Live data from Hacker News

An update on our security incident

blog.twitter.com

101–110 of 308 posts

Re: An update on our security incident

#101

Is there any information on whether a single employee or a number of employees were involved? I don't think the attackers could have had someone hired at Twitter Support only to carry out this attack, given how they tried to monetize. Also I suspect no more than one employee was involved, and that "social engineering" was done only to compromise their credentials, instead of asking them nicely to allow them access to…

Some of the people involved were interviewed by the New York Times [0] and indicated that the person who was offering access claimed they managed to get into the Twitter Slack account and saw credentials being shared. I don’t know if that is true or not, but all the external reporting doesn’t indicate that a Twitter employee was actively involved. It’s always possible someone was, but given the small amount of money…

> all the external reporting doesn’t indicate that a Twitter employee was actively involved

Joseph Cox at Vice Motherboard is claiming exactly that from his interview with the hackers:

"We used a rep that literally done all the work for us," one of the sources told Motherboard. The second source added they paid the Twitter insider. Motherboard granted the sources anonymity to speak candidly about a security incident. A Twitter spokesperson told Motherboard that the company is still investigating whether the employee hijacked the accounts themselves or gave hackers access to the tool.

https://www.vice.com/en_us/article/jgxd3d/twitter-insider-ac...

Re: An update on our security incident

#102

How did they manipulate their employees? that's the most important part don't you think?

In an interview with the hacker by Vice Motherboard, they claimed they had an employee on the inside doing all the work, and they just paid the employee to do it: https://www.vice.com/en_us/article/jgxd3d/twitter-insider-ac...

I just don't buy it. This guy or girl managed to get a job at Twitter but was willing to sell access to underground hackers for a bit of extra cash and expected no blowback? When the hackers were instructing the employee to post these tweets on behalf of Barack Obama and Joe Biden, did the employee not wonder if this could go wrong for him?

Re: An update on our security incident

#103

> Attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack. They so carefully avoiding mentioning how they do store passwords that I have to wonder what their security practices are on that front (and the rest). What tools are they available under? You'd think they would've said "passwords are hashed and salted" to rule it out…

> "passwords are hashed and salted" Means something to you and me, but means nothing to the average Twitter user who is the audience for this blog post.

"plain text" is also a technical term.

Ask the average joe what it means for something to be in "plain text" and you'd probably get the answer "Oh that's simple, they didn't write it out in cursive!"

Re: An update on our security incident

#104

Earlier quoted context omitted.

I think the hackers were going after OG accounts that were single, two-character, or common first name usernames. Many OG accounts aren’t verified.

Why would anyone care about the DM history of OG accounts? I believe that it is more likely to be politically motivated.

I could imagine a teenage hacker downloading his friend's or enemy's DMs. People the hacker knows in real life may be more interesting for him.

Re: An update on our security incident

#105
What a joke of a company. They literally have done nothing in terms of building innovative products in the past 7 yrs since IPO and their monthly active users is static. And then, to distract away from their poor product roadmap, they take controversial political stands - but which don't result in any major impact given mostly bots and celebrities use that platform. And now this.

Keep in mind, some 4k employees work in this jungle. Don't know what they do apart from just tweeting #lovewhereyouwork

Re: An update on our security incident

#106
post #22

Earlier quoted context omitted.

In some old articles it was mentioned they used Bcrypt. Not sure if that has changed. Not so many new algos are proven to be good.

As long as they’re continually bumping the work factor it should be good for now.

If passwords are peppered as well as salted, is the bcrypt work factor a factor?

Re: An update on our security incident

#107
post #81

Earlier quoted context omitted.

I don't mean this in any kind of condescending way, but I honestly think you might be in a bubble. If I was only looking at my immediate friend group, I would think the same way, as none of them use Twitter DMs at all . However, I recently met up with some old acquaintances from high school, and they use Twitter DMs and Instagram DMs as one of their main methods of communication. There's a reason "slide into the DMs"…

Yes, introductions get made on Twitter, "slide into the DMs" does not mean that you're trying to conduct a three year romantic relationship on it. Usually people are going to get off it, and onto a real messenger application, even if they just want sex.

[deleted]

Re: An update on our security incident

#108

What a joke of a company. They literally have done nothing in terms of building innovative products in the past 7 yrs since IPO and their monthly active users is static. And then, to distract away from their poor product roadmap, they take controversial political stands - but which don't result in any major impact given mostly bots and celebrities use that platform. And now this. Keep in mind, some 4k employees work…

> In 2009, an 18-year-old hacker from the US managed to gain access to Twitter’s back-end systems by targeting a member of the company’s support staff

https://decrypt.co/35911/6-times-twitters-security-was-breac...

Re: An update on our security incident

#109
We need the guys at CMU (who also operate CERT) to engineer a replacement and setup a program for interns to operate it as a private non-profit for the rest of time.

The system that is out there now has been a running technological joke since it was (sort of) running on Windows and it would be My_ dust now if it weren't for the President who they now (rightly or wrongly) scorn. Some seriously bad things can (and probably are going to) happen to actual human beings because of that s*faced idiot phoning it in for way too long. He doesn't get to impact the democracy or influence the beating of other human beings hearts because he is not competent or careful enough to be trusted in such capacity.

Re: An update on our security incident

#110
post #86
post #73

Earlier quoted context omitted.

> Nobody is communicating anything valuable over Twitter. This is such a ridiculous point that people bring up all the time. Scandalous relationships? Most of that will be on true messenger applications. Business deals? Business email. Many more mainstream prominent people don't even run their own account. GP was talking about the 2016 election, where Julian Assange and Roger Stone literally communicated strategies,…

> On 4 October, 2016, Mr Stone tweeted: “Payload coming. #Lockthemup.” It was clear publicly that Stone had a very inappropriate relationship with Wikileaks. What would you do, attempt to extort Stone for more than $100k and hope he pays? Leak little more than was publicly known?

No, if you were a bad actor looking to cause chaos for a target, you would gather all such things and release it. Either way, that example disproves your claim that nothing sensitive would be discussed of Twitter DM's.
Post reply on HN