Live data from Hacker News

An update on our security incident

blog.twitter.com

21–30 of 308 posts

Re: An update on our security incident

#21
I wonder if ZeroHedge prediction might end being accurate:

That attackers probably would get most of their profits from blackmailing people because of their DMs.

I had hoped the hack was just API abuse to tweet in someone's name, not an actual account takeover, this introduce a whole lot of issues (including the fact some world powers use twitter... ever thought what would have happened if they had hijacked Trump's and Khamenei's accounts and started to give plausible threats to each other?)

Re: An update on our security incident

#22

> Attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack. They so carefully avoiding mentioning how they do store passwords that I have to wonder what their security practices are on that front (and the rest). What tools are they available under? You'd think they would've said "passwords are hashed and salted" to rule it out…

In some old articles it was mentioned they used Bcrypt. Not sure if that has changed. Not so many new algos are proven to be good.

Re: An update on our security incident

#23

> Attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack. They so carefully avoiding mentioning how they do store passwords that I have to wonder what their security practices are on that front (and the rest). What tools are they available under? You'd think they would've said "passwords are hashed and salted" to rule it out…

> "passwords are hashed and salted"

Means something to you and me, but means nothing to the average Twitter user who is the audience for this blog post.

Re: An update on our security incident

#25

> For 45 of those accounts, the attackers were able to initiate a password reset, login to the account, and send Tweets How did they initiate a password reset and successfully reset the password to login to the account? They must've had the owners' email passwords too? EDIT: So they changed the mail associated to the accounts to their own... but the system didnt email out to "old" email to notify them of the action b…

They changed the email addresses first to an account they controlled.

Re: An update on our security incident

#26

> For 45 of those accounts, the attackers were able to initiate a password reset, login to the account, and send Tweets How did they initiate a password reset and successfully reset the password to login to the account? They must've had the owners' email passwords too? EDIT: So they changed the mail associated to the accounts to their own... but the system didnt email out to "old" email to notify them of the action b…

As I understand it, the internal tools allow for changing the email. Change email -> password reset.

Re: An update on our security incident

#27

>For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account’s information through our “Your Twitter Data” tool. Yikes. Pretty much a confirmation of the speculation that the hackers would have access to Twitter DMs. Question is, which accounts? edit: For reference, here's what's included in the "Your Twitter Data" tool [0]. There's some other info that may be o…

> There is a lot speculation about the identity of these 8 accounts. We will only disclose this to the impacted accounts, however to address some of the speculation: none of the eight were Verified accounts.[0]

[0]: https://twitter.com/TwitterSupport/status/128433914877449830...

Re: An update on our security incident

#28

> For 45 of those accounts, the attackers were able to initiate a password reset, login to the account, and send Tweets How did they initiate a password reset and successfully reset the password to login to the account? They must've had the owners' email passwords too? EDIT: So they changed the mail associated to the accounts to their own... but the system didnt email out to "old" email to notify them of the action b…

[deleted]

Re: An update on our security incident

#29

So the photos going around showing they have detrending tools might be real? Is it ethically acceptable that they “curate” what is trending? (Edit: I was actually asking, but apparently got my answer) Edit: I didn’t believe it when I saw people claiming those pictures were being deleted when posted by to twitter, but verge confirms they’re real. Trends blacklist and search blacklist. Didn’t Jack testify to Congress t…

There has to be a trend manipulation option, otherwise the trending algorithm sooner or later will become a liability. What social media giants lack is transparency about when, why and how are trends manipulated. Transparency is also a liability for their business model.

Re: An update on our security incident

#30

> For 45 of those accounts, the attackers were able to initiate a password reset, login to the account, and send Tweets How did they initiate a password reset and successfully reset the password to login to the account? They must've had the owners' email passwords too? EDIT: So they changed the mail associated to the accounts to their own... but the system didnt email out to "old" email to notify them of the action b…

I'd assume they had the ability to change the email on the account.
Post reply on HN