Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

321–330 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#321
post #133

Earlier quoted context omitted.

The same could be said for radio, whether Orson Wells "Alien Invasion" broadcast or the multitude of April 1st jokes that got out of hand.

It's not feasible for every trusted source of knowledge to have their own radio station, so the sources utilize existing stations, and consumers have no choice but to tune into those stations. It's perfectly feasible for every trusted source of knowledge to run a web server, and they actually do it, so it's sad that consumers don't connect directly to those servers and instead use middlemen.

I know we're not supposed to discuss downvotes, but there's a sibling comment that makes the point I wanted to make, but it's dead. It seems fine, and the user's history is filled with dead comments that mostly also seem fine.

Regardless, if anyone has a response to a bunch of websites being a worse security model than one giant platform, you can reply to me instead.

Re: Who’s behind Wednesday’s epic Twitter hack?

#322

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

This. It almost seems like a proof of concept for someone selling services to a bigger player, using the Bitcoin angle as a smokescreen. Something like this right before the election or after could wreak havoc if targeted to the right accounts. I imagine certain state sponsors would pay handsomely for that.

>This. It almost seems like a proof of concept for someone selling services to a bigger player, using the Bitcoin angle as a smokescreen.

This is rather unlikely. There is nothing left to sell. The vulnerabilty was "burned" in the showcase. The code will now be patched 6 ways till sunday and they will probably uncover even more vulns in the code audit. Twitter got caught with their pants down and they will make sure it doesn't happen againg the same way.

If you want to make a display PoC before the sale, let the buyer arbitrarily choose a Twitter account and then do your thing. Taking over dozens of high-profile Twitter accounts the way it happened is just drawing unnecessary attention. Everyone will now trust Twitter less and no one know what kind of new security measure will come of this.

Re: Who’s behind Wednesday’s epic Twitter hack?

#323

Earlier quoted context omitted.

This. It almost seems like a proof of concept for someone selling services to a bigger player, using the Bitcoin angle as a smokescreen. Something like this right before the election or after could wreak havoc if targeted to the right accounts. I imagine certain state sponsors would pay handsomely for that.

That was my thought as well. A big stunt to show they can take over some of the largest names on Twitter/world as a proof of concept. Think of what they can do if they fan this out at scale to millions of normal accounts.

pretty dumb criminals then. Exposing their approach to twitter before doing the real thing...

Re: Who’s behind Wednesday’s epic Twitter hack?

#324
post #61

Earlier quoted context omitted.

Many startups and hip companies don't do VPNs anymore - unfortunately they also dont do Zero Trust (which would require machine certs for everything and be enforced) - so stuff is often available over Internet with password auth + maybe MFA. Attacker who gets hold of cookie or bearer token wins. And the best part, support personnel often doesnt have MFA, because its outsourced to countries where smart phones with Aut…

Really stupid question. A key employee leaves, with their personal 2FA. Is there a standardized corporate solution for this yet? Sorry if that’s weirdly worded

The best part are breakglass keys or certs!

Who rotates them when someone who had access to one leaves the org? :)

Re: Who’s behind Wednesday’s epic Twitter hack?

#325
post #158
post #133

Earlier quoted context omitted.

The same could be said for radio, whether Orson Wells "Alien Invasion" broadcast or the multitude of April 1st jokes that got out of hand.

Apparently the "fallout" was an exaggeration that Orson went along with because it gave him more publicity. From the Wikipedia: >"The supposed panic was so tiny as to be practically immeasurable on the night of the broadcast. ... Radio had siphoned off advertising revenue from print during the Depression, badly damaging the newspaper industry. So the papers seized the opportunity presented by Welles’ program to discr…

[deleted]

Re: Who’s behind Wednesday’s epic Twitter hack?

#326

Earlier quoted context omitted.

I believe they are referring to the fact that they could have theoretically tweeted the wrong thing from the wrong account that could have caused a war. It isn't extremely likely but not comically unrealistic. Definitely within the realm of possibility.

How do you envision that happening? I mean the actual chain of events. A tweet is seen and some general launches all ICBMs? They pour their country’s military might into a war because of a tweet that is known to be fake within 3 minutes? No, it is not within the realm of possibility.

Threaten North Korea Back it up from different reliable sources North Korea launches preemptive strike on South Korea

Re: Who’s behind Wednesday’s epic Twitter hack?

#327

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

To be honest, I think that would indicate a dysfunction of equity markets, not necessarily a problem of Twitter. I would like Twitter to be not that important. For politics and other topics.

Re: Who’s behind Wednesday’s epic Twitter hack?

#328
post #133

Earlier quoted context omitted.

It's almost as if web services that let people post whatever they want at any time, vulnerable to whatever security flaws may be present, shouldn't be used as a reliable source for up-to-the-minute information about literally anything important at all.

The same could be said for radio, whether Orson Wells "Alien Invasion" broadcast or the multitude of April 1st jokes that got out of hand.

There's a documentary I saw that explains that the hubbub around Welles' "War of the Worlds" broadcast was just to cover up the arrival of Red Lectroids.

Re: Who’s behind Wednesday’s epic Twitter hack?

#329

Twitter: function adminPanelShow() { if ( !isInOurVPN() ) throw logSecurityBreach(); if ( !isLoggedIn() ) throw logSecurityBreach(); slackSecurityChannel("AdminPanel Access: " + userName); ... }

Do you know how account takeovers work?

Re: Who’s behind Wednesday’s epic Twitter hack?

#330

Earlier quoted context omitted.

Yes it was dangerous, but nothing is “erased” if that market valuation is restored a few minutes later

In the aggregate sense, it eventually netted out. But a lot of people who sold when it looked like prices were collapsing sure got a pretty decent chunk of their bank accounts "erased".

I fail to see that anything or anyone could be blamed besides themselves. We cannot have the net to be emotional support for investors.
Post reply on HN