity (by various metric) by an order of magnitude.
Example: When I started my startup, we made the decision not to hire any salesperson who wasn't proficient in using a computer (we have no IT support line). We also made the decision to not sell to any customer that couldn't figure out how to use the website (we have no telephone support).
I cannot even tell you how multiplicative the benefits are. The 2% employees who couldn't use a computer or clients who couldn't use the website were responsible for 90% of the issues we had at my prior company. Everything from regulatory complaints, to lawsuits, to ad-hoc report requests, to virus infected PCs, to... the list goes on and on.
Having smart people is great. Not dealing with idiots is equally important.
Re: Twitter internal panel linked to account hijackings
#425Earlier quoted context omitted.
I think there are three possible explanations here: 1- (Tinfoil hats please) This is a state owned attack, which is a retaliation from US Government to ruin Twitter's credibility and introduce social media regulations. 2- The hackers are gray hat hackers, who know that reporting this vulnerability will not make them any money and they want to get what they think they deserve, so they make it public and get some good…
Could also be a #4 that additional data has been exfiltrated that hasn't come to light yet (the DMs of said accounts perhaps?).
Re: Twitter internal panel linked to account hijackings
#426Earlier quoted context omitted.
The problem is that customers don't remember basically anything. I don't know my telephone banking password for any bank. When I call, I get asked to tell them what my last transaction was, or my mother's maiden name and DOB (public info), or what town I last used my card. I've been wrong about the recent usage questions more often than I've been right, and they say "close enough". The technological measures have to…
When I bought my house a couple years ago, I had to put my signature to make a big and urgent money transfer. The bank however didn't accept my signature for some reason, though I had been using it every time with them. It appeared that normally they not really check if it matches, but this time given the transfer amount they did. And it just so happened that the signature they had scanned in their system was the fir…
Because they showed you the signature and let you practice, right?
Re: Twitter internal panel linked to account hijackings
#427The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…
This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…
Re: Twitter internal panel linked to account hijackings
#428> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
The problem is that customers don't remember basically anything. I don't know my telephone banking password for any bank. When I call, I get asked to tell them what my last transaction was, or my mother's maiden name and DOB (public info), or what town I last used my card. I've been wrong about the recent usage questions more often than I've been right, and they say "close enough". The technological measures have to…
I guess one, admittedly brutal, solution is for customers to act like the immune system. Call up, fudge your way through to something that should be protected, and then escalate to a manager and report that you got access to your own account with vague details; they can listen to the call log to verify.
Worst case is that the rep gets fired (which sucks..) but if enough reps get fired then future reps will be hired and trained more diligently.
Re: Twitter internal panel linked to account hijackings
#429> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
Think about your own life: how often do you lose money because an insider hacked your credit accounts and bank accounts? How often do you get pulled over and your car taken away because someone changed the title/tags in DMV records? How often is your identity stolen by an employee at the IRS?
These bad things all happen to some people, of course, but the VAST majority of the time, they do not.
It is obvious that there are effective countermeasures to prevent and mitigate insider threats. Insider threat is not a new concept, and there are well-proven tactics for addressing it.
Re: Twitter internal panel linked to account hijackings
#430Earlier quoted context omitted.
Vaguely plausible excuses will not dissuade prosecutors in possession of contrary evidence.
“I was working remotely at a coffee shop and my computer was swiped while I went to the toilet“ isn’t even plausible given take-out only as well...