Earlier quoted context omitted.
> Do you really think someone like elon musk will pay a bitcoin ransom assuming there is anything incriminating? Maybe? I mean I certainly don't dismiss the idea out of hand. The one strong counter-argument I can think of is that very few things would actually embarrass Musk at this point.
Yeah, Musk specifically doesn't feel likely to care, perhaps if we assume someone else, who is less, shall we say, favorable to controversy?
Who’s behind Wednesday’s epic Twitter hack?
371–380 of 536 posts
Re: Who’s behind Wednesday’s epic Twitter hack?
#372I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…
Re: Who’s behind Wednesday’s epic Twitter hack?
#373Earlier quoted context omitted.
I know we're not supposed to discuss downvotes, but there's a sibling comment that makes the point I wanted to make, but it's dead. It seems fine, and the user's history is filled with dead comments that mostly also seem fine. Regardless, if anyone has a response to a bunch of websites being a worse security model than one giant platform, you can reply to me instead.
if you click into that comment (through the timestamp) you can vouch for it, which if vouched by enough people will show the comment. The account is likely shadow-banned or similar, so their comments are dead by default.
Re: Who’s behind Wednesday’s epic Twitter hack?
#374Earlier quoted context omitted.
This. We've entered a world where the lowest common denominator of information is being used as primary source for current events. That's asinine.
That's partially because the sources formally seen as primary, at least in the US, have started to be viewed as biased and unreliable. This is largely through their own actions. Examples are legion, but a recent one is debacle at NYT over an op-ed. The news-consuming public was able to view the shenanigans of NYT reporters and staffers, which would formerly been done being the scenes. Many eyes were opened, and I'm c…
Re: Who’s behind Wednesday’s epic Twitter hack?
#375I'm sure it's been said before, but I just continue to be surprised that the admin panel used to carry out this attack wasn't locked behind a VPN. I've worked for multiple fully-remote companies that were easily able to protect tools like this from the outside world. The company I currently work for (fully remote) has tons of internal services that our engineers (who we trust) can access as needed in order to debug p…
How do you know it wasn't behind a VPN?
Re: Who’s behind Wednesday’s epic Twitter hack?
#376Earlier quoted context omitted.
People keep saying it could have started a war. Excuse me for being naive but come on—really? This is total sensationalism. What party wouldn’t verify something on twitter through diplomatic channels before going to war? Equity destruction: sure. War: no way.
Here's how I think it could be done: Get Trump's account, and tweet something like, "I've ordered a NUCLEAR STRIKE on China! The missiles are already in the air. The DEEP STATE is trying to take me out. They will try to silence me and delete these tweets and use deep fakes to say this was a hoax! The storm is here, Q is real, it's time to take up arms and kill democrats." Then continue tweeting escalating things over…
> My fellow Americans, I'm pleased to tell you today that I've signed legislation that will outlaw Russia forever. We begin bombing in five minutes.
Re: Who’s behind Wednesday’s epic Twitter hack?
#377Earlier quoted context omitted.
> It feels a very, very small step away from doxxing to me. What small step is that? Looks like a textbook case of doxxing to me.
This isn't his first time doing it, either. https://itwire.com/security/infosec-researchers-slam-ex-wapo...
1. https://krebsonsecurity.com/2020/04/whos-behind-the-reopen-d...
2. https://twitter.com/cyberingcc/status/1252460981546090496
Re: Who’s behind Wednesday’s epic Twitter hack?
#378This is the most important point: > Also, it seems clear that this Twitter hack could have let the attackers view the direct messages of anyone on Twitter, information that is difficult to put a price on but which nevertheless would be of great interest to a variety of parties, from nation states to corporate spies and blackmailers. My understanding is the hackers used the admin panel to change the email addresses of…
If you're already logged in to a Twitter account you can deactivate 2FA by disabling the account (aka deleting with a 30 day window) and then re-enabling the account.
Re: Who’s behind Wednesday’s epic Twitter hack?
#379Earlier quoted context omitted.
If this indeed had happened, I wonder how it would have played out. It would not be pretty, that is for sure.
Well let’s see...since all countries with ICBMs also have technology in place to detect or verify via satellite a nuclear launch, absolutely nothing would happen. If a real launch had taken place, they would have known about it far before they heard about a post on Twitter. The alarmism here on HN is really disappointing. This is the kind of foolishness usually reserved for Reddit.
Re: Who’s behind Wednesday’s epic Twitter hack?
#380Earlier quoted context omitted.
https://www.beyondcorp.com/ Yes, basically you should consider all networks untrusted including your internal network. You can still have a VPN but it shouldn't be the thing that protects the services inside your corp net because if it is then any breach means the intruder gets access to all your stuff.
This thread is a bit confusing to me. Have we moved past layered security for some reason? The purpose of a VPN was never supposed to be the authentication layer to internal services. It's just a layer of security that makes it more difficult to carry out some types of attacks; thus increasing security defenses of an organization. Assuming that it has been breached is good practice, but doesn't mean that there's no p…
I'm all for debate but some things are close and shut. Yes, don't trust your user just because they are in the internal network, but no, that doesn't mean everything has to be visible from the outside.