Live data from Hacker News

An update on our security incident

blog.twitter.com

11–20 of 308 posts

Re: An update on our security incident

#11

So the photos going around showing they have detrending tools might be real? Is it ethically acceptable that they “curate” what is trending? (Edit: I was actually asking, but apparently got my answer) Edit: I didn’t believe it when I saw people claiming those pictures were being deleted when posted by to twitter, but verge confirms they’re real. Trends blacklist and search blacklist. Didn’t Jack testify to Congress t…

I haven’t seen this, do you have a link?

Re: An update on our security incident

#12
> Attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack.

They so carefully avoiding mentioning how they do store passwords that I have to wonder what their security practices are on that front (and the rest). What tools are they available under? You'd think they would've said "passwords are hashed and salted" to rule it out entirely if that was a thing.

Re: An update on our security incident

#14

Earlier quoted context omitted.

From what I saw most of the “famous” accounts are surely run by PR teams. I doubt Obama has touched the Obama account let alone DM’ed Jesse Jackson some Trump memes. But I guess it’s entirely possible that people put sensitive things in DMs and inexplicably just trusted Twitter with that info.

I think it likely varies on the person we're talking about. Is Obama personally tweeting and sending private memes in his DMs? Doubtful. Kanye or Elon Musk? I'd guess yes, actually.

Ah, Elon, forgot about that one. I fully believe he runs his own twitter. How else is he going to control the stock market!? ;)

You’re right, I assume his would be one of the accounts that was exfil’ed

Re: An update on our security incident

#17
> For 45 of those accounts, the attackers were able to initiate a password reset, login to the account, and send Tweets

How did they initiate a password reset and successfully reset the password to login to the account? They must've had the owners' email passwords too? EDIT: So they changed the mail associated to the accounts to their own... but the system didnt email out to "old" email to notify them of the action being taken like most companies do?

Re: An update on our security incident

#18

> Attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack. They so carefully avoiding mentioning how they do store passwords that I have to wonder what their security practices are on that front (and the rest). What tools are they available under? You'd think they would've said "passwords are hashed and salted" to rule it out…

Wording is suspicious, you would assume they mean "they had no db access so they didn't see the hashed passwords". Hopefully it just wasn't completely thought out.

The only other reference to password storage efforts: https://blog.twitter.com/en_us/a/2013/keeping-our-users-secu...

> attackers may have had access to limited user information – usernames, email addresses, session tokens and encrypted/salted versions of passwords – for approximately 250,000 users.

Re: An update on our security incident

#19
post #13

It's still happening. I just saw this blue checkmark account linking to cryptocurrency scams only 2 hours ago: https://twitter.com/sephr/status/1284310424855343105

That’s a different scam that has been going on for years. They phish/crack random, usually inactive, verified accounts. And then they chance the display name / profile picture to Elon’s. Then they reply to his tweets with this message

Re: An update on our security incident

#20
post #13

It's still happening. I just saw this blue checkmark account linking to cryptocurrency scams only 2 hours ago: https://twitter.com/sephr/status/1284310424855343105

Those have been happening for a long time before this, and consist of taking over some some little-known verified account (presumably through phishing, password reuse, and other such conventional means), changeing the (non-unique) display name and profile picture to Elon Musk and doing some bitcoin scammery. The actual well-known accounts are unaffected.
Post reply on HN