Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

451–460 of 477 posts

Re: Twitter internal panel linked to account hijackings

#451
post #438

Earlier quoted context omitted.

The only calls I get any more are recruiters (80%) scammers (15%) and family 5%.

Recruiters call ? I would have expected them to use other more asynchronous methods like text or email, unless you strongly indicate a preference.

At least in the Chicago area, they seem to really prefer to speak on the phone. I'm hard of hearing so phone conversations are challenging at best and despite that, when I've actually been looking for work and talked with recruiters, if they do e-mail it's to ask me to call them. It's seriously annoying. I think a lot of recruiters here have managers who take the view that if they're not on the phone they're not "working."

Re: Twitter internal panel linked to account hijackings

#452

Its pretty amazing that realdonaldtrump@ was not a part of this. I guess the controls on that account are at an even higher level than elon musk/obama.

NYT article says that Trump's account is under special "lock and key" protection.

And that came about because a rogue low-level employee suspended his account.

Re: Twitter internal panel linked to account hijackings

#453

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

there are countermeasures. any competent org (agree with you -- probably not the majority of them) have auditing, so accesses are logged. back in the 90s we had this at my university ... it's an age-old practice. you as user would never know it.

i would bet that most of the places you are thinking about (banks, credit card, and so on) where you get on the phone with a rep, with a phone entry system ahead of the agent, the agent can only access that specific data during the call, the access is logged, and any other access (some other account) is flagged for review. by calling in you are granting access. most users simply don't care about privacy and extra hurdles are just asking for complaints. limiting access to specific accounts during live calls is a fair compromise and a tight control.

xero (they suck, so this is not an endorsement) requires you to give the rep access explicitly, as an option, when requesting tech support. of course i have zero doubt that senior reps can get access anyway (which would be audited), so the explicit control is more about signalling comfort to you about their security measures.

after google had the SRE stalker incident they implemented very tight access controls to user data.

i walked into a verizon store the other day to buy a hotspot. the rep could not get access to any info whatsoever (even billing status) until i acknowledged a message on my phone. it's clear they only had access to my specific data (ie, they don't get to enter any phone number and get access) for that specific interaction.

Re: Twitter internal panel linked to account hijackings

#454

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

* > Every customer service rep that works at any of those places can pull up info on anyone at any time. *

This is simply not true. For example with banks, high-profile accounts can't be accessed by regular tellers. If someone attempts to, it is logged and someone is notified that Teller X tried to access the account.

Now that Twitter is being used for high-profile official communications, they need to re-design their employee control panels to limit, alert, and control what an employee can do with an account.

The fact that important credentials on so many high-profile verified accounts could be changed without notifying employees or locking the affected accounts until the actions are verified is unacceptable.

Re: Twitter internal panel linked to account hijackings

#455

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

* > Every customer service rep that works at any of those places can pull up info on anyone at any time. * This is simply not true. For example with banks, high-profile accounts can't be accessed by regular tellers. If someone attempts to, it is logged and someone is notified that Teller X tried to access the account. Now that Twitter is being used for high-profile official communications, they need to re-design thei…

It shouldn't just be "high profile" accounts. Every person is susceptible to abuse by insiders, so give the same protections to all.

Re: Twitter internal panel linked to account hijackings

#456
post #417
post #395

Earlier quoted context omitted.

The problem is that customers don't remember basically anything. I don't know my telephone banking password for any bank. When I call, I get asked to tell them what my last transaction was, or my mother's maiden name and DOB (public info), or what town I last used my card. I've been wrong about the recent usage questions more often than I've been right, and they say "close enough". The technological measures have to…

When I bought my house a couple years ago, I had to put my signature to make a big and urgent money transfer. The bank however didn't accept my signature for some reason, though I had been using it every time with them. It appeared that normally they not really check if it matches, but this time given the transfer amount they did. And it just so happened that the signature they had scanned in their system was the fir…

This kind of poor security is why we need legislation to make banks responsible for financial damages due to identity theft or fraud. When they will be on the hook for potentially millions of dollars, maybe they will care more about security and offer better protections than a signature

Re: Twitter internal panel linked to account hijackings

#457

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

> Does anyone know of customer service panels at big companies or government departments where this is the case?

E-government services in Estonia have nice features, aimed at giving more control to the owner of the data [1]. Among other: "It allows the Citizen to query who has accessed his/her records. [...] In Estonia, this feature has led to some very public cases of government officials being caught accessing private data of Citizens - without any legitimate and authorized reason for such access."

[1]: https://doi.org/10.1007/s12553-017-0195-1

Re: Twitter internal panel linked to account hijackings

#458
post #124

RE: social engineering, as long as a human is involved somewhere, the system can be compromised. IT security is a very depressing field because of this fact. I also hope these incidents remind people of how little control you really have over your online identity. We're all just IDs in a database somewhere, waiting to be impersonated. Decentralization is the only solution for this IMO.

Often, what people think is "good customer service" really means "allowing me to socially engineer you". I don't think there is any solution to this. "Decentralization" in this context seems equivalent to a centralized system that simply gives up on any ability to recover accounts. Whoever owns the authentication details of an account is the owner, period. If you lose the password or the account gets hacked and stole…

My father recently had an issue getting into his Southwest Airlines account so he called customer service. All he had to do was give them the email address attached to the account, and they read off a temporary password that he entered to get logged in.

As far as I’m aware they didn’t even make him create a new one and he thought everything was totally fine.

It was the moment where I realized I want nothing to do with IT Management/Security in the future and am actively working to distance myself from that aspect.

Re: Twitter internal panel linked to account hijackings

#459
post #395

Earlier quoted context omitted.

The problem is that customers don't remember basically anything. I don't know my telephone banking password for any bank. When I call, I get asked to tell them what my last transaction was, or my mother's maiden name and DOB (public info), or what town I last used my card. I've been wrong about the recent usage questions more often than I've been right, and they say "close enough". The technological measures have to…

This is a more general and larger problem where society is constantly bending over backwards to cater to the 2% lowest performers. If you added up all the costs of the people at the lowest extremes (by various metrics), I'd venture to guess that we could increase our prosperity (by various metric) by an order of magnitude. Example: When I started my startup, we made the decision not to hire any salesperson who wasn't…

> This is a more general and larger problem where society is constantly bending over backwards to cater to the 2% lowest performers.

As your parent said, it's not 2%, it's more like everyone. No one is perfect all the time.

More importantly, it's one thing when hiring, but are you seriously suggesting 2% of the population shouldn't be able to use Twitter or online banking or other online services? 140,000,000 people should effectively face social death because you can't be fucked to help them?

This is backwards, we should be sacrificing profits and convenience to be more inclusive.

Re: Twitter internal panel linked to account hijackings

#460
post #306

Earlier quoted context omitted.

Regarding #1, my thinking was this is China or their allied nations (North Korea, Iran etc). The US has taken extremely forceful steps on China in the last couple of days. This could be their response; discrediting a huge piece of the American crown jewels (big tech companies) and making it a laughing stock. Just the massive blast radius of the hack reminded me of the NK Sony hack and release of documents. Big up you…

I would expect state actors to have gone for a lot more damage than "make Twitter look stupid". Also, all the high-profile state actor hacks I'm aware of were a lot more clandestine - it was months before they were discovered. State actors are highly professional, they're in it for the long haul, and they do serious damage. The "massive blast radius" of this hack lies more in the damage it could have done, rather tha…

Trump wants nothing more than to “win” against perceived competitors.

Remember when Twitter fact checked those Trump tweets?

Trump is the type of petty person to not let something like this go.

Post reply on HN