Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

421–430 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#421
post #158
post #133

Earlier quoted context omitted.

The same could be said for radio, whether Orson Wells "Alien Invasion" broadcast or the multitude of April 1st jokes that got out of hand.

Apparently the "fallout" was an exaggeration that Orson went along with because it gave him more publicity. From the Wikipedia: >"The supposed panic was so tiny as to be practically immeasurable on the night of the broadcast. ... Radio had siphoned off advertising revenue from print during the Depression, badly damaging the newspaper industry. So the papers seized the opportunity presented by Welles’ program to discr…

According to family folk lore, during WWII when they had double summer time, my grandmother managed to put the clocks 2 hours forwards instead of 2 hours back. So woke up in the small hours and turned on radio to BBC and heard German (they transmitted to Germany as propaganda, and during night used channels normally broadcasting in English). Immediately wakes whole household - "we've been invaded - the Germans have taken over the BBC"!

Re: Who’s behind Wednesday’s epic Twitter hack?

#422

Earlier quoted context omitted.

The issue is that, for any company without thousands of employees (heck, probably even some of these are guilty), the VPN is often the only barrier to the entire network. The BeyondCorp model makes you explicitly specify "John can access support.corp.com but not admin.corp.com", while setting up these explicit checks is the exception for VPN-based access, not the norm (and sometimes it isn't even done right - eg. rel…

In short: VPN can be a security tool, as long as it is not your only security tool.

Think of VPN, just a wifi router. Don't rely on it! Design your internal tools to be secure. Not trust any network or client submitted data.

For these big companies (FAANG, Twitter too), please spend all those money on your security instead of market please.

Re: Who’s behind Wednesday’s epic Twitter hack?

#423

Earlier quoted context omitted.

Financial markets do. Where acting faster than your competition is essential you don't have a lot of choice. As for the blackmail and war starting you probably couldn't do much with public tweets (nobody is going to go to war over a tweet without fact checking it) but access to private messages is an entirely different story.

> As for the blackmail and war starting you probably couldn't do much with public tweets Depends how tense the situation already was. A well-timed tweet could be enough to tip things over the edge if both sides were already on the edge, and I don't think we're too far away from that.

Also remember that the soldiers themselves have twitter.

Those tweets can make them more itchy than they already are in a tense situation and nervous persons make more mistakes.

Re: Who’s behind Wednesday’s epic Twitter hack?

#424
post #162

Earlier quoted context omitted.

That didn't get disseminated and diffused to tens of millions. If something was published they'd look for official sources or corroborating sources and or secondary evidence. If AP, EFE, UPI, Kyodo, Interfax etc all get their news from one source [Twitter] that's just laziness.

Agreed but I said "apart from scale and reach". The point I was trying to make was that people have always found it fairly easy to believe non-credible sources. In this sense, social media is not qualitatively different. Only quantitatively different.

A large quantitative change is indistinguishable from a qualitative change: what's the difference between light rain and a flood, between some small waves and a tsunami?

Re: Who’s behind Wednesday’s epic Twitter hack?

#425
post #283

Earlier quoted context omitted.

If this indeed had happened, I wonder how it would have played out. It would not be pretty, that is for sure.

Well let’s see...since all countries with ICBMs also have technology in place to detect or verify via satellite a nuclear launch, absolutely nothing would happen. If a real launch had taken place, they would have known about it far before they heard about a post on Twitter. The alarmism here on HN is really disappointing. This is the kind of foolishness usually reserved for Reddit.

> since all countries with ICBMs also have technology in place to detect or verify via satellite a nuclear launch

It's lucky that those kinds of things never go wron...

"On 26 September 1983, the nuclear early-warning system of the Soviet Union reported the launch of multiple intercontinental ballistic missiles from bases in the United States."

...oh.

https://en.wikipedia.org/wiki/1983_Soviet_nuclear_false_alar...

Re: Who’s behind Wednesday’s epic Twitter hack?

#426

I don’t really think he should be naming who his unnamed sources “think” is behind an attack on this scale, especially with full name, city of origin, Instagram, suggested current location, age, etc. It feels a very, very small step away from doxxing to me. Added to which he has somebody in the comments essentially calling for the death penalty over this. If he has this personal information and evidence, pass it to t…

There is also a link in the comments on that page to a very comprehensive doxxing of j0e and his family members.

Re: Who’s behind Wednesday’s epic Twitter hack?

#427

Earlier quoted context omitted.

Here's how I think it could be done: Get Trump's account, and tweet something like, "I've ordered a NUCLEAR STRIKE on China! The missiles are already in the air. The DEEP STATE is trying to take me out. They will try to silence me and delete these tweets and use deep fakes to say this was a hoax! The storm is here, Q is real, it's time to take up arms and kill democrats." Then continue tweeting escalating things over…

Not to mention hijacking other accounts that would plausibly say things along the same lines as "proof" that the statement is real. Even after dozens of high profile accounts were hacked many were still commenting that they didn't think it was possible for it to be a twitter vulnerability, but rather individual accounts being compromised or a 3rd party. If you only tweeted plausible things about war and corroborated…

Considering that they got Obama's account as well, you could very well create a narrative and counter narrative using the POTUS and ex-POTUS accounts. For the sake of fiction, you could have Obama tweet that he is, indeed, taking over, and arresting Trump. Maybe not war, but it could exacerbate the lack of trust across political divides.

Re: Who’s behind Wednesday’s epic Twitter hack?

#428

Earlier quoted context omitted.

It's almost as if web services that let people post whatever they want at any time, vulnerable to whatever security flaws may be present, shouldn't be used as a reliable source for up-to-the-minute information about literally anything important at all.

This. We've entered a world where the lowest common denominator of information is being used as primary source for current events. That's asinine.

>is being used as primary source for current events

Is it though? According to Pew, only 20% of US adults use Twitter: https://www.pewresearch.org/fact-tank/2019/04/10/share-of-u-...

In comparison, Fox news is used as a source by 40% of the US population: https://www.pewresearch.org/fact-tank/2020/04/08/five-facts-...

The share is bigger for Facebook, though (69%)

Re: Who’s behind Wednesday’s epic Twitter hack?

#429

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

Or maybe it could be seen as a helpful reminder for idiots to not act based on a single source. If some guy on the stock market sells millions of dollar's worth of stock based on a single Tweet, they deserve the consequences.

Re: Who’s behind Wednesday’s epic Twitter hack?

#430
post #184

Earlier quoted context omitted.

>If Krebs got it wrong, well, he can suffer the consequences of that, too. And, if he got it wrong, the innocent person he doxxed has to suffer the (potentially much more harsh) consequences of someone else's irresponsible actions. While Krebs begins working on his next story, and if we're lucky, posts an "oopsie" comment. How can you justify that as okay?

Do you think Krebs got it wrong? But regardless, harassment is harassment. If the public starts harassing the dude, even if he is guilty, they're just as guilty of their own offenses. Two wrongs don't make a right.

He has in the past, and his response has been to delete the tweets but not offer an apology, or retraction. So when those tweets are re-posted, and/or screenshotted, there is no way to tell that the information is incorrect.
Post reply on HN