Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

311–320 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#311

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

Oh please. The rest of the world doesn’t take Twitter as seriously as Americans do. And truth be told, Americans shouldn’t take it seriously either. The platform derives power from the audience. Stop giving it your power.

So true. it's a toilet. A few months back I told myself no more, I resigned my account and haven't missed it at all. massive time sink, and utterly pointless. It isn't a conversation, it's yelling at a brick wall, then yelling louder when you don't get an answer.

Re: Who’s behind Wednesday’s epic Twitter hack?

#312

Twitter: function adminPanelShow() { if ( !isInOurVPN() ) throw logSecurityBreach(); if ( !isLoggedIn() ) throw logSecurityBreach(); slackSecurityChannel("AdminPanel Access: " + userName); ... }

Is it possible the attacker was in the VPN and logged in?

Re: Who’s behind Wednesday’s epic Twitter hack?

#313

Earlier quoted context omitted.

https://www.beyondcorp.com/ Yes, basically you should consider all networks untrusted including your internal network. You can still have a VPN but it shouldn't be the thing that protects the services inside your corp net because if it is then any breach means the intruder gets access to all your stuff.

This thread is a bit confusing to me. Have we moved past layered security for some reason? The purpose of a VPN was never supposed to be the authentication layer to internal services. It's just a layer of security that makes it more difficult to carry out some types of attacks; thus increasing security defenses of an organization. Assuming that it has been breached is good practice, but doesn't mean that there's no p…

The issue is that, for any company without thousands of employees (heck, probably even some of these are guilty), the VPN is often the only barrier to the entire network. The BeyondCorp model makes you explicitly specify "John can access support.corp.com but not admin.corp.com", while setting up these explicit checks is the exception for VPN-based access, not the norm (and sometimes it isn't even done right - eg. relying on DNS filtering).

Re: Who’s behind Wednesday’s epic Twitter hack?

#314

Earlier quoted context omitted.

Interesting. I looked for evidence supporting your claim and found this: https://github.com/keybase/keybase-issues/issues/3442 It's a very awkward thread where Lucky225 accidentally demonstrates that he has indeed taken over Adrian Lamo's email account. Note this doesn't say anything about whether they were or weren't friends. They definitely had overlapping interests.

Lamo died in '18, comment is from '19.

Sure. Does that indicate whether the account was taken over maliciously or sincerely?

Re: Who’s behind Wednesday’s epic Twitter hack?

#315
post #162

Earlier quoted context omitted.

But is that really new? Other than scale and reach (quantitative difference), how is that any different qualitatively from the old grapevine/gossip network? "My dad's co-worker's, girlfriend's uncle works at ... and said..."

That didn't get disseminated and diffused to tens of millions. If something was published they'd look for official sources or corroborating sources and or secondary evidence. If AP, EFE, UPI, Kyodo, Interfax etc all get their news from one source [Twitter] that's just laziness.

Agreed but I said "apart from scale and reach". The point I was trying to make was that people have always found it fairly easy to believe non-credible sources. In this sense, social media is not qualitatively different. Only quantitatively different.

Re: Who’s behind Wednesday’s epic Twitter hack?

#316

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

Important accounts should require 2fa for posting anything.

Re: Who’s behind Wednesday’s epic Twitter hack?

#317
post #192

Earlier quoted context omitted.

I guess I just don't think we should plan society around the assumption that the internet will overreact and take justice into its own hands, which is not in fact justice. Why can't we hold people on the internet accountable for harassment?

because you put ppl at risk without any benefit. you could easily as said I believe I know who did this and I've turned that information over to the authorities. what does the public or kerp gain by putting it out in public when you dont know. yes he (kerp) can be held accountable (and should be hit immediately with a defamation lawsuit if hes wrong) but not everyone has the resources to do that. look at reddit and b…

> look at reddit and boston bomber the person they accused killed himself..

Do we know this was due to the Reddit misidentification? His body was found on April 23, after being accused on April 18, but he had been missing since March 16. I've never seen a definitive order of events given.

(I've no doubt such accusations _could_ lead to such horrible outcomes, but I'm not sure if we know they did here with certainty)

Re: Who’s behind Wednesday’s epic Twitter hack?

#318
post #283

Earlier quoted context omitted.

If this indeed had happened, I wonder how it would have played out. It would not be pretty, that is for sure.

Well let’s see...since all countries with ICBMs also have technology in place to detect or verify via satellite a nuclear launch, absolutely nothing would happen. If a real launch had taken place, they would have known about it far before they heard about a post on Twitter. The alarmism here on HN is really disappointing. This is the kind of foolishness usually reserved for Reddit.

I think plenty could have happened. Compare with the false nuclear attack alarm in Hawaii the other year. Panic can cause all kinds of unforseeable consequences.

Re: Who’s behind Wednesday’s epic Twitter hack?

#319
post #151
post #133

Earlier quoted context omitted.

The same could be said for radio, whether Orson Wells "Alien Invasion" broadcast or the multitude of April 1st jokes that got out of hand.

tl;dr don't rely on a single source

Bingo. Information should always be confirmed with at least one other (hopefully) independent source. The more sources, the merrier. If there aren't independent sources then don't jump to conclusions.

Re: Who’s behind Wednesday’s epic Twitter hack?

#320

Earlier quoted context omitted.

Isn’t most crime journalism the same? Three examples from the front page of the NY post right now. I am having a hard time figuring out how to distinguish this and the OP doxxing. The organizationS fact-checking process? Solidness of the evidence? > Allegations were made against longtime radio broadcaster Larry Michael (retired Wednesday), director of pro personnel Alex Santos (fired last week), assistant director of…

It is in the United States. In other countries until conviction only initials are used. This to avoid ruining people's lives (or even endangering them) in case an allegation turns out not to be true.

We don't even do initials here for regular people. Usually it's some vague age and gender. Maybe ethnicity if relevant.
Post reply on HN