Earlier quoted context omitted.
> Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. Nobody is communicating anything valuable over Twitter. This is such a ridiculous point that people bring up all the time. Scandalous relationships? Most of that will be on true messenger applications. Business deals? Business email. Many more mainstream prominent people don't even run their own account. It's not that everyone is…
I don't mean this in any kind of condescending way, but I honestly think you might be in a bubble. If I was only looking at my immediate friend group, I would think the same way, as none of them use Twitter DMs at all . However, I recently met up with some old acquaintances from high school, and they use Twitter DMs and Instagram DMs as one of their main methods of communication. There's a reason "slide into the DMs"…
An update on our security incident
81–90 of 308 posts
Re: An update on our security incident
#82Earlier quoted context omitted.
very poorly is a bit much. Yes yubikey would be much better, but its not exactly standard across the industry yet. For something to reflect very poorly on twitter opsec, I would expect it to be something that is below what the average tech company was doing. e.g. There was some news article claiming [Without a whole lot of evidence] that the compromised tool used a shared password that was posted as the topic of a sl…
Twitter is not an average company. As one of the top 40 internet companies, they are in the position of setting industry standards. I think it's fair to expect more than what the average company does from Twitter.
I personally have 3 Yubikeys, one on my keyring, one in my small first aid kit (which is kept in my backpack and usually close to me) and one that doesn't ever travel with me. We give our staff yubikeys and require them to use them for services where we have customer data (including logins to our own service).
And we support them for our customers to use, but mandating that all our customers have physical 2FA devices to protect their own accounts is still a bridge very much too far today.
Re: An update on our security incident
#83I wish they mentioned what kind of social engineering attack it was. It could be a case study for any such incidents in the future. P.S. I feel bad for the employees who were manipulated to give away the info.
I want to know how they social engineered an employee at a 2FA-enabled company into bypassing 2FA. Was the employee able to disable 2FA for their own account? Was the employee social engineered into adding someone else's 2FA key to their account? Did the employee read a 2FA code to the attacker, and that somehow enabled all the evil things the attacker did, without any additional checks or 2FA codes? Did the attacker…
Get employee's password
Call employee
"Hey [employee], I'm [coworker] from the security team and we noticed your DUO was locked. I just enabled it, but we want to make sure it works. Hit Approve when you get a notification."
Log in with password
Wait for employee to hit Approve.
Re: An update on our security incident
#84Earlier quoted context omitted.
I don't mean this in any kind of condescending way, but I honestly think you might be in a bubble. If I was only looking at my immediate friend group, I would think the same way, as none of them use Twitter DMs at all . However, I recently met up with some old acquaintances from high school, and they use Twitter DMs and Instagram DMs as one of their main methods of communication. There's a reason "slide into the DMs"…
Yes, introductions get made on Twitter, "slide into the DMs" does not mean that you're trying to conduct a three year romantic relationship on it. Usually people are going to get off it, and onto a real messenger application, even if they just want sex.
It's also worth mentioning that it's very common for companies and celebrities to use Twitter DMs as a sort of "customer support" where they specifically ask people to send them private information via DM. I've seen tweets from utility companies where they say "Please send us a DM with your account number and we will look into your issue" [0], for example. There's the possibility for valuable information there.
0: https://twitter.com/comcastcares/status/1284358479835258881
Re: An update on our security incident
#85Earlier quoted context omitted.
I think the hackers were going after OG accounts that were single, two-character, or common first name usernames. Many OG accounts aren’t verified.
Why would anyone care about the DM history of OG accounts? I believe that it is more likely to be politically motivated.
Re: An update on our security incident
#86Earlier quoted context omitted.
> Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. Nobody is communicating anything valuable over Twitter. This is such a ridiculous point that people bring up all the time. Scandalous relationships? Most of that will be on true messenger applications. Business deals? Business email. Many more mainstream prominent people don't even run their own account. It's not that everyone is…
> Nobody is communicating anything valuable over Twitter. This is such a ridiculous point that people bring up all the time. Scandalous relationships? Most of that will be on true messenger applications. Business deals? Business email. Many more mainstream prominent people don't even run their own account. GP was talking about the 2016 election, where Julian Assange and Roger Stone literally communicated strategies,…
It was clear publicly that Stone had a very inappropriate relationship with Wikileaks. What would you do, attempt to extort Stone for more than $100k and hope he pays? Leak little more than was publicly known?
Re: An update on our security incident
#87Earlier quoted context omitted.
I think the hackers were going after OG accounts that were single, two-character, or common first name usernames. Many OG accounts aren’t verified.
Why would anyone care about the DM history of OG accounts? I believe that it is more likely to be politically motivated.
Re: An update on our security incident
#88Uhhhh.... > Attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack. Does this mean _current passwords ARE stored in plain text_?? IF this is the case, chances are it's because plaintext passwords more straightforward remediation and (statistically significantly) lower support times/costs. The convenience of this cannot be und…
Re: An update on our security incident
#89> Attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack. They so carefully avoiding mentioning how they do store passwords that I have to wonder what their security practices are on that front (and the rest). What tools are they available under? You'd think they would've said "passwords are hashed and salted" to rule it out…
In some old articles it was mentioned they used Bcrypt. Not sure if that has changed. Not so many new algos are proven to be good.
Re: An update on our security incident
#90How did they manipulate their employees? that's the most important part don't you think?
For sure. And how did the hackers access the Twitter backend from an unknown IP? Surely Twitter has that locked down. My guess is the hackers managed to gain access to laptops of remote support staff and controlled them with Teamviewer type software. Going remote for covid might have made this all possible.