Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

41–50 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#41
post #25

Earlier quoted context omitted.

https://cointelegraph.com/news/fake-spacex-youtube-channels-... The first one I saw was a Rip of a SpaceX livestream. I watched it for a bit then noticed all the BitCoin references and got confused then realized it was a scam account. How they get promoted basically to the front page is the issue.

A solution as simple as just hiring someone for $10/hour to periodically scan youtube for crypto keywords and disable the scam videos and accounts would have prevented millions of dollars of theft.

I think this is a good solution, but maybe not viable. Going past Crypto this could apply to so many issues needed to be reviewed on YouTube. But at that scale, the human cost is something YouTube refuses to pay.

Re: Who’s behind Wednesday’s epic Twitter hack?

#42

man who falls for this stuff. i've been seeing "send me money to this account to get double that" scam for like 20 years, its hard to believe there are people who still don't know better.

Consider this: i'd argue that the fundamental feature of twitter isn't tweets. It is the underlying certainty that the tweeted content belongs to the person with the blue checkmark. My friends in social media positions heard about the twitter hack from me, not the other way around. Given how this info disseminated, combined with the breaking of twitters fundamental feature, i'm surprised more people didn't fall for t…

makes me wonder why they did the scam in the afternoon PST when everyone is at work. why not wait until midnight. bitcoin is as popular overseas as in america.

Re: Who’s behind Wednesday’s epic Twitter hack?

#43
post #25

Earlier quoted context omitted.

https://cointelegraph.com/news/fake-spacex-youtube-channels-... The first one I saw was a Rip of a SpaceX livestream. I watched it for a bit then noticed all the BitCoin references and got confused then realized it was a scam account. How they get promoted basically to the front page is the issue.

A solution as simple as just hiring someone for $10/hour to periodically scan youtube for crypto keywords and disable the scam videos and accounts would have prevented millions of dollars of theft.

What are examples of keywords that would have a low false positive (and ideally, low false negative) rate, such that a minimum wage worker could efficiently disable videos with little context or time?

Re: Who’s behind Wednesday’s epic Twitter hack?

#44

man who falls for this stuff. i've been seeing "send me money to this account to get double that" scam for like 20 years, its hard to believe there are people who still don't know better.

The trick is the scale at which you teach people. You only need a few people who are new to Bitcoin and stupid, intoxicated or otherwise not at their best in that moment and you made a profit that's significant in many countries. If you reach 100k+ people your odds should be good.

Re: Who’s behind Wednesday’s epic Twitter hack?

#46
post #27

While it may sound ridiculous that anyone would be fooled into sending bitcoin in response to these tweets, an analysis of the BTC wallet promoted by many of the hacked Twitter profiles shows that on July 15 the account processed 383 transactions and received almost 13 bitcoin on July 15 — or approximately USD $117,000. This could be mostly the attackers’ own money. It’s impossible to tell, but I haven’t seen anyone…

What would they gain by doing that?

Social proof. People would see others donating and assume it was indeed legit.

Re: Who’s behind Wednesday’s epic Twitter hack?

#47
post #43

Earlier quoted context omitted.

A solution as simple as just hiring someone for $10/hour to periodically scan youtube for crypto keywords and disable the scam videos and accounts would have prevented millions of dollars of theft.

What are examples of keywords that would have a low false positive (and ideally, low false negative) rate, such that a minimum wage worker could efficiently disable videos with little context or time?

it is not the keywords but the content of the videos. anything that involves a livestream and a pitch to send X to get 2x-10x back. very easy to train someone to identify what these scam look like with zero low false positive rate

Re: Who’s behind Wednesday’s epic Twitter hack?

#48
It will be interesting to see how the access was gained. I wonder how well this administrative system was protected. Did they have basic controls like:

1) Accessible via corporate VPN only (requiring 2fa)

2) Admin panel protected by 2fa plus necessary authentication+authorization controls

3) Audit trails

Short of cooperative access (device handover), I could only see an outsider gaining access to the system due to poor security practices or a remote access trojan getting installed. Though more likely, Twitter lacked these basic controls.

Verified accounts could probably be subject to 2nd person controls so IF someone were to modify an account via admin panel, then a 2nd support person (preferably in a different location), would have to vet the change.

Re: Who’s behind Wednesday’s epic Twitter hack?

#49

Earlier quoted context omitted.

A solution as simple as just hiring someone for $10/hour to periodically scan youtube for crypto keywords and disable the scam videos and accounts would have prevented millions of dollars of theft.

I think this is a good solution, but maybe not viable. Going past Crypto this could apply to so many issues needed to be reviewed on YouTube. But at that scale, the human cost is something YouTube refuses to pay.

it would be a stopgap measure until the algos are refined to filter out the videos without the need for human intervention. YouTube is being sued by Brad Garlinghouse for not taking action fast enough. My guess is my $10/hour solution is cheaper than $1000/hour lawyers.

Re: Who’s behind Wednesday’s epic Twitter hack?

#50
post #37

> “This is NOT a method, you will be given a full refund if for any reason you aren’t given the email/@, however if it is revered/suspended I will not be held accountable,” Chaewon wrote in their sales thread, which was titled “Pulling email for any Twitter/Taking Requests.” If access were being sold via message board, I wonder if the thread contains stipulations on which accounts are off-limits for being hacked. My…

You don't think that hacking biden and obama will do that too?
Post reply on HN