Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

121–130 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#121
post #45

Krebs should get someone half as good at html and CSS as he is in security to update his awful site. Doesnt even work in Firefox reader.

Maybe Firefox should get someone half as good as Chrome developers, because the reader mode works on his site fine there.

Works fine in FF reader mode too.

Re: Who’s behind Wednesday’s epic Twitter hack?

#122
post #48

It will be interesting to see how the access was gained. I wonder how well this administrative system was protected. Did they have basic controls like: 1) Accessible via corporate VPN only (requiring 2fa) 2) Admin panel protected by 2fa plus necessary authentication+authorization controls 3) Audit trails Short of cooperative access (device handover), I could only see an outsider gaining access to the system due to po…

With everyone working from home due to the pandemic I think these admin tools have never been more vulnerable. I would bet these tools were unavailable outside of a twitter office building until now. But now these tools are accessible from the homes of twitter admins. How many of them are running behind compromised home routers, etc? Everyone in the house has access - spouses, partners, teens, visitors. I bet twitter…

Yes, given increased working from home I'd expect more breaches to come. Especially if companies allow non-corporate machines to connect to their VPNs (or other once internal systems are on the open internet). Putting an admin tool on the internet places a lot of trust on your users and developers to be perfect. That also assumes any 3rd party dependencies are free of issues.

Putting VPN and MFA on shouldn't slow down people much. They'd just have to spend a bit more time logging in each day. Annoying? Yes, but that's better than a breach.

Re: Who’s behind Wednesday’s epic Twitter hack?

#123

Earlier quoted context omitted.

It's almost as if web services that let people post whatever they want at any time, vulnerable to whatever security flaws may be present, shouldn't be used as a reliable source for up-to-the-minute information about literally anything important at all.

This. We've entered a world where the lowest common denominator of information is being used as primary source for current events. That's asinine.

But is that really new? Other than scale and reach (quantitative difference), how is that any different qualitatively from the old grapevine/gossip network? "My dad's co-worker's, girlfriend's uncle works at ... and said..."

Re: Who’s behind Wednesday’s epic Twitter hack?

#124
post #77

Earlier quoted context omitted.

What about Reps. Nancy Pelosi or AOC, both of whom are extremely visible and active politicians, and who draw similar kinds of ire as Obama/Biden?

They're active in the Politics game...

So is Kanye West and Taylor Swift, who, like Obama, can do things like work full time as a registered lobbyist, and not have to publicly disclose financial investments or otherwise ever publicly respond to the public, and many other things that regular citizens are allowed to do.

Re: Who’s behind Wednesday’s epic Twitter hack?

#125
post #67

Is it generally known that this hack was live for at least a few days, not just Wednesday? I personally saw one of the official @elonmusk scam tweets earlier this week.

The tweets didn't come from his handle. They were using the same image and name but what really caught my attention was that those accounts had a blue verified badge.

Re: Who’s behind Wednesday’s epic Twitter hack?

#126

This is the most important point: > Also, it seems clear that this Twitter hack could have let the attackers view the direct messages of anyone on Twitter, information that is difficult to put a price on but which nevertheless would be of great interest to a variety of parties, from nation states to corporate spies and blackmailers. My understanding is the hackers used the admin panel to change the email addresses of…

>> Also, it seems clear that this Twitter hack could have let the attackers view the direct messages of anyone on Twitter, information that is difficult to put a price on but which nevertheless would be of great interest to a variety of parties, from nation states to corporate spies and blackmailers. It is not as much money as pundits probably think it is worth. And also, trying to negotiate a blackmail is time consu…

> Do you really think someone like elon musk will pay a bitcoin ransom

A somewhat odd blog post by Jeff Bezos about blackmail from last year is quite interesting in this context. [1]

[1] https://medium.com/@jeffreypbezos/no-thank-you-mr-pecker-146...

Re: Who’s behind Wednesday’s epic Twitter hack?

#127

Why would the hackers gain this level of access, and do something that nets them so little money(relative to the amount they could have gained), when they can't even spend without having law enforcement outside their door?

You are assuming the kids doing this don’t think just getting 100k is a lot of money. They most likely originally got the backdoor solely to get original usernames and someone had the idea “we could phish bitcoin with this”. I doubt they went into it with a big plan

Re: Who’s behind Wednesday’s epic Twitter hack?

#128

This is the most important point: > Also, it seems clear that this Twitter hack could have let the attackers view the direct messages of anyone on Twitter, information that is difficult to put a price on but which nevertheless would be of great interest to a variety of parties, from nation states to corporate spies and blackmailers. My understanding is the hackers used the admin panel to change the email addresses of…

Not 100% positive on this, but I believe the admin panel allowed to remove 2FA as well.

Yep or else none of this could happen. I work at a company that we need at least two methods to authenticate you to remove MFA through the admin console so this wouldn’t have happened.

Re: Who’s behind Wednesday’s epic Twitter hack?

#129
post #58

It's bizarre to me that someone pulled off an account takeover of this magnitude and the end result was random people being scammed out of ~$100K in Bitcoin (that too allegedly). A single well-crafted Tweet from one of these accounts is probably worth more. Heck Twitter would have paid that much or more just in bug bounties for reporting this.

There's no bug bounty for "get an employee to reset an account for you."

"You can update the email address of any Twitter user, [...] without sending any kind of notification to the user" sounds like a bug, but if your repro starts with "get access to the internal dashboard" it'll get rejected out of hand.

Re: Who’s behind Wednesday’s epic Twitter hack?

#130
post #84

Earlier quoted context omitted.

see this, from earlier: https://news.ycombinator.com/item?id=23860584 "No, you couldn't have made more money than the Twitter hacker" https://fortenf.org/e/security/2020/07/15/twitter-hack.html

I don't buy the stock market argument. People open short positions worth more than $100K every day, especially against companies like Tesla. There would be nothing suspicious about a few such trades. But really, my point is that pulling off a sophisticated exploit involving major celebrities, politicians and CEOs, social engineering/bribery, internal access at a top company etc. doesn't really seem worth the risk if…

But you can't make those trades anonymously. So everyone who even remotely profited from the stock movement gets put on the suspect list, and the FBI just went from needing to investigate literally anyone to maybe a few hundred people at most. The FBI is more than capable of going through a list like that and narrowing it down quickly.
Post reply on HN