Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

431–440 of 477 posts

Re: Twitter internal panel linked to account hijackings

#431

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right. Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do. So a random customer service rep couldn't access my account without my phone in their hand, even if they managed t…

I’ve long considered why apps don’t have some VOIP client in them; if one can Face ID into their account, and use the VOIP client to connect to a rep - then the metadata associated with the call can inform the rep you are who you say you are. Seems E* is almost there!

Re: Twitter internal panel linked to account hijackings

#432
post #417
post #395

Earlier quoted context omitted.

The problem is that customers don't remember basically anything. I don't know my telephone banking password for any bank. When I call, I get asked to tell them what my last transaction was, or my mother's maiden name and DOB (public info), or what town I last used my card. I've been wrong about the recent usage questions more often than I've been right, and they say "close enough". The technological measures have to…

When I bought my house a couple years ago, I had to put my signature to make a big and urgent money transfer. The bank however didn't accept my signature for some reason, though I had been using it every time with them. It appeared that normally they not really check if it matches, but this time given the transfer amount they did. And it just so happened that the signature they had scanned in their system was the fir…

It sounds really useless but requiring a signature means a fraudster would have to forge a signature which is a separate, perhaps more easily proven crime that carries extra penalties.

Re: Twitter internal panel linked to account hijackings

#433
post #417

Earlier quoted context omitted.

When I bought my house a couple years ago, I had to put my signature to make a big and urgent money transfer. The bank however didn't accept my signature for some reason, though I had been using it every time with them. It appeared that normally they not really check if it matches, but this time given the transfer amount they did. And it just so happened that the signature they had scanned in their system was the fir…

> immediately after I ditched that bank account. Because they showed you the signature and let you practice, right?

Yup, but also because they could have my evolved adult signature on file, or at least asked me after certain time interval to update it for their records.

Re: Twitter internal panel linked to account hijackings

#434
post #20

Earlier quoted context omitted.

Some suggested the admin panel can initiate a password reset, and that, coupled with email management would allow account takeover, effectively (without allowing 'tweet as user' functionality).

All the hacked accounts seem to have had the associated email changed. I think the attack goes admin panel -> change email -> reset PW -> tweet bitcoin scams. https://twitter.com/sniko_/status/1283485972286656517

Given the number of accounts that were taken over, there must have been many people conducting the hack. Also considering that tweets were being deleted then re-tweeted, others must have been monitoring the tweets. Seems somewhat well coordinated.

Re: Twitter internal panel linked to account hijackings

#435
post #403

Earlier quoted context omitted.

You don't think part of the reason they don't have customer service is that the # of people they'd have to employ is huge?

They do have customer service, if you pay for their premium service Google One. They also have support agents for YouTube creators above a certain subscriber threshold.

For reasons I cannot fully remember my voicemail broke many years ago. It goes something like: I’d switched to google voice for vm, where T-Mobile handled my line generally. Then google did something to google voice, some sort of discontinuation + merging with gmail and my vm broke. This occurred in tandem with me moving to a house with terrible cell reception and before wide spread WiFi calling support. The result was that many folks figured I’d had my number disconnected because calls which couldn’t connect to my phone would get the “disconnected number tone” when being directed to my voicemail box.

Every month or two I’d fill in the google support text area explaining the problem. No response for ~4 years. Just this Feb, for whatever reason, I decided to call T-Mobile and report it. Problem was fixed by a higher up tech that described the problem as “very strange” and the “first time” he’d seen something like this. It took approx. an hour.

Upon rumination I full accept that I took the “easy way out” by filling in the text box vs trying to talk to someone. End result is that google lost a gvoice customer and no one calls me anymore. meh

Re: Twitter internal panel linked to account hijackings

#436

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

I'm really surprised that this is the top comment right now because even the most basic back of the envelope check shows that it is wrong. Think about your own life: how often do you lose money because an insider hacked your credit accounts and bank accounts? How often do you get pulled over and your car taken away because someone changed the title/tags in DMV records? How often is your identity stolen by an employee…

I agree with most of your post, but the parent comment is not wrong about customer service panels being accessible by employees. A friend of mine worked at a call center for a major us phone provider, the only thing stopping employees from accessing customer records is a point based penalty system for infractions. While my friend worked there, one employee was caught accessing customer records and was never fired or anything and continued to do shady things until quitting. It was discovered he'd worked at multiple call centers before and did the same thing.

Around the same time, at a nearby call center, two employees were caught ordering multiple manager's laptops, which managers can use to access customer records from their home. These laptops were sent out to multiple addresses and never found.

Re: Twitter internal panel linked to account hijackings

#437

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

I have worked on controls in this area for a few US health insurance companies. From what I have seen, it is common to have additional restrictions on accessing high profile individuals and specific groups data. There is also a ton of auditing around this stuff. It is more primitive than what you described, but things are heading in that direction. It is a somewhat harder problem space because many parties need acces…

I worked for a healthcare claims processing company that at the time stored all the production database and server passwords in a text file accessible to half the company, all because the chief architect didn't want to remember passwords. Yet we were covered by HIPPA and "passed our audits". If people don't care to follow the law and can manipulate the audit, who is going to stop them?

Re: Twitter internal panel linked to account hijackings

#438
post #435
post #403

Earlier quoted context omitted.

They do have customer service, if you pay for their premium service Google One. They also have support agents for YouTube creators above a certain subscriber threshold.

For reasons I cannot fully remember my voicemail broke many years ago. It goes something like: I’d switched to google voice for vm, where T-Mobile handled my line generally. Then google did something to google voice, some sort of discontinuation + merging with gmail and my vm broke. This occurred in tandem with me moving to a house with terrible cell reception and before wide spread WiFi calling support. The result w…

The only calls I get any more are recruiters (80%) scammers (15%) and family 5%.

Re: Twitter internal panel linked to account hijackings

#439

Earlier quoted context omitted.

It would be pretty easy. You could just post on reddit or 4chan and ask "If you could make anyone on Twitter post anything, what's the most you could earn?" And people who know a lot about a lot of things would give you ideas. It's just not smart to use the hack for just this. Example: Contact Trump's kids. Demonstrate your power. Tell them you'll make Joe Biden tweet "8 year old girl nude hair" at a time of their ch…

5 million BTC is about US$45 billion.

He probably meant $5 million USD in BTC.

Re: Twitter internal panel linked to account hijackings

#440
post #90

FYI for anyone working at Twitter, the legacy JS disabled mobile site still displays the hacked bitcoin tweets. For example try this with JS disabled vs enabled (404): https://mobile.twitter.com/JoeBiden/status/12835123178466590...

I’ve been checking periodically and they finally removed the data from this vector. It was up for at least 12 hours longer than the rest of the site.
Post reply on HN