Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

151–160 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#151
post #133

Earlier quoted context omitted.

It's almost as if web services that let people post whatever they want at any time, vulnerable to whatever security flaws may be present, shouldn't be used as a reliable source for up-to-the-minute information about literally anything important at all.

The same could be said for radio, whether Orson Wells "Alien Invasion" broadcast or the multitude of April 1st jokes that got out of hand.

tl;dr don't rely on a single source

Re: Who’s behind Wednesday’s epic Twitter hack?

#152
post #75

Earlier quoted context omitted.

I am used to spotting cryptocurrency scams. The tweet I saw was from his official account, days before the "Wednesday hack".

I don't think that's been reported anywhere, could you link to an archive or something?

I couldn't find any screenshots, archive.org link, or browser history for the tweet I saw. So, unfortunately I have no evidence that the scam tweets started before Wednesday. We'll see what Twitter finds.

Re: Who’s behind Wednesday’s epic Twitter hack?

#153

I don’t really think he should be naming who his unnamed sources “think” is behind an attack on this scale, especially with full name, city of origin, Instagram, suggested current location, age, etc. It feels a very, very small step away from doxxing to me. Added to which he has somebody in the comments essentially calling for the death penalty over this. If he has this personal information and evidence, pass it to t…

It's doxxing. My question is why is that a bad thing in this case? Zero tolerance policies don't make any sense to me.

On the off-chance that you're serious - doxxing someone who is suspected to be linked to a crime is staggeringly irresponsible, because you are then effectively convicting them in the court of public opinion. If they are innocent, but you have not only levelled accusations at them, but provided ways to access them, then you are partially responsible for what others choose to do with that information.

Re: Who’s behind Wednesday’s epic Twitter hack?

#154

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

Yes it was dangerous, but nothing is “erased” if that market valuation is restored a few minutes later

For a market to move, people need to buy and sell. So while value might not be erased on a global scale if the market recovers to the original position, lots of people will lose (and gain) large amounts of money.

Re: Who’s behind Wednesday’s epic Twitter hack?

#155

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

It's almost as if web services that let people post whatever they want at any time, vulnerable to whatever security flaws may be present, shouldn't be used as a reliable source for up-to-the-minute information about literally anything important at all.

It shouldn't be, but the bleeding edge of markets have always relied on having the latest data from anywhere that can indicate a shift and I don't expect it to change anytime soon.

Re: Who’s behind Wednesday’s epic Twitter hack?

#156
post #5

Earlier quoted context omitted.

You'd have to be a special kind of stupid to "un-wash" your own bitcoins this way.

Possibly. The only reason this would be stupid is because Bitcoin has rapidly been centralizing. I suspect many exchanges might start blacklisting any wallet that has any transactions from this wallet. On the other hand, they can’t really do that. At that point the attackers would be able to poison any wallet just by sending a small amount of BTC to it. Therefore it seems like the only penalty is that they’d have to…

Random, totally not thought all the way through, idea. Could a decentralized nullifier be put in the blockchain? Allow the consensus algorithm to "vote" for when an address should be marked as invalid and miners would reject transactions with it. It would work by someone submitting an "anti-coin" transaction and wagering their own coin. Miners would provide PoW to confirm the transaction but instead of the miners collecting a reward they pay a fraction of the initial wager. Once enough blocks with a confirmation of the anti-coin are mined to pay back the wager it's accepted as permanent. Now the only way to use that address would be to fork the blockchain. On the other hand, if the anti-coin is not accepted the submitter loses their wager, so it becomes expensive to attempt to destroy coins without cause.

But I don't know nearly enough crypto to even guess at whether or not this is a really stupid idea. Don't torch me for being foolish.

Re: Who’s behind Wednesday’s epic Twitter hack?

#157
post #133

Earlier quoted context omitted.

It's almost as if web services that let people post whatever they want at any time, vulnerable to whatever security flaws may be present, shouldn't be used as a reliable source for up-to-the-minute information about literally anything important at all.

The same could be said for radio, whether Orson Wells "Alien Invasion" broadcast or the multitude of April 1st jokes that got out of hand.

> The same could be said for radio

Yes, except the FCC can forcefully suspend the operations of a radio station.

Re: Who’s behind Wednesday’s epic Twitter hack?

#158
post #133

Earlier quoted context omitted.

It's almost as if web services that let people post whatever they want at any time, vulnerable to whatever security flaws may be present, shouldn't be used as a reliable source for up-to-the-minute information about literally anything important at all.

The same could be said for radio, whether Orson Wells "Alien Invasion" broadcast or the multitude of April 1st jokes that got out of hand.

Apparently the "fallout" was an exaggeration that Orson went along with because it gave him more publicity. From the Wikipedia:

>"The supposed panic was so tiny as to be practically immeasurable on the night of the broadcast. ... Radio had siphoned off advertising revenue from print during the Depression, badly damaging the newspaper industry. So the papers seized the opportunity presented by Welles’ program to discredit radio as a source of news. The newspaper industry sensationalized the panic to prove to advertisers, and regulators, that radio management was irresponsible and not to be trusted."

and

"Welles later embraced the story as part of his personal myth. "Houses were emptying, churches were filling up; from Nashville to Minneapolis there was wailing in the streets and the rending of garments," he told Peter Bogdanovich years later."

"CBS, too, found reports ultimately useful in promoting the strength of its influence. radio management was irresponsible and not to be trusted."

Re: Who’s behind Wednesday’s epic Twitter hack?

#159
Funny that Krebs refers to Lucky225 as a longtime friend of Adrian Lamo.

I thought it was very well-known that Lucky225 made that story up as a cover to hide the fact that he gained control of Adrian Lamo’s @6 Twitter via a SIM swap hack himself, and also took control of Lamo’s Facebook in order to hijack ownership of the 2600 Magazine group on Facebook.

Re: Who’s behind Wednesday’s epic Twitter hack?

#160

man who falls for this stuff. i've been seeing "send me money to this account to get double that" scam for like 20 years, its hard to believe there are people who still don't know better.

I too don't understand who's technical enough to know what BitCoin is but not technical enough to understand the scam. I think some people are possibly just sending the scammers some money for the banter? A sign of respect for the hack.

The very fact that someone owns bitcoin means they have been scammed by the promise of doubling their money.
Post reply on HN