> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right. Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do. So a random customer service rep couldn't access my account without my phone in their hand, even if they managed t…
Twitter internal panel linked to account hijackings
431–440 of 477 posts
Re: Twitter internal panel linked to account hijackings
#432Earlier quoted context omitted.
The problem is that customers don't remember basically anything. I don't know my telephone banking password for any bank. When I call, I get asked to tell them what my last transaction was, or my mother's maiden name and DOB (public info), or what town I last used my card. I've been wrong about the recent usage questions more often than I've been right, and they say "close enough". The technological measures have to…
When I bought my house a couple years ago, I had to put my signature to make a big and urgent money transfer. The bank however didn't accept my signature for some reason, though I had been using it every time with them. It appeared that normally they not really check if it matches, but this time given the transfer amount they did. And it just so happened that the signature they had scanned in their system was the fir…
Re: Twitter internal panel linked to account hijackings
#433Earlier quoted context omitted.
When I bought my house a couple years ago, I had to put my signature to make a big and urgent money transfer. The bank however didn't accept my signature for some reason, though I had been using it every time with them. It appeared that normally they not really check if it matches, but this time given the transfer amount they did. And it just so happened that the signature they had scanned in their system was the fir…
> immediately after I ditched that bank account. Because they showed you the signature and let you practice, right?
Re: Twitter internal panel linked to account hijackings
#434Earlier quoted context omitted.
Some suggested the admin panel can initiate a password reset, and that, coupled with email management would allow account takeover, effectively (without allowing 'tweet as user' functionality).
All the hacked accounts seem to have had the associated email changed. I think the attack goes admin panel -> change email -> reset PW -> tweet bitcoin scams. https://twitter.com/sniko_/status/1283485972286656517
Re: Twitter internal panel linked to account hijackings
#435Earlier quoted context omitted.
You don't think part of the reason they don't have customer service is that the # of people they'd have to employ is huge?
They do have customer service, if you pay for their premium service Google One. They also have support agents for YouTube creators above a certain subscriber threshold.
Every month or two I’d fill in the google support text area explaining the problem. No response for ~4 years. Just this Feb, for whatever reason, I decided to call T-Mobile and report it. Problem was fixed by a higher up tech that described the problem as “very strange” and the “first time” he’d seen something like this. It took approx. an hour.
Upon rumination I full accept that I took the “easy way out” by filling in the text box vs trying to talk to someone. End result is that google lost a gvoice customer and no one calls me anymore. meh
Re: Twitter internal panel linked to account hijackings
#436> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
I'm really surprised that this is the top comment right now because even the most basic back of the envelope check shows that it is wrong. Think about your own life: how often do you lose money because an insider hacked your credit accounts and bank accounts? How often do you get pulled over and your car taken away because someone changed the title/tags in DMV records? How often is your identity stolen by an employee…
Around the same time, at a nearby call center, two employees were caught ordering multiple manager's laptops, which managers can use to access customer records from their home. These laptops were sent out to multiple addresses and never found.
Re: Twitter internal panel linked to account hijackings
#437> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
I have worked on controls in this area for a few US health insurance companies. From what I have seen, it is common to have additional restrictions on accessing high profile individuals and specific groups data. There is also a ton of auditing around this stuff. It is more primitive than what you described, but things are heading in that direction. It is a somewhat harder problem space because many parties need acces…
Re: Twitter internal panel linked to account hijackings
#438Earlier quoted context omitted.
They do have customer service, if you pay for their premium service Google One. They also have support agents for YouTube creators above a certain subscriber threshold.
For reasons I cannot fully remember my voicemail broke many years ago. It goes something like: I’d switched to google voice for vm, where T-Mobile handled my line generally. Then google did something to google voice, some sort of discontinuation + merging with gmail and my vm broke. This occurred in tandem with me moving to a house with terrible cell reception and before wide spread WiFi calling support. The result w…
Re: Twitter internal panel linked to account hijackings
#439Earlier quoted context omitted.
It would be pretty easy. You could just post on reddit or 4chan and ask "If you could make anyone on Twitter post anything, what's the most you could earn?" And people who know a lot about a lot of things would give you ideas. It's just not smart to use the hack for just this. Example: Contact Trump's kids. Demonstrate your power. Tell them you'll make Joe Biden tweet "8 year old girl nude hair" at a time of their ch…
5 million BTC is about US$45 billion.
Re: Twitter internal panel linked to account hijackings
#440FYI for anyone working at Twitter, the legacy JS disabled mobile site still displays the hacked bitcoin tweets. For example try this with JS disabled vs enabled (404): https://mobile.twitter.com/JoeBiden/status/12835123178466590...