Live data from Hacker News

An update on our security incident

blog.twitter.com

51–60 of 308 posts

Re: An update on our security incident

#51
post #26

Earlier quoted context omitted.

As I understand it, the internal tools allow for changing the email. Change email -> password reset.

If this is true then it completely defeats the purpose of a two-factor authentication

Almost all internet companies have internal tools to disable 2FA. People destroy/break/etc their phones constantly and need it reset.

2FA is meant to protect against someone impersonating you. It is not designed to protect against malicious insider at the org you are trying to prove your identity to

Re: An update on our security incident

#52
post #45

> Attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack. They so carefully avoiding mentioning how they do store passwords that I have to wonder what their security practices are on that front (and the rest). What tools are they available under? You'd think they would've said "passwords are hashed and salted" to rule it out…

Not really, this document is clearly intended for a general public audience (They define the term "social engineering" after all). I don't think its surprising they didn't go into the details of which algorithms they use on old passwords

They could've just said "...as this is not possible" or something like that. I wasn't suggesting they need to drop in acronyms like PBKDF2 or whatever. They go out of their way to say "through the tools used in the attack" which might as well imply there are other tools through which the passwords are available...

Re: An update on our security incident

#53
It’s interesting that the Your Data tool only started including DMs after GDPR stuff went into effect. For many years, DMs weren’t part of the archive. When the feature was added in late 2018 or early 2019, it became clear that Twitter actually maintained an archive of all DMs, whether you had previously deleted them or not.

I’m glad this was only 8 accounts — but it’s a good reminder that DMs aren’t encrypted or secure and shouldn’t be used that way.

Re: An update on our security incident

#54

How did they manipulate their employees? that's the most important part don't you think?

If I had to guess, likely textbook spear phishing. If they were able to get past 2FA, then either it was weak 2FA or they stole auth tokens, not passwords. In general that approach is unreasonably effective - at least single-digit percentage points of effectiveness.

Between that and just bribing support people (or they were in on it to begin with), you have the two of the most common attacks on user/customer data.

Re: An update on our security incident

#55
> As mentioned above, we are deliberately limiting the detail we share on our remediation steps at this time to protect their effectiveness and will provide more technical details, where possible, in the future.

With all due respect, I have no confidence in measures that aren’t transparent and open. They can share a lot of details without risking security, but by being vague about remediations, they’re being obscure, not secure.

If they posted their exact remediations (hiding sensitive parts like precise information needed to take control of an admin account or use it), they would have an entire world of security experts ready to critique their plans. Instead, we have to trust and hope they get it right the second time.

Re: An update on our security incident

#56

Earlier quoted context omitted.

> There is a lot speculation about the identity of these 8 accounts. We will only disclose this to the impacted accounts, however to address some of the speculation: none of the eight were Verified accounts.[0] [0]: https://twitter.com/TwitterSupport/status/128433914877449830...

>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…

I think the hackers were going after OG accounts that were single, two-character, or common first name usernames. Many OG accounts aren’t verified.

Re: An update on our security incident

#57
It would be helpful if Twitter supported the deletion of Direct Messages for all parties, as they do with public tweets. Right now, they just sit around in at least one party's inbox and accumulate, creating a valuable cache of private information.

(Twitter's implementation of Direct Messaging aligns more closely with instant messaging than email, therefore I believe a real deletion feature isn't an unreasonable expectation or ask.)

Re: An update on our security incident

#58

How did they manipulate their employees? that's the most important part don't you think?

I actually don't think it's as important as identifying how and why those employees were able to do things like tweet on behalf of Obama. Proper access controls would have high-profile accounts extremely locked down, ideally such that no single person could independently choose to access this info.

Re: An update on our security incident

#59
post #45

Earlier quoted context omitted.

Not really, this document is clearly intended for a general public audience (They define the term "social engineering" after all). I don't think its surprising they didn't go into the details of which algorithms they use on old passwords

They could've just said "...as this is not possible" or something like that. I wasn't suggesting they need to drop in acronyms like PBKDF2 or whatever. They go out of their way to say "through the tools used in the attack" which might as well imply there are other tools through which the passwords are available...

They said "those [passwords] are not stored in plain text or available through the tools used in the attack." - "Or" means both clauses are true.

I think it most likely means, the passwords are hashed, and the hashes aren't available in this tool. There's undoubtedly other tools that allow people to view the hash, (Mysql command line client is a "tool" after all ;) Although I agree the statement is ambiguous enough, that it could mean things that aren't best practise.

Re: An update on our security incident

#60

>For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account’s information through our “Your Twitter Data” tool. Yikes. Pretty much a confirmation of the speculation that the hackers would have access to Twitter DMs. Question is, which accounts? edit: For reference, here's what's included in the "Your Twitter Data" tool [0]. There's some other info that may be o…

Here's my suspicions. I may well be wrong, but this is what it feels like...

I was wondering what kind of thing some actors (possibly state-based) were going to do this election cycle since the 2016 one (hacks of Republican and Democratic emails) worked so darn well. Exfiltrating DMs seems like it's going to accomplish just about as much, if not more.

And there's no big reason to think that the exfiltration of private DMs was limited to the people that had the Bitcoin scam tweeted on their accounts.

I think the Bitcoin scam was also the perfect innocuous cover story - a legitimate motive that nevertheless leaves one with the impression that the operator is a pretty small fry. So many dismissals of it's a silly scamp wanting money but only got 12 BTC, next day's news please.

But it did put it out there so that the public (and the public needs to know to establish the credibility of the compromised data instantly, immediately, with no room for doubt) is aware a broad hack occurred, without even exposing who was targeted specifically and the BTC didn't matter one iota. Now they can trickle-feed what they actually got all the way until the election. Also, they don't care who'll win, just like the email hackers didn't in 2016. They just want to sow discord. Tweeting the same unrelated thing on so many accounts also sends the message that they're not on anyone's side.

The only reason I think Trump didn't have anything tweeted isn't because they particularly like him, but because it gives of the image of graver national security consequences.

Post reply on HN