> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
> Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no technical countermeasures. Yup. Doubly so for sysadmins, many of which have abhorrent data security practices. My personal solution is to use cover names, disposable phone numbers, and unique email addresses (the + trick…
Twitter internal panel linked to account hijackings
461–470 of 477 posts
Re: Twitter internal panel linked to account hijackings
#462Earlier quoted context omitted.
The only calls I get any more are recruiters (80%) scammers (15%) and family 5%.
Recruiters call ? I would have expected them to use other more asynchronous methods like text or email, unless you strongly indicate a preference.
Re: Twitter internal panel linked to account hijackings
#463Earlier quoted context omitted.
There’s bribery but I think blackmail is even likelier. This is such a huge breach that no one should think they could get away with leaking their credentials or opening a backdoor. Plus Twitter employees are really well paid. Now some life-ruining online behavior material is another type of a motivator.
Are twitter support contractors in third world countries really well paid?
Re: Twitter internal panel linked to account hijackings
#464Earlier quoted context omitted.
This is a more general and larger problem where society is constantly bending over backwards to cater to the 2% lowest performers. If you added up all the costs of the people at the lowest extremes (by various metrics), I'd venture to guess that we could increase our prosperity (by various metric) by an order of magnitude. Example: When I started my startup, we made the decision not to hire any salesperson who wasn't…
> This is a more general and larger problem where society is constantly bending over backwards to cater to the 2% lowest performers. As your parent said, it's not 2%, it's more like everyone. No one is perfect all the time. More importantly, it's one thing when hiring, but are you seriously suggesting 2% of the population shouldn't be able to use Twitter or online banking or other online services? 140,000,000 people…
...and it's not correct to say that "everyone is imperfect sometimes" because the correlation between people who are problems across various metrics, is high.
Re: Twitter internal panel linked to account hijackings
#465Earlier quoted context omitted.
Your hnews username is an identity. A small, weak, and reasonably disposable one, that you can have many of. Why do you want to use your God damn real name on the Internet unless you are a public person already? What do you have to gain? Hate mail, Death threats and calls for your firing? I've always wanted more of those. You do not WANT to be verified. Verified is a euphemism for doxxed. You could trust it was Elon…
How can we evaluate previous performance of (new) disposable accounts?
Re: Twitter internal panel linked to account hijackings
#466Earlier quoted context omitted.
Also ensuring that a hacker can get the 2FA token directly from the owner by pretending to be customer service...
In this case it sounds like the user is calling ETrade, so unless the user calls a wrong number that just so happens to be a hacker it's unlikely this would be an issue.
Then, people searching for things like "Microsoft tech support" would get the scammers number and call it. Google and other search engines will even pull that number from your site and handily present it to you at the top of the search results to make it appear even more legit.
Taking over unclaimed Google map listings for businesses is also really common.
Simply buying a toll free number that is close to the customer service number for a large company is bound to get you more inbound callers than you care to scam.
So no, absolutely no excuses for teaching people to share their 2fa codes.
Re: Twitter internal panel linked to account hijackings
#467Earlier quoted context omitted.
> Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no technical countermeasures. Yup. Doubly so for sysadmins, many of which have abhorrent data security practices. My personal solution is to use cover names, disposable phone numbers, and unique email addresses (the + trick…
What are the form of the emails? text@singledomain.com, text@disposible.email.service.com ? What if the service requires constant SMS OTP that you cannot opt out of?
Re: Twitter internal panel linked to account hijackings
#468Re: Twitter internal panel linked to account hijackings
#469> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
Re: Twitter internal panel linked to account hijackings
#470Earlier quoted context omitted.
Most tech companies like google and Facebook use hardware keys like Yubikey. TOTP and definitely sms are not as secure as hardware keys
The mechanism isn't relevant because the admin tool has a reset function. It is needed of course, because people loose their phones, keys and whatnot. No security mechanism is safe against an administrative reset for services like Twatter. SMS is seen as less safe because the transport layer is not encrypted. But there isn't much difference in the practical security of the average user.