Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

101–110 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#101

I don’t really think he should be naming who his unnamed sources “think” is behind an attack on this scale, especially with full name, city of origin, Instagram, suggested current location, age, etc. It feels a very, very small step away from doxxing to me. Added to which he has somebody in the comments essentially calling for the death penalty over this. If he has this personal information and evidence, pass it to t…

> It feels a very, very small step away from doxxing to me. What small step is that? Looks like a textbook case of doxxing to me.

This isn't his first time doing it, either.

https://itwire.com/security/infosec-researchers-slam-ex-wapo...

Re: Who’s behind Wednesday’s epic Twitter hack?

#102

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

What you call value is really speculations. There is really no association between the value generated by corporations and what the traders think they'll make off trading its stock.

Re: Who’s behind Wednesday’s epic Twitter hack?

#103
post #43

Earlier quoted context omitted.

A solution as simple as just hiring someone for $10/hour to periodically scan youtube for crypto keywords and disable the scam videos and accounts would have prevented millions of dollars of theft.

What are examples of keywords that would have a low false positive (and ideally, low false negative) rate, such that a minimum wage worker could efficiently disable videos with little context or time?

> "What are examples of keywords that would have a low false positive"

"Bitcoin"

Re: Who’s behind Wednesday’s epic Twitter hack?

#104
post #43

Earlier quoted context omitted.

What are examples of keywords that would have a low false positive (and ideally, low false negative) rate, such that a minimum wage worker could efficiently disable videos with little context or time?

it is not the keywords but the content of the videos. anything that involves a livestream and a pitch to send X to get 2x-10x back. very easy to train someone to identify what these scam look like with zero low false positive rate

Why would you need a human to do a job that a computer can do 100x faster?

Re: Who’s behind Wednesday’s epic Twitter hack?

#105
post #48

It will be interesting to see how the access was gained. I wonder how well this administrative system was protected. Did they have basic controls like: 1) Accessible via corporate VPN only (requiring 2fa) 2) Admin panel protected by 2fa plus necessary authentication+authorization controls 3) Audit trails Short of cooperative access (device handover), I could only see an outsider gaining access to the system due to po…

With everyone working from home due to the pandemic I think these admin tools have never been more vulnerable. I would bet these tools were unavailable outside of a twitter office building until now.

But now these tools are accessible from the homes of twitter admins. How many of them are running behind compromised home routers, etc? Everyone in the house has access - spouses, partners, teens, visitors.

I bet twitter doesn't have a lot of extra security on their admin tools. They probably write straight to the production database. Those safeguards would really slow down day to day support and be expensive to build, and they probably assumed the physical security of the office building was good enough.

I think the most like cause was a disgruntled employee working from home plus a little bribery.

Re: Who’s behind Wednesday’s epic Twitter hack?

#106
post #75

Earlier quoted context omitted.

I've been seeing similar scams in Elon's replies, they just copy his profile picture and name and reply with a different account. You might have seen that one

I am used to spotting cryptocurrency scams. The tweet I saw was from his official account, days before the "Wednesday hack".

Elon Musk's account getting hacked or promoting a cryptocurrency scam would have made news immediately, so I think you are mistaken.

Re: Who’s behind Wednesday’s epic Twitter hack?

#107
post #86
post #73

Earlier quoted context omitted.

Neither Obama nor Biden nor Bloomberg are "active government officials". They have no power to conduct U.S. government business, thus an intrusion on their private social media accounts is not going to be an obvious or immediate threat to the security of the U.S. government.

Former presidents are still privy to a lot of information (e.g. they receive national security briefings still). Hacking their technology accounts is absolutely a threat to the security of the US govt, and is one reason the Secret Service specifically monitors their technology usage. I'd bet a lot of money the inclusion of people like Obama and Biden all but guaranteed the FBI/NSA get involved now, or at the very lea…

It's not just about access to information, but actual power and perceived power; the chances that the average rational person will be fooled and react to "The U.S. Treasury has been ordered to fast-track the evaluation and adoption of Bitcoin as an option for official government transactions" is much higher coming from Trump, Pence, Mnuchin, McConnell, or any number of the official social media accounts of U.S. agencies than it is for Obama or Biden. Sure, the latter could most definitely fool people, but that's possible with any famous account, like Elon Musk's or Kanye's.

Re: Who’s behind Wednesday’s epic Twitter hack?

#108
post #61
post #48

It will be interesting to see how the access was gained. I wonder how well this administrative system was protected. Did they have basic controls like: 1) Accessible via corporate VPN only (requiring 2fa) 2) Admin panel protected by 2fa plus necessary authentication+authorization controls 3) Audit trails Short of cooperative access (device handover), I could only see an outsider gaining access to the system due to po…

Many startups and hip companies don't do VPNs anymore - unfortunately they also dont do Zero Trust (which would require machine certs for everything and be enforced) - so stuff is often available over Internet with password auth + maybe MFA. Attacker who gets hold of cookie or bearer token wins. And the best part, support personnel often doesnt have MFA, because its outsourced to countries where smart phones with Aut…

To be honest VPN's are a huge pain in the arse for everybody involved.

Re: Who’s behind Wednesday’s epic Twitter hack?

#109
post #87
post #61

Earlier quoted context omitted.

Many startups and hip companies don't do VPNs anymore - unfortunately they also dont do Zero Trust (which would require machine certs for everything and be enforced) - so stuff is often available over Internet with password auth + maybe MFA. Attacker who gets hold of cookie or bearer token wins. And the best part, support personnel often doesnt have MFA, because its outsourced to countries where smart phones with Aut…

I don't see any issue with auth without VPN if TLS is terminated by owner

The better answer/question is maybe more about what kind of auth?

Re: Who’s behind Wednesday’s epic Twitter hack?

#110
post #84

Earlier quoted context omitted.

see this, from earlier: https://news.ycombinator.com/item?id=23860584 "No, you couldn't have made more money than the Twitter hacker" https://fortenf.org/e/security/2020/07/15/twitter-hack.html

I don't buy the stock market argument. People open short positions worth more than $100K every day, especially against companies like Tesla. There would be nothing suspicious about a few such trades. But really, my point is that pulling off a sophisticated exploit involving major celebrities, politicians and CEOs, social engineering/bribery, internal access at a top company etc. doesn't really seem worth the risk if…

You need a substantial amount of capital to make the short position more profitable than $100k to begin with.
Post reply on HN