I think this is relevant here - https://m.youtube.com/watch?feature=emb_title&v=MjufyLPKsEw
An update on our security incident
111–120 of 308 posts
Re: An update on our security incident
#112I don’t understand the hubbub. It’s just a stupid messaging network. Not our emails that got hacked. I think this is relevant here - https://m.youtube.com/watch?feature=emb_title&v=MjufyLPKsEw
Re: An update on our security incident
#113Re: An update on our security incident
#114Re: An update on our security incident
#115Earlier quoted context omitted.
In an interview with the hacker by Vice Motherboard, they claimed they had an employee on the inside doing all the work, and they just paid the employee to do it: https://www.vice.com/en_us/article/jgxd3d/twitter-insider-ac...
I just don't buy it. This guy or girl managed to get a job at Twitter but was willing to sell access to underground hackers for a bit of extra cash and expected no blowback? When the hackers were instructing the employee to post these tweets on behalf of Barack Obama and Joe Biden, did the employee not wonder if this could go wrong for him?
Most people in jail didn't think or care about what could go wrong.
Re: An update on our security incident
#116Earlier quoted context omitted.
In an interview with the hacker by Vice Motherboard, they claimed they had an employee on the inside doing all the work, and they just paid the employee to do it: https://www.vice.com/en_us/article/jgxd3d/twitter-insider-ac...
I just don't buy it. This guy or girl managed to get a job at Twitter but was willing to sell access to underground hackers for a bit of extra cash and expected no blowback? When the hackers were instructing the employee to post these tweets on behalf of Barack Obama and Joe Biden, did the employee not wonder if this could go wrong for him?
The employee was likely a customer service rep. Incidents like this have happened before at Twitter, in 2017 a customer service rep at their San Francisco office deleted Trump's account:
https://www.abc.net.au/news/2017-12-01/trump-twitter-employe...
> When the hackers were instructing the employee to post these tweets...
The employee didn't post the tweets, their involvement was changing the email addresses on the accounts they were told to (which bypasses 2FA). The Krebs article shows screenshots of the Twitter customer support dashboard for an account:
https://krebsonsecurity.com/2020/07/whos-behind-wednesdays-e...
Re: An update on our security incident
#117Earlier quoted context omitted.
>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…
This is by far the most eyebrow-raising part of the update. To take over such a large number of verified accounts and then run a download on only eight non-verified ones seems almost impossible to have been anything other than targeted. The original idea that the bitcoin scam was a diversion starts to look more plausible in this light, but in the absence of any information about the downloaded accounts, there’s reall…
Re: An update on our security incident
#118>For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account’s information through our “Your Twitter Data” tool. Yikes. Pretty much a confirmation of the speculation that the hackers would have access to Twitter DMs. Question is, which accounts? edit: For reference, here's what's included in the "Your Twitter Data" tool [0]. There's some other info that may be o…
- "Download all my data" was mandated by GDPR (article 20)
- Right to delete, right to access made it so that there is up to a ten million dollar fine if you refuse it, so you are more prone to social engineering attacks. Meaning if some user requests access or deletion, (e.g. having forgotten their password or username) you might not be 100% sure that it's him but arguing with him or asking too personal a verification proof can get you in hot water and you'd rather not get dragged into a fight with the European committee.
- While our users could initially create an account without e-mails and be relatively anonymous, a couple of "right to access" requests from "users who have forgotten their username" means you are basically forced to require e-mail, thereby carrying even more PII unnecessarily.
It probably wouldn't have slowed the hackers down much here though.
Re: An update on our security incident
#119>For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account’s information through our “Your Twitter Data” tool. Yikes. Pretty much a confirmation of the speculation that the hackers would have access to Twitter DMs. Question is, which accounts? edit: For reference, here's what's included in the "Your Twitter Data" tool [0]. There's some other info that may be o…
Here's my suspicions. I may well be wrong, but this is what it feels like... I was wondering what kind of thing some actors (possibly state-based) were going to do this election cycle since the 2016 one (hacks of Republican and Democratic emails) worked so darn well. Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. And there's no big reason to think that the exfiltration of privat…
Re: An update on our security incident
#120Earlier quoted context omitted.
Why would anyone care about the DM history of OG accounts? I believe that it is more likely to be politically motivated.
I could imagine a teenage hacker downloading his friend's or enemy's DMs. People the hacker knows in real life may be more interesting for him.