Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

351–360 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#351
post #158
post #133

Earlier quoted context omitted.

The same could be said for radio, whether Orson Wells "Alien Invasion" broadcast or the multitude of April 1st jokes that got out of hand.

Apparently the "fallout" was an exaggeration that Orson went along with because it gave him more publicity. From the Wikipedia: >"The supposed panic was so tiny as to be practically immeasurable on the night of the broadcast. ... Radio had siphoned off advertising revenue from print during the Depression, badly damaging the newspaper industry. So the papers seized the opportunity presented by Welles’ program to discr…

“Getting it Wrong” tells about this and other commonly believed media myths

Getting It Wrong: Ten of the Greatest Misreported Stories in American Journalism

https://www.amazon.com/dp/0520262093/ref=cm_sw_r_cp_api_i_y5...

Re: Who’s behind Wednesday’s epic Twitter hack?

#352
post #299

Earlier quoted context omitted.

Exactly, assume zero trust but VPN with MFA provides another layer of security. Given the weekly volume of package vulns Github notifies me about I don't want to miss a 0day and get scanned. Perimeterless is fine if you're only using SaaS or you have an army of SecOps, but I don't want an internal app rumbled.

Is a VPN a suitable replacement for good security hygiene and vulnerability management?

Nobody is saying VPN is a replacement. Users should still have to authenticate against an IDP once they're inside the perimeter. VPN + MFA protects apps from drive-by attacks while they're waiting to be patched.

Yes, in a perfect world everyone would have an army of SecOps ninjas pentesting and patching all systems 24/7, but this is the Real World™

Defence in depth.

Re: Who’s behind Wednesday’s epic Twitter hack?

#353

Funny that Krebs refers to Lucky225 as a longtime friend of Adrian Lamo. I thought it was very well-known that Lucky225 made that story up as a cover to hide the fact that he gained control of Adrian Lamo’s @6 Twitter via a SIM swap hack himself, and also took control of Lamo’s Facebook in order to hijack ownership of the 2600 Magazine group on Facebook.

Is your assertion that Lucky and Adrian and no relationship and he had no right to assume stewardship of his online accounts after his demise?

Re: Who’s behind Wednesday’s epic Twitter hack?

#354

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

That market value was recovered in 5 minutes. It sucks for anyone with stop orders, or anyone who got a margin call; but to say it could start wars is really not giving any credit to the humans in the loop.

Re: Who’s behind Wednesday’s epic Twitter hack?

#355
post #200

I'm sure it's been said before, but I just continue to be surprised that the admin panel used to carry out this attack wasn't locked behind a VPN. I've worked for multiple fully-remote companies that were easily able to protect tools like this from the outside world. The company I currently work for (fully remote) has tons of internal services that our engineers (who we trust) can access as needed in order to debug p…

Internal networks only accessible via VPN is considered an anti-pattern now in terms of security. It puts authorization firmly on the VPN. If the account with VPN access is compromised, then the attacker has full access to these sensitive systems. This hack probably underscores the importance of zero trust. Although if the system is compromised from within (like this hack is) then there is not much you can do.

Of course not

> If the account with VPN access is compromised, then the attacker has full access to these sensitive systems.

No. Logging in the VPN is one thing, logging into the internal systems requires an extra login

This is not hard

Re: Who’s behind Wednesday’s epic Twitter hack?

#356

Earlier quoted context omitted.

This thread is a bit confusing to me. Have we moved past layered security for some reason? The purpose of a VPN was never supposed to be the authentication layer to internal services. It's just a layer of security that makes it more difficult to carry out some types of attacks; thus increasing security defenses of an organization. Assuming that it has been breached is good practice, but doesn't mean that there's no p…

If the "layers" of your security use the same factors are they really layers or are they simply a time sink for you permitted users, and another thing to break? My visceral reaction was "you got to have a VPN" as well but the more I thought about it the more I was convinced you don't _need_ a VPN.

Effectively are you saying: if I hacked your account I hacked your VPN username/password too? It's still an extra step that might trigger some sketchy senses of some people.

Not sure if it still doesn't work effectively for that.

Re: Who’s behind Wednesday’s epic Twitter hack?

#357

Earlier quoted context omitted.

I would be curious as to who is citing that using a vpn is some "anti-pattern", to what? Not protecting your network accessible assets? If you have the means, certainly use a corporate/smb/personal vpn. It is one layer in a multitude of layers you should be using to protect your network. Its not as if once you achieve vpn access you have no other authz gates to internal applications. Its a "great filter" to help narr…

https://www.beyondcorp.com/ Yes, basically you should consider all networks untrusted including your internal network. You can still have a VPN but it shouldn't be the thing that protects the services inside your corp net because if it is then any breach means the intruder gets access to all your stuff.

That’s a shockingly dumb approach in the context of security today where zero days have to be included in your threat model. A VPN should be requisite to even get network connectivity to such critical services. Then on top of that, you should still have to auth to access them.

Re: Who’s behind Wednesday’s epic Twitter hack?

#358

Earlier quoted context omitted.

This thread is a bit confusing to me. Have we moved past layered security for some reason? The purpose of a VPN was never supposed to be the authentication layer to internal services. It's just a layer of security that makes it more difficult to carry out some types of attacks; thus increasing security defenses of an organization. Assuming that it has been breached is good practice, but doesn't mean that there's no p…

If the "layers" of your security use the same factors are they really layers or are they simply a time sink for you permitted users, and another thing to break? My visceral reaction was "you got to have a VPN" as well but the more I thought about it the more I was convinced you don't _need_ a VPN.

If your only threat model is leaked credentials and not vulnerabilities, sure.

Re: Who’s behind Wednesday’s epic Twitter hack?

#359

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

Destroyed economies? Started a war? The tiny effect on the market lasted less than 5 minutes. Your post is bordering on comical.

Why do I feel this is a post that will not age well :-/

Re: Who’s behind Wednesday’s epic Twitter hack?

#360
post #283

Earlier quoted context omitted.

If this indeed had happened, I wonder how it would have played out. It would not be pretty, that is for sure.

Well let’s see...since all countries with ICBMs also have technology in place to detect or verify via satellite a nuclear launch, absolutely nothing would happen. If a real launch had taken place, they would have known about it far before they heard about a post on Twitter. The alarmism here on HN is really disappointing. This is the kind of foolishness usually reserved for Reddit.

I think brainstorming about combinations of variables that could plausibly lead to a black swan event is worthwhile, and an excellent application for the collective mental processing powers of HN. I would advocate for a new kind of discussion class for threads, to focus on discrete perspectives and goals, risk being one of the most important kinds. Smart casual conversation is excellent, but there are other types that are also excellent, but in a different way.
Post reply on HN