Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

61–70 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#61
post #48

It will be interesting to see how the access was gained. I wonder how well this administrative system was protected. Did they have basic controls like: 1) Accessible via corporate VPN only (requiring 2fa) 2) Admin panel protected by 2fa plus necessary authentication+authorization controls 3) Audit trails Short of cooperative access (device handover), I could only see an outsider gaining access to the system due to po…

Many startups and hip companies don't do VPNs anymore - unfortunately they also dont do Zero Trust (which would require machine certs for everything and be enforced) - so stuff is often available over Internet with password auth + maybe MFA. Attacker who gets hold of cookie or bearer token wins.

And the best part, support personnel often doesnt have MFA, because its outsourced to countries where smart phones with Authenticator apps are not as common to own for the regular person. I'm not joking.

Re: Who’s behind Wednesday’s epic Twitter hack?

#62
post #58

It's bizarre to me that someone pulled off an account takeover of this magnitude and the end result was random people being scammed out of ~$100K in Bitcoin (that too allegedly). A single well-crafted Tweet from one of these accounts is probably worth more. Heck Twitter would have paid that much or more just in bug bounties for reporting this.

see this, from earlier:

https://news.ycombinator.com/item?id=23860584

"No, you couldn't have made more money than the Twitter hacker" https://fortenf.org/e/security/2020/07/15/twitter-hack.html

Re: Who’s behind Wednesday’s epic Twitter hack?

#63

This is the most important point: > Also, it seems clear that this Twitter hack could have let the attackers view the direct messages of anyone on Twitter, information that is difficult to put a price on but which nevertheless would be of great interest to a variety of parties, from nation states to corporate spies and blackmailers. My understanding is the hackers used the admin panel to change the email addresses of…

Not 100% positive on this, but I believe the admin panel allowed to remove 2FA as well.

Re: Who’s behind Wednesday’s epic Twitter hack?

#64

It's not a hack when an employee holds the door open and gives use of an admin management tool to a third party. Likewise, it's not a bitcoin scam when bitcoin is the method of transfer, just like it's not a US-dollar scam every other time dollars are used in theft.

To use your analogy, it literally is still burglary when an employee holds the door open to the office for you to enter and steal things. The attackers took over accounts by technical means. This is a perfectly reasonable usage of “hack.”

Re: Who’s behind Wednesday’s epic Twitter hack?

#65

man who falls for this stuff. i've been seeing "send me money to this account to get double that" scam for like 20 years, its hard to believe there are people who still don't know better.

I wonder if a lot of people sent test amounts to see if it worked or not. 5000 people sending $10 adds up fast.

Re: Who’s behind Wednesday’s epic Twitter hack?

#66

It's not a hack when an employee holds the door open and gives use of an admin management tool to a third party. Likewise, it's not a bitcoin scam when bitcoin is the method of transfer, just like it's not a US-dollar scam every other time dollars are used in theft.

Is bribery not considered a viable form of social engineering?

No, the term (as used in the context of information security) implies deceiving/manipulating people.

Re: Who’s behind Wednesday’s epic Twitter hack?

#68

This is the most important point: > Also, it seems clear that this Twitter hack could have let the attackers view the direct messages of anyone on Twitter, information that is difficult to put a price on but which nevertheless would be of great interest to a variety of parties, from nation states to corporate spies and blackmailers. My understanding is the hackers used the admin panel to change the email addresses of…

>> Also, it seems clear that this Twitter hack could have let the attackers view the direct messages of anyone on Twitter, information that is difficult to put a price on but which nevertheless would be of great interest to a variety of parties, from nation states to corporate spies and blackmailers.

It is not as much money as pundits probably think it is worth. And also, trying to negotiate a blackmail is time consuming and opens the risk of being caught especially if it a high profile target, with no guarantee of being paid. Do you really think someone like elon musk will pay a bitcoin ransom assuming there is anything incriminating? Paying off a blackmailer is an admission of guilt and does no good if the info is released anyway.

It also depends on how sophisticated the thief was. Did he have everything automated to dump anything everything from the inboxes while automating the posting of the spam tweets, or was he frantically doing all his postings by hand before twitter could shut it down. If the thief is not sophisticated his main priority would probably be making as much money as possible with the posts and ignore the private messages

Re: Who’s behind Wednesday’s epic Twitter hack?

#69
I think people are still severely under-estimating how dangerous this was.

Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value:

Archive: http://archive.is/8lCMV

https://www.washingtonpost.com/news/worldviews/wp/2013/04/23...

This twitter hack could have literally destroyed economies, started a war, potential for black mailing politicians and others etc.

This really needs to be looked at with much bigger eyes. This wasn't just a bitcoin scam.

Re: Who’s behind Wednesday’s epic Twitter hack?

#70
post #28

It's not a hack when an employee holds the door open and gives use of an admin management tool to a third party. Likewise, it's not a bitcoin scam when bitcoin is the method of transfer, just like it's not a US-dollar scam every other time dollars are used in theft.

We have devalued the term hacking to the point were just opening cmd on windows is "hacking" now

Funny because that's exactly what the original definition of the term is, before it started being used purely for infosec.
Post reply on HN