Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

491–500 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#491
post #200

I'm sure it's been said before, but I just continue to be surprised that the admin panel used to carry out this attack wasn't locked behind a VPN. I've worked for multiple fully-remote companies that were easily able to protect tools like this from the outside world. The company I currently work for (fully remote) has tons of internal services that our engineers (who we trust) can access as needed in order to debug p…

Internal networks only accessible via VPN is considered an anti-pattern now in terms of security. It puts authorization firmly on the VPN. If the account with VPN access is compromised, then the attacker has full access to these sensitive systems. This hack probably underscores the importance of zero trust. Although if the system is compromised from within (like this hack is) then there is not much you can do.

It's not an anti-pattern though.

It's a part of security, along with other multi-faceted authentication routes.

Re: Who’s behind Wednesday’s epic Twitter hack?

#492

Earlier quoted context omitted.

If the "layers" of your security use the same factors are they really layers or are they simply a time sink for you permitted users, and another thing to break? My visceral reaction was "you got to have a VPN" as well but the more I thought about it the more I was convinced you don't _need_ a VPN.

If your only threat model is leaked credentials and not vulnerabilities, sure.

Or if your threat model accounts for the prevalence of stolen credentials and end-point compromise vs. the vulnerability of your exposed application attack surface.

Re: Who’s behind Wednesday’s epic Twitter hack?

#493

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

It's almost as if web services that let people post whatever they want at any time, vulnerable to whatever security flaws may be present, shouldn't be used as a reliable source for up-to-the-minute information about literally anything important at all.

Nay, Sir, our brave corporations that regularly sell themselves out to low-cost labour markets will surely defend democracy here and around the world when we call upon them!

Not.

Re: Who’s behind Wednesday’s epic Twitter hack?

#494

Earlier quoted context omitted.

It's not one step away from doxxing at all -- in this case Lucky225 is not an unnamed source, that is actually his real legal name per his twitter [1] and the FCC database entry for his ham radio license (not linking that) [1] https://twitter.com/lucky225/status/1258503072323526657

Well, I think they meant doxxing Joe, but also seems to be doxxing Lucky225 as you noted. Once you look at Lucky225's Ham then you get an address. Of course, what is somewhat interesting is their listed address actually is located at Colorado's Division of Central Services building, which very interestingly is a way to obtain a confidential mail forwarding address. It says it is only to be used by victims of stalking…

> Either way, I think SexyCyborg (well-known Maker) is quite right to call out HAM license as a vector for getting doxxed.

The ham license process itself is the doxxing, not a vector to it. The FCC is the one doing the public publishing of identifying information.

Re: Who’s behind Wednesday’s epic Twitter hack?

#495

Earlier quoted context omitted.

A US president has the power to unilaterally launch the nuclear arsenal: https://allthingsnuclear.org/dwright/trump-and-the-nuclear-c... Whether the military would actually carry out those orders when no one else has ICBMs in the air is debatable, but the president's defined role as the commander-in-chief and the sole arbiter of when to open the gates of hell on earth is not.

> Whether the military would actually carry out those orders when no one else has ICBMs in the air is debatable It's not merely debatable, it's highly debatable. People aren't just going to launch nuclear weapons willy nilly, no matter who the president is, muchless for Donald J. Trump, who few people in his administration take seriously. Trump couldn't even get Mark Esper to deploy troops domestically. Now imagine t…

I hope Trump wouldn't actually be able to nuke anyone while throwing a fit, and I think it's unlikely that he could.

It is important to remember how the US launch system actually works, though, and that it's theoretically possible he could.

Re: Who’s behind Wednesday’s epic Twitter hack?

#496
post #477

Earlier quoted context omitted.

What about the internet-using population? Supposedly only 60% of the world uses the internet whereas almost all of the US population does https://www.statista.com/statistics/617136/digital-populatio...

250 million non-US users to 4.3 billion Internet users (excluding the US) is about 5.8%. Compared that to 23% in the US. Twitter is very US-centric.

If Twitter is 20% American users, how can that be considered "US-centric?" The vast majority of Twitter's users are not in the US...

Re: Who’s behind Wednesday’s epic Twitter hack?

#497

This is the most important point: > Also, it seems clear that this Twitter hack could have let the attackers view the direct messages of anyone on Twitter, information that is difficult to put a price on but which nevertheless would be of great interest to a variety of parties, from nation states to corporate spies and blackmailers. My understanding is the hackers used the admin panel to change the email addresses of…

>> Also, it seems clear that this Twitter hack could have let the attackers view the direct messages of anyone on Twitter, information that is difficult to put a price on but which nevertheless would be of great interest to a variety of parties, from nation states to corporate spies and blackmailers. It is not as much money as pundits probably think it is worth. And also, trying to negotiate a blackmail is time consu…

The thief did not appear to be too sophisticated. Obviously sophisticated enough to pull off the twitter hack, but we don't really know how much sophistication that required just yet (the exploit may have been trivial). But, they didn't disseminate this message anywhere other than twitter? That seems very shortsighted.

They used different approaches on different twitter accounts, some suggested a coin return, others suggested a charitable donation match, etc. But, they all used the same bitcoin address. If they were sophisticated, they would have used a different bitcoin address for each to evaluate the more profitable messages for a future scam.

Re: Who’s behind Wednesday’s epic Twitter hack?

#498

Earlier quoted context omitted.

If you're already logged in to a Twitter account you can deactivate 2FA by disabling the account (aka deleting with a 30 day window) and then re-enabling the account.

You don't need 2FA to deactivate 2FA? That seems like a big flaw.

Yup. The interesting thing is that this 2FA exploit was posted to hacker news two days before the twitter hack. It's possible someone seized the opportunity before it was fixed.

Re: Who’s behind Wednesday’s epic Twitter hack?

#499

Earlier quoted context omitted.

>If Krebs got it wrong, well, he can suffer the consequences of that, too. And, if he got it wrong, the innocent person he doxxed has to suffer the (potentially much more harsh) consequences of someone else's irresponsible actions. While Krebs begins working on his next story, and if we're lucky, posts an "oopsie" comment. How can you justify that as okay?

If you believe the story, the people who are pointed to were already being looked for for arrest. Don't buy the poor innocent narrative too quickly. It just happens that their last actions affected powerful figures and the US government so they might actually be some real international effort to arrest them now.

What I stated is not exclusive to this story.

People's home addresses and names should not be released to the public until a legal conviction has been ascertained. This has nothing to do with "innocent narrative". It has everything to do with due process, which is a foundation many countries entire law systems are founded upon.

The legal process is innocent until proven guilty. You seem to be advocating for guilty until proven innocent, with a side of public vigilante justice as the punishment.

If doxxing innocent (reminder: you are innocent until /proven/ guilty) people is the norm... And allowing vigilante justice is okay... We are in a very dangerous place.

You don't have to look far for numerous cases of innocent people having their lives ruined, or sometimes literally snuffed out, due to situations exactly like this.

Re: Who’s behind Wednesday’s epic Twitter hack?

#500

Earlier quoted context omitted.

He is one of the more peaceful presidents. This is ridiculous, there is ample room for criticism against Trump. This wouldn't fit at all. I guess you can blame him on Turkeys reaction in Syria, his staunch anti-Iranian policies that made talks more difficult. But the criticism of him starting random wars comes from an emotional corner beyond reality in my opinion.

It's ironic that our kids in the future reading wikipedia there will be a table of numbers killed overseas by US presidents. Trump will be listed as one of the most peaceful in that table. It's ironic because his image today is of violence and instability and that the opponents of him don't consider violence overseas or international peace as that important. It's things happening at home which counts politically in a…

I looked it up and from what I could tell, drone strkes are actually up under Trump. I thought they were down, but looks like they just not being reported as much.
Post reply on HN