Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

341–350 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#341

Earlier quoted context omitted.

I would be curious as to who is citing that using a vpn is some "anti-pattern", to what? Not protecting your network accessible assets? If you have the means, certainly use a corporate/smb/personal vpn. It is one layer in a multitude of layers you should be using to protect your network. Its not as if once you achieve vpn access you have no other authz gates to internal applications. Its a "great filter" to help narr…

https://www.beyondcorp.com/ Yes, basically you should consider all networks untrusted including your internal network. You can still have a VPN but it shouldn't be the thing that protects the services inside your corp net because if it is then any breach means the intruder gets access to all your stuff.

oh come on. Competent companies regard their internal networks untrusted with or without a vpn access solution. If your an incompetent company then there is no argument for a vpn vs no vpn because your incompetent, and will eventually succumb to the horrors of your insecurities regardless if your applications and network endpoints are directly exposed to the internet or behind a vpn solution.

your beyondcorp link has nothing to do with a well implemented vpn solution + standard access controls to network endpoints like the link suggests. Your clearly supporting a false dichotomy in which having a well constructed vpn solution is "wrong" and does not add to your overall security posture. Shenanigans.

vpn or not you still need to authorize/authenticate your network endpoints. But hey, you don't want a vpn so give me a list of your internet accessible ssh hosts and well see how well your "zero trust" gets you if you can't keep up with best practices. Good luck!

Re: Who’s behind Wednesday’s epic Twitter hack?

#342

I'm sure it's been said before, but I just continue to be surprised that the admin panel used to carry out this attack wasn't locked behind a VPN. I've worked for multiple fully-remote companies that were easily able to protect tools like this from the outside world. The company I currently work for (fully remote) has tons of internal services that our engineers (who we trust) can access as needed in order to debug p…

Web authentication technology (eg U2F) is much more advanced and safe than VPN authentication technology (key files or strings sitting unencrypted on disk).

Additionally, TLS1.3 is better than most VPNs from a cryptographic standpoint.

Re: Who’s behind Wednesday’s epic Twitter hack?

#343
post #316

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

Important accounts should require 2fa for posting anything.

many of the affected accounts had 2fa.

Re: Who’s behind Wednesday’s epic Twitter hack?

#344

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

One way to look at this problem is to ask "how to secure Twitter". Another way to look at this problem is to ask whether people should trust Twitter as an official source of information. I think there is a big organisational difference between the AP and Twitter, but that's just me. Twitter does not employ journalists. Twitter is not the press.

People who have been interviewed by journalists know they regularly get things wrong, like a game of Telephone Whispers. Journalists are not experts in the topic and get things wrong even when they don't mean to - it might be as simple as mishearing the interviewed person, or rounding up a number that they shouldn't. Sometimes it's far more egregious.

At least when Twitter is secure, you see the exact words that were typed, and not through the filter of a reporter who may have misread.

I've personally been misquoted in media interviews. Not a major thing, but I could now use that newspaper article to claim I've done more than I really have, because hey, the newspapers said I did! It must be true!

(I didn't downvote you though, I think the downvotes are unfair.)

Re: Who’s behind Wednesday’s epic Twitter hack?

#345

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

People keep saying it could have started a war. Excuse me for being naive but come on—really? This is total sensationalism. What party wouldn’t verify something on twitter through diplomatic channels before going to war? Equity destruction: sure. War: no way.

How about civil war, or at least large-scale riots?

Re: Who’s behind Wednesday’s epic Twitter hack?

#346

Post on your own sever, syndicate elsewhere? Nobody mentioned indieweb.org/POSSE yet as a way to mitigate such?

POSSE is a great model. One of the problems is that there is no platform that reduces the friction of implementation. I have the technical ability to implement this myself on my own website, but I don't have the free time to set it all up and maintain all of the integrations with various platforms. And syndication is the creation side of the problem, but on the consumption side there's the issue of aggregating your friend's posts on other platforms into one place so you can keep up with everyone without remembering to check several different websites. That's arguably the more challenging part of making this model work at scale, and social networks actively prevent this by blocking API access and making it difficult to programmaticly access data within their platforms. I can't even subscribe to 2/3 of my content sources via RSS anymore.

Re: Who’s behind Wednesday’s epic Twitter hack?

#347

Earlier quoted context omitted.

https://www.beyondcorp.com/ Yes, basically you should consider all networks untrusted including your internal network. You can still have a VPN but it shouldn't be the thing that protects the services inside your corp net because if it is then any breach means the intruder gets access to all your stuff.

This thread is a bit confusing to me. Have we moved past layered security for some reason? The purpose of a VPN was never supposed to be the authentication layer to internal services. It's just a layer of security that makes it more difficult to carry out some types of attacks; thus increasing security defenses of an organization. Assuming that it has been breached is good practice, but doesn't mean that there's no p…

If the "layers" of your security use the same factors are they really layers or are they simply a time sink for you permitted users, and another thing to break?

My visceral reaction was "you got to have a VPN" as well but the more I thought about it the more I was convinced you don't _need_ a VPN.

Re: Who’s behind Wednesday’s epic Twitter hack?

#348
post #299
post #238

Earlier quoted context omitted.

Does it though? Using a VPN for access to internal infrastructure doesn't mean said internal infrastructure is insecure or authless itself. As in, defense in layers.

Exactly, assume zero trust but VPN with MFA provides another layer of security. Given the weekly volume of package vulns Github notifies me about I don't want to miss a 0day and get scanned. Perimeterless is fine if you're only using SaaS or you have an army of SecOps, but I don't want an internal app rumbled.

Is a VPN a suitable replacement for good security hygiene and vulnerability management?

Re: Who’s behind Wednesday’s epic Twitter hack?

#350

Earlier quoted context omitted.

I believe they are referring to the fact that they could have theoretically tweeted the wrong thing from the wrong account that could have caused a war. It isn't extremely likely but not comically unrealistic. Definitely within the realm of possibility.

How do you envision that happening? I mean the actual chain of events. A tweet is seen and some general launches all ICBMs? They pour their country’s military might into a war because of a tweet that is known to be fake within 3 minutes? No, it is not within the realm of possibility.

It really shouldn't be too hard to come up with a plausible threat scenario, particularly, say, at a time tensions are already running high:

https://en.wikipedia.org/wiki/2018_Hawaii_false_missile_aler...

https://en.wikipedia.org/wiki/Jyllands-Posten_Muhammad_carto...

https://historynewsnetwork.org/article/168374

Post reply on HN