Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

181–190 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#181

The among taken in this scam is chump change compared to the YouTube scammers. YouTube is a vastly bigger website than twitter and way slower to respond to accounts begin stolen by scammers. I remember seeing an Ripple giveaway scam that in a single day made 100k with just a single account ,. And fake bill gates one made 40k. the list goes on and on. My guess is the total taken is in the $3-5 million range from youtu…

Youtube served me the Bill Gates bitcoin scam on Monday, 2 days before the Twitter hack, as opening ad for a video from their recommendation algorithm. The ad's site clearly perpetuated the scam for at least a couple days before changing the website to an innocent iframe link to Bill's foundation page.

Alphabet Inc should be held liable.

Re: Who’s behind Wednesday’s epic Twitter hack?

#182

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

I really think that world leaders twitter accounts should be on completely separate systems from the twitter world. Like a twitter.gov service. It should be insanely locked down, and twitter employees don't have access to it unless they are certified and thoroughly trained. It's just become that important to the stock market and world policy.

Or, just possibly, world leaders shouldn't be on Twitter.

Seems to me having them there is about 99% downside, 1% upside.

Disclosure: I dislike Twitter on principle.

Re: Who’s behind Wednesday’s epic Twitter hack?

#183
post #167

I don’t really think he should be naming who his unnamed sources “think” is behind an attack on this scale, especially with full name, city of origin, Instagram, suggested current location, age, etc. It feels a very, very small step away from doxxing to me. Added to which he has somebody in the comments essentially calling for the death penalty over this. If he has this personal information and evidence, pass it to t…

I never understood the whole doxing thing... the actions you take in this world are real. You can't take them back. You don't get to be anonymous just because you wish to be or because you frequent hacker sub-cults where doxing is some holy transgression. Bad op sec is bad op sec. Nothing more, nothing less. If Krebs got it wrong, well, he can suffer the consequences of that, too.

But the risk to the target outweighs the potential benefit to the doxxer. Consequences can be unequal. And if the doxee ends up being the perpetrator, then the bad things were already on their way via the legal system.

Re: Who’s behind Wednesday’s epic Twitter hack?

#184
post #167

Earlier quoted context omitted.

I never understood the whole doxing thing... the actions you take in this world are real. You can't take them back. You don't get to be anonymous just because you wish to be or because you frequent hacker sub-cults where doxing is some holy transgression. Bad op sec is bad op sec. Nothing more, nothing less. If Krebs got it wrong, well, he can suffer the consequences of that, too.

>If Krebs got it wrong, well, he can suffer the consequences of that, too. And, if he got it wrong, the innocent person he doxxed has to suffer the (potentially much more harsh) consequences of someone else's irresponsible actions. While Krebs begins working on his next story, and if we're lucky, posts an "oopsie" comment. How can you justify that as okay?

Do you think Krebs got it wrong?

But regardless, harassment is harassment. If the public starts harassing the dude, even if he is guilty, they're just as guilty of their own offenses. Two wrongs don't make a right.

Re: Who’s behind Wednesday’s epic Twitter hack?

#185
post #167

Earlier quoted context omitted.

I never understood the whole doxing thing... the actions you take in this world are real. You can't take them back. You don't get to be anonymous just because you wish to be or because you frequent hacker sub-cults where doxing is some holy transgression. Bad op sec is bad op sec. Nothing more, nothing less. If Krebs got it wrong, well, he can suffer the consequences of that, too.

The actions you take in this world are real yes, but the scale at which the internet enables retribution is unprecedented. If you punch someone in the street maybe three people will beat you up. If you punch someone online, tens of thousands of people might pile on and start kicking.

There's a certain symmetry to that, though. You fuck up on the world stage then you suffer a world of consequences. Anyway, I would sincerely hope people are more mature than to start harassing a dude that some security has-been decided to name as the perpetrator. You're not allow to harass and threaten someone just because they're suspected of being guilty of some crime.

Re: Who’s behind Wednesday’s epic Twitter hack?

#186
post #61
post #48

It will be interesting to see how the access was gained. I wonder how well this administrative system was protected. Did they have basic controls like: 1) Accessible via corporate VPN only (requiring 2fa) 2) Admin panel protected by 2fa plus necessary authentication+authorization controls 3) Audit trails Short of cooperative access (device handover), I could only see an outsider gaining access to the system due to po…

Many startups and hip companies don't do VPNs anymore - unfortunately they also dont do Zero Trust (which would require machine certs for everything and be enforced) - so stuff is often available over Internet with password auth + maybe MFA. Attacker who gets hold of cookie or bearer token wins. And the best part, support personnel often doesnt have MFA, because its outsourced to countries where smart phones with Aut…

Really stupid question. A key employee leaves, with their personal 2FA. Is there a standardized corporate solution for this yet? Sorry if that’s weirdly worded

Re: Who’s behind Wednesday’s epic Twitter hack?

#187
post #177
post #167

Earlier quoted context omitted.

I never understood the whole doxing thing... the actions you take in this world are real. You can't take them back. You don't get to be anonymous just because you wish to be or because you frequent hacker sub-cults where doxing is some holy transgression. Bad op sec is bad op sec. Nothing more, nothing less. If Krebs got it wrong, well, he can suffer the consequences of that, too.

Like a lot of terms doxing can mean different things. Sometimes it means holding people accountable and sometimes it means releasing the home address and workplace of a person misidentified as a wrongdoer by an internet mob. A recent example was the biker misidentified as a man who assaulted a child putting up posters. https://www.bbc.com/news/technology-52978880

And I would hold the people who acted on partial information accountable for their actions. Harassment is wrong regardless of whether you think someone is guilty of something or not. The internet needs to grow up.

Re: Who’s behind Wednesday’s epic Twitter hack?

#188
post #153

Earlier quoted context omitted.

On the off-chance that you're serious - doxxing someone who is suspected to be linked to a crime is staggeringly irresponsible, because you are then effectively convicting them in the court of public opinion. If they are innocent, but you have not only levelled accusations at them, but provided ways to access them, then you are partially responsible for what others choose to do with that information.

Isn’t most crime journalism the same? Three examples from the front page of the NY post right now. I am having a hard time figuring out how to distinguish this and the OP doxxing. The organizationS fact-checking process? Solidness of the evidence? > Allegations were made against longtime radio broadcaster Larry Michael (retired Wednesday), director of pro personnel Alex Santos (fired last week), assistant director of…

It is in the United States. In other countries until conviction only initials are used. This to avoid ruining people's lives (or even endangering them) in case an allegation turns out not to be true.

Re: Who’s behind Wednesday’s epic Twitter hack?

#189
post #45

Krebs should get someone half as good at html and CSS as he is in security to update his awful site. Doesnt even work in Firefox reader.

Maybe Firefox should get someone half as good as Chrome developers, because the reader mode works on his site fine there.

As much as folks here on HN extol Firefox, it just feels somewhat sluggish and buggy compared to Chrome. I try to use Firefox Developer edition sometimes but just can't because primarily it feels tangibly slower than Chrome.
Post reply on HN