Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

291–300 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#291

Earlier quoted context omitted.

Not 100% positive on this, but I believe the admin panel allowed to remove 2FA as well.

Yep or else none of this could happen. I work at a company that we need at least two methods to authenticate you to remove MFA through the admin console so this wouldn’t have happened.

Is this a part of your company’s product or internal tooling, or is this 2FA part of a software you use? If it’s the latter, please give a recommendation if it’s good!

Re: Who’s behind Wednesday’s epic Twitter hack?

#292

Earlier quoted context omitted.

It's not feasible for every trusted source of knowledge to have their own radio station, so the sources utilize existing stations, and consumers have no choice but to tune into those stations. It's perfectly feasible for every trusted source of knowledge to run a web server, and they actually do it, so it's sad that consumers don't connect directly to those servers and instead use middlemen.

People are not looking for trusted sources of knowledge. They are looking for entertainment.

Trust is a loaded concept.

What people trust is generally what fits their worldview which is increasingly reinforced by the filter bubbles provided by tech companies. The increasing polarisation and tribalism is made worse by the traditional network programming and now algorithms that present what the audience is comfortable to see and hear.

I like using DDG because it doesn't filter, but at the same time I hate wading through utter crap and being the filter.

Twitter for all its flaws is pretty good at giving everyone a voice so you can read something and then the criticisms without having to aggregate that from multiple sites.

Re: Who’s behind Wednesday’s epic Twitter hack?

#293

Earlier quoted context omitted.

Many people have auto-sell / buy triggers set up when something drops below a value.

And?

They should realize that being too vigilant has its own downsides. Autosell is no magic. It fails to see into the future, it might as well go up the second the shares are sold. Tough luck...

Re: Who’s behind Wednesday’s epic Twitter hack?

#294
post #71

Earlier quoted context omitted.

I think they could have done a lot better by having Elon tweet out a new product preorder page (limited edition Tesla merch?), which accepts payments in crypto. Really anything other than give me X so I can give you 2X, which has been done to death already. 100k is chump change, historically for this class of scam. Another idea is, hijack customer service request DM's from crypto exchanges, and lead customer to phish…

The traffic burst would be huge for the Tesla tweet. That type of scam introduces more complexity, such as requiring hosting for millions of visitors in an hour, which can leave a traceable trail.

Hosting for millions of visitors/hour isn't that hard. Maybe the cloud companies want to make you think otherwise, but a handful of bare metal servers around the world should be enough to handle that kind of load unless you're streaming video or running a really heavy web framework. Those can easily be obtained for free if you're already a criminal and have access to compromised servers or stolen credit cards to buy them with.

Re: Who’s behind Wednesday’s epic Twitter hack?

#295
post #147

Earlier quoted context omitted.

Erased as in moved to other markets only to return a short time later.

Many people have auto-sell / buy triggers set up when something drops below a value.

The value changed hands, it wasn't erased. The stock market doesn't change the underlying fundamentals of the companies.

Re: Who’s behind Wednesday’s epic Twitter hack?

#296

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

People keep saying it could have started a war. Excuse me for being naive but come on—really? This is total sensationalism. What party wouldn’t verify something on twitter through diplomatic channels before going to war? Equity destruction: sure. War: no way.

A war of tweets maybe. If this hack could start a war then any state actor could manipulate us into war.

Let’s not speculate war here. We’re on HN:)

Re: Who’s behind Wednesday’s epic Twitter hack?

#297
post #258
post #158

Earlier quoted context omitted.

Apparently the "fallout" was an exaggeration that Orson went along with because it gave him more publicity. From the Wikipedia: >"The supposed panic was so tiny as to be practically immeasurable on the night of the broadcast. ... Radio had siphoned off advertising revenue from print during the Depression, badly damaging the newspaper industry. So the papers seized the opportunity presented by Welles’ program to discr…

I loved to ask my grandmother about this because she recalled listening to the original broadcast. She said the station would take commercial breaks to interrupt the story, and they reminded listeners it was a fictitious broadcast when taking these breaks. She didn't believe that anyone could be fooled by it, at least not to the extent that was reported.

[deleted]

Re: Who’s behind Wednesday’s epic Twitter hack?

#298

I keep saying phone numbers for 2FA is dumb but entire industry thinks this is a good idea for some reason. The problem here is that it's not even used as 2FA, it's just one factor and these services think it's sufficient to prove identity.

phone numbers for almost anything is dumb.

Discord wants my phone number for forums about sexual topics that could get me killed if I was in certain countries. Obviously I don't want to give them something which actually identifies me.

Re: Who’s behind Wednesday’s epic Twitter hack?

#299
post #238
post #200

Earlier quoted context omitted.

Internal networks only accessible via VPN is considered an anti-pattern now in terms of security. It puts authorization firmly on the VPN. If the account with VPN access is compromised, then the attacker has full access to these sensitive systems. This hack probably underscores the importance of zero trust. Although if the system is compromised from within (like this hack is) then there is not much you can do.

Does it though? Using a VPN for access to internal infrastructure doesn't mean said internal infrastructure is insecure or authless itself. As in, defense in layers.

Exactly, assume zero trust but VPN with MFA provides another layer of security. Given the weekly volume of package vulns Github notifies me about I don't want to miss a 0day and get scanned. Perimeterless is fine if you're only using SaaS or you have an army of SecOps, but I don't want an internal app rumbled.

Re: Who’s behind Wednesday’s epic Twitter hack?

#300
post #199

Earlier quoted context omitted.

Donald Trump?

A president can’t just “start a war”, muchless order air strikes. dozens of people are involved. Donald Trump yells and hollers all the time and people send Jared to calm him down. There have already been documented instances of this in the Trump admin, and it wasn’t over tweets.

A US president has the power to unilaterally launch the nuclear arsenal:

https://allthingsnuclear.org/dwright/trump-and-the-nuclear-c...

Whether the military would actually carry out those orders when no one else has ICBMs in the air is debatable, but the president's defined role as the commander-in-chief and the sole arbiter of when to open the gates of hell on earth is not.

Post reply on HN