Live data from Hacker News

An update on our security incident

blog.twitter.com

61–70 of 308 posts

Re: An update on our security incident

#61
post #46

Uhhhh.... > Attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack. Does this mean _current passwords ARE stored in plain text_?? IF this is the case, chances are it's because plaintext passwords more straightforward remediation and (statistically significantly) lower support times/costs. The convenience of this cannot be und…

They mean "previous" as in before the hackers did the password resets. (So all your passwords, except the one the hackers set.)

I don't think this implies a problem with "your current password" security, just that you don't care if the hackers have the password that they set themselves (and clearly already know then).

Re: An update on our security incident

#62

Is there any information on whether a single employee or a number of employees were involved? I don't think the attackers could have had someone hired at Twitter Support only to carry out this attack, given how they tried to monetize. Also I suspect no more than one employee was involved, and that "social engineering" was done only to compromise their credentials, instead of asking them nicely to allow them access to…

Some of the people involved were interviewed by the New York Times [0] and indicated that the person who was offering access claimed they managed to get into the Twitter Slack account and saw credentials being shared. I don’t know if that is true or not, but all the external reporting doesn’t indicate that a Twitter employee was actively involved. It’s always possible someone was, but given the small amount of money made and the goal of the hackers themselves (OG accounts), it strikes me as unlikely. I would assume that any engineer with access to those types of systems would want to sell out for more than a tiny amount of crypto to some script kiddies on Discord, but you never know.

[0]: https://www.nytimes.com/2020/07/17/technology/twitter-hacker...

Re: An update on our security incident

#63
post #49

> 2FA compromised This is why sending or generating a OTP, that the user types in, is not secure. The user can be tricked into handing the OTP over the phone. Even the O365 system isn't secure (because the user can be told which number to tap over the phone). The only secure authentication these days is a non-communicable possession: Yubikey or similar. This reflects *very poorly on Twitter opsec.

very poorly is a bit much. Yes yubikey would be much better, but its not exactly standard across the industry yet.

For something to reflect very poorly on twitter opsec, I would expect it to be something that is below what the average tech company was doing. e.g. There was some news article claiming [Without a whole lot of evidence] that the compromised tool used a shared password that was posted as the topic of a slack channel. Now if that was actually true, I think that would fit the description of "very poor" opsec.

Re: An update on our security incident

#64

Earlier quoted context omitted.

>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…

I think the hackers were going after OG accounts that were single, two-character, or common first name usernames. Many OG accounts aren’t verified.

Why would anyone care about the DM history of OG accounts? I believe that it is more likely to be politically motivated.

Re: An update on our security incident

#65
post #60

>For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account’s information through our “Your Twitter Data” tool. Yikes. Pretty much a confirmation of the speculation that the hackers would have access to Twitter DMs. Question is, which accounts? edit: For reference, here's what's included in the "Your Twitter Data" tool [0]. There's some other info that may be o…

Here's my suspicions. I may well be wrong, but this is what it feels like... I was wondering what kind of thing some actors (possibly state-based) were going to do this election cycle since the 2016 one (hacks of Republican and Democratic emails) worked so darn well. Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. And there's no big reason to think that the exfiltration of privat…

> Exfiltrating DMs seems like it's going to accomplish just about as much, if not more.

Nobody is communicating anything valuable over Twitter. This is such a ridiculous point that people bring up all the time. Scandalous relationships? Most of that will be on true messenger applications. Business deals? Business email. Many more mainstream prominent people don't even run their own account.

It's not that everyone is so security-minded, it's just that Twitter is an extremely inconvenient way to maintain personal relationships.

> I think the Bitcoin scam was also the perfect innocuous cover story

There is almost no value in DMs. Funny seeing HN speculate about these elite hackers selling them as if there's any market for them, let alone one that would pay $100k+.

Re: An update on our security incident

#67
post #4

I wish they mentioned what kind of social engineering attack it was. It could be a case study for any such incidents in the future. P.S. I feel bad for the employees who were manipulated to give away the info.

I want to know how they social engineered an employee at a 2FA-enabled company into bypassing 2FA.

Was the employee able to disable 2FA for their own account?

Was the employee social engineered into adding someone else's 2FA key to their account?

Did the employee read a 2FA code to the attacker, and that somehow enabled all the evil things the attacker did, without any additional checks or 2FA codes?

Did the attacker hack the employee's system and MITM their 2FA code without their knowledge? It doesn't sound like it, because that wouldn't be social engineering.

Re: An update on our security incident

#68

So the photos going around showing they have detrending tools might be real? Is it ethically acceptable that they “curate” what is trending? (Edit: I was actually asking, but apparently got my answer) Edit: I didn’t believe it when I saw people claiming those pictures were being deleted when posted by to twitter, but verge confirms they’re real. Trends blacklist and search blacklist. Didn’t Jack testify to Congress t…

Of course they’d have to. Regardless of all the cries about free speech, people will instantly turn against Twitter when, say, 4chan gets #paedophiles trending.

Re: An update on our security incident

#69

Earlier quoted context omitted.

From what I saw most of the “famous” accounts are surely run by PR teams. I doubt Obama has touched the Obama account let alone DM’ed Jesse Jackson some Trump memes. But I guess it’s entirely possible that people put sensitive things in DMs and inexplicably just trusted Twitter with that info.

I think it likely varies on the person we're talking about. Is Obama personally tweeting and sending private memes in his DMs? Doubtful. Kanye or Elon Musk? I'd guess yes, actually.

Kanye West and Elon Musk have absolutely nothing of value in their DMs. Anything you could do with access to Musk's DMs you could do better just by tweeting as Musk.

There is no value in Twitter DMs.

Re: An update on our security incident

#70
post #65
post #60

Earlier quoted context omitted.

Here's my suspicions. I may well be wrong, but this is what it feels like... I was wondering what kind of thing some actors (possibly state-based) were going to do this election cycle since the 2016 one (hacks of Republican and Democratic emails) worked so darn well. Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. And there's no big reason to think that the exfiltration of privat…

> Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. Nobody is communicating anything valuable over Twitter. This is such a ridiculous point that people bring up all the time. Scandalous relationships? Most of that will be on true messenger applications. Business deals? Business email. Many more mainstream prominent people don't even run their own account. It's not that everyone is…

99.9% of the email hacks was uninteresting. 0.1% was nothingburger. That wouldn’t stop it from dominating in the media, especially with a trickle feed strategy. Google the whole ‘Spirit Cooking’ thing as a good example. Completely nothing. 0% interesting. Stupid enough to be idle Twitter DM chat. Did it hit the media just before the election and blow up? Yup.
Post reply on HN