Live data from Hacker News

An update on our security incident

blog.twitter.com

31–40 of 308 posts

Re: An update on our security incident

#31

How did they manipulate their employees? that's the most important part don't you think?

Absolutely! Insofar as a post mortem will help others avoid the same fate, understanding the specifics of the social engineering hack is by far the most useful information they could share about what happened. My guess is that they won't because either a) they are lying about this being the underlying cause, or b) it is itself too sensitive to reveal (either about the company or the targeted individuals).

Re: An update on our security incident

#32

So the photos going around showing they have detrending tools might be real? Is it ethically acceptable that they “curate” what is trending? (Edit: I was actually asking, but apparently got my answer) Edit: I didn’t believe it when I saw people claiming those pictures were being deleted when posted by to twitter, but verge confirms they’re real. Trends blacklist and search blacklist. Didn’t Jack testify to Congress t…

I haven’t seen this, do you have a link?

Can't tell which part you mean by "this." The pictures, or the Jack testimony.

You have one of the best usernames ever btw.

Re: An update on our security incident

#33
I will use this as an ugly reminder that it's better to assume that any DMs could be public at any moment.

I don't subscribe to the "nothing to fear, if you have nothing to hide", I had conversations that are not illegal, lewd or even non-politically correct jokes, but would still hate to made public by a 3rd entity; from secrets that were shared by friends, to sensitive data like addresses, or information with clients with NDAs.

Re: An update on our security incident

#35

> For 45 of those accounts, the attackers were able to initiate a password reset, login to the account, and send Tweets How did they initiate a password reset and successfully reset the password to login to the account? They must've had the owners' email passwords too? EDIT: So they changed the mail associated to the accounts to their own... but the system didnt email out to "old" email to notify them of the action b…

[deleted]

Re: An update on our security incident

#37

>For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account’s information through our “Your Twitter Data” tool. Yikes. Pretty much a confirmation of the speculation that the hackers would have access to Twitter DMs. Question is, which accounts? edit: For reference, here's what's included in the "Your Twitter Data" tool [0]. There's some other info that may be o…

> There is a lot speculation about the identity of these 8 accounts. We will only disclose this to the impacted accounts, however to address some of the speculation: none of the eight were Verified accounts.[0] [0]: https://twitter.com/TwitterSupport/status/128433914877449830...

>none of the eight were Verified accounts.

That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them picking solely non-verifieds.

Re: An update on our security incident

#39
> on Wednesday, July 15, 2020, we detected a security incident at Twitter and took immediate action.

> We became aware of the attackers’ action on Wednesday

No mention of how they detected the incident or what alerted them to the attackers' action?

Re: An update on our security incident

#40

Earlier quoted context omitted.

> There is a lot speculation about the identity of these 8 accounts. We will only disclose this to the impacted accounts, however to address some of the speculation: none of the eight were Verified accounts.[0] [0]: https://twitter.com/TwitterSupport/status/128433914877449830...

>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…

Someone pointed out that it could be targeted at activists...
Post reply on HN