Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

221–230 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#221

Earlier quoted context omitted.

It's almost as if web services that let people post whatever they want at any time, vulnerable to whatever security flaws may be present, shouldn't be used as a reliable source for up-to-the-minute information about literally anything important at all.

This. We've entered a world where the lowest common denominator of information is being used as primary source for current events. That's asinine.

I don't think this is new though. The same thing happens on the radio too - and radio can be hacked too.

Re: Who’s behind Wednesday’s epic Twitter hack?

#222
post #84

Earlier quoted context omitted.

I don't buy the stock market argument. People open short positions worth more than $100K every day, especially against companies like Tesla. There would be nothing suspicious about a few such trades. But really, my point is that pulling off a sophisticated exploit involving major celebrities, politicians and CEOs, social engineering/bribery, internal access at a top company etc. doesn't really seem worth the risk if…

> People open short positions worth more than $100K every day Yes, but you'd need to open one worth $1m to make $100k on a 10% move. $1m is still not "much" in the grand scheme of things, but it's still significant.

You can use variety of instruments to get a lot more then 10%

If you have a million to play with you could probably get something on the order of 10-20million or a lot more I guess depending on time you have to prepare

Re: Who’s behind Wednesday’s epic Twitter hack?

#223

Earlier quoted context omitted.

This. We've entered a world where the lowest common denominator of information is being used as primary source for current events. That's asinine.

That's partially because the sources formally seen as primary, at least in the US, have started to be viewed as biased and unreliable. This is largely through their own actions. Examples are legion, but a recent one is debacle at NYT over an op-ed. The news-consuming public was able to view the shenanigans of NYT reporters and staffers, which would formerly been done being the scenes. Many eyes were opened, and I'm c…

I agree. I have been following the rule of not trusting any such significant news for 48 hours and sometimes even a week because often, news gets debunked or more info comes out.

Re: Who’s behind Wednesday’s epic Twitter hack?

#224
post #61

Earlier quoted context omitted.

Many startups and hip companies don't do VPNs anymore - unfortunately they also dont do Zero Trust (which would require machine certs for everything and be enforced) - so stuff is often available over Internet with password auth + maybe MFA. Attacker who gets hold of cookie or bearer token wins. And the best part, support personnel often doesnt have MFA, because its outsourced to countries where smart phones with Aut…

Really stupid question. A key employee leaves, with their personal 2FA. Is there a standardized corporate solution for this yet? Sorry if that’s weirdly worded

Disabling their account or altering their first factor makes the second factor irrelevant. Who cares if I have a TOTP code for my old account, if the account is deactivated and/or its password changed?

Re: Who’s behind Wednesday’s epic Twitter hack?

#225
post #179

Earlier quoted context omitted.

It's almost as if web services that let people post whatever they want at any time, vulnerable to whatever security flaws may be present, shouldn't be used as a reliable source for up-to-the-minute information about literally anything important at all.

Its almost as if we shouldn't centralize such communication in a single giant private corporation.

While I am 10000% onboard with decentralizing communication, I am not sure if that would help in cases like this though. Back in 2013, only a single news outlet AP's twitter was hacked and had similar consequences. Decentralizing wouldn't have helped there I think.

Re: Who’s behind Wednesday’s epic Twitter hack?

#226

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

Yes it was dangerous, but nothing is “erased” if that market valuation is restored a few minutes later

That's not true. Many people have auto-sell / buy triggers set up when something drops below a value.

Re: Who’s behind Wednesday’s epic Twitter hack?

#227
post #125
post #67

Is it generally known that this hack was live for at least a few days, not just Wednesday? I personally saw one of the official @elonmusk scam tweets earlier this week.

The tweets didn't come from his handle. They were using the same image and name but what really caught my attention was that those accounts had a blue verified badge.

Yep, the newest strategy of the Twitter crypto scammers is to hack verified accounts of lesser-known users, then change the account name and profile picture to that of the user they wish to imitate.

Re: Who’s behind Wednesday’s epic Twitter hack?

#228
post #147

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

Erased as in moved to other markets only to return a short time later.

Many people have auto-sell / buy triggers set up when something drops below a value.

Re: Who’s behind Wednesday’s epic Twitter hack?

#229

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

People keep saying it could have started a war. Excuse me for being naive but come on—really? This is total sensationalism. What party wouldn’t verify something on twitter through diplomatic channels before going to war? Equity destruction: sure. War: no way.

This hack simply proved that a lot bigger things are possible. They could have (maybe they did) read private messages which could simply be used for blackmail. A top defense official getting blackmailed is pretty easy step to escalation to broken diplomacy.

Re: Who’s behind Wednesday’s epic Twitter hack?

#230

I don’t really think he should be naming who his unnamed sources “think” is behind an attack on this scale, especially with full name, city of origin, Instagram, suggested current location, age, etc. It feels a very, very small step away from doxxing to me. Added to which he has somebody in the comments essentially calling for the death penalty over this. If he has this personal information and evidence, pass it to t…

[deleted]
Post reply on HN