Live data from Hacker News

An update on our security incident

blog.twitter.com

41–50 of 308 posts

Re: An update on our security incident

#41

So the photos going around showing they have detrending tools might be real? Is it ethically acceptable that they “curate” what is trending? (Edit: I was actually asking, but apparently got my answer) Edit: I didn’t believe it when I saw people claiming those pictures were being deleted when posted by to twitter, but verge confirms they’re real. Trends blacklist and search blacklist. Didn’t Jack testify to Congress t…

These blacklist tags are "not new"* and are, for the most part, a necessary moderation tool to keep explicit and/or harmful content from trending.

Now, is this potentially something that could be abused to truly curate away ("censor") content from individuals, particularly conservatives, posting in good faith? Sure. It could.

But let's think about this -- if Twitter didn't have these tools in place, there are plenty of bad-faith actors who would constantly push profane and/or derogatory memes up into the realm of trending content. To me, preventing such content from trending is a necessary part of the service Twitter operates.

The unfortunate fact of the "profane" that there is no broad consensus around what is and isn't offensive. This means that Twitter will naturally step on toes in the process of keeping their platform friendly to the masses. I honestly don't see a way around it, and I far prefer a world where more people feel comfortable than the kinds of content I see on, cough, alternative "free speech" forums. But maybe that's just me.

* source: https://www.vice.com/en_us/article/n7wdxd/twitter-blacklists...

Re: An update on our security incident

#42
post #26

> For 45 of those accounts, the attackers were able to initiate a password reset, login to the account, and send Tweets How did they initiate a password reset and successfully reset the password to login to the account? They must've had the owners' email passwords too? EDIT: So they changed the mail associated to the accounts to their own... but the system didnt email out to "old" email to notify them of the action b…

As I understand it, the internal tools allow for changing the email. Change email -> password reset.

If this is true then it completely defeats the purpose of a two-factor authentication

Re: An update on our security incident

#43
post #9

> did the attackers see any of my private information? For the vast majority of people, we believe the answer is, no. This is such a weasel-y answer. “Yes, most of Earth’s population was not affected by this breach” - sure, but those that were affected, how would you be certain that they didn’t have their private information, such as DMs, pulled?

That's kind of a cynical take. I parsed that statement as saying:

> did the attackers see any of my private information? For the vast majority of people [who we previously mentioned were affected by this hack], we believe the answer is, no.

Re: An update on our security incident

#44
Is there any information on whether a single employee or a number of employees were involved? I don't think the attackers could have had someone hired at Twitter Support only to carry out this attack, given how they tried to monetize. Also I suspect no more than one employee was involved, and that "social engineering" was done only to compromise their credentials, instead of asking them nicely to allow them access to multiple (130) popular accounts.

Re: An update on our security incident

#45

> Attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack. They so carefully avoiding mentioning how they do store passwords that I have to wonder what their security practices are on that front (and the rest). What tools are they available under? You'd think they would've said "passwords are hashed and salted" to rule it out…

Not really, this document is clearly intended for a general public audience (They define the term "social engineering" after all). I don't think its surprising they didn't go into the details of which algorithms they use on old passwords

Re: An update on our security incident

#46
Uhhhh....

> Attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack.

Does this mean _current passwords ARE stored in plain text_??

IF this is the case, chances are it's because plaintext passwords more straightforward remediation and (statistically significantly) lower support times/costs. The convenience of this cannot be understated. BUT:

- Twitter just leaked that current passwords are stored in plain text

- Twitter just leaked that current passwords can be viewed by support tools used by employees susceptible to social engineering

Again, IF this is true, it's a lesson about the privacy and security risks ever-more-frequently associated with convenience (in this case internal convenience).

Re: An update on our security incident

#47

> on Wednesday, July 15, 2020, we detected a security incident at Twitter and took immediate action. > We became aware of the attackers’ action on Wednesday No mention of how they detected the incident or what alerted them to the attackers' action?

The fact it was world news was probably their first hint.

Re: An update on our security incident

#48

> Attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack. They so carefully avoiding mentioning how they do store passwords that I have to wonder what their security practices are on that front (and the rest). What tools are they available under? You'd think they would've said "passwords are hashed and salted" to rule it out…

It also sounds like they may keep old passwords?

Re: An update on our security incident

#49
> 2FA compromised

This is why sending or generating a OTP, that the user types in, is not secure. The user can be tricked into handing the OTP over the phone. Even the O365 system isn't secure (because the user can be told which number to tap over the phone).

The only secure authentication these days is a non-communicable possession: Yubikey or similar. This reflects *very poorly on Twitter opsec.

Post reply on HN