Live data from Hacker News

An update on our security incident

blog.twitter.com

121–130 of 308 posts

Re: An update on our security incident

#121
post #118

>For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account’s information through our “Your Twitter Data” tool. Yikes. Pretty much a confirmation of the speculation that the hackers would have access to Twitter DMs. Question is, which accounts? edit: For reference, here's what's included in the "Your Twitter Data" tool [0]. There's some other info that may be o…

Only slightly related, but back when GDPR was first enacted I mentioned that it would inadvertently open up some vulnerabilities and that it should have been reviewed by white hat security researchers. - "Download all my data" was mandated by GDPR (article 20) - Right to delete, right to access made it so that there is up to a ten million dollar fine if you refuse it, so you are more prone to social engineering attac…

Where does it say you have to follow through with data or erasure of users who can’t prove they are who they say they are? Both of those seem like the opposite of what you are supposed to do. I just checked the first result, and even the ICO [0] says

> [Your full name and address and any other details such as account number to help identify you]

[0] https://ico.org.uk/your-data-matters/your-right-to-get-your-...

Re: An update on our security incident

#122

Earlier quoted context omitted.

I want to know how they social engineered an employee at a 2FA-enabled company into bypassing 2FA. Was the employee able to disable 2FA for their own account? Was the employee social engineered into adding someone else's 2FA key to their account? Did the employee read a 2FA code to the attacker, and that somehow enabled all the evil things the attacker did, without any additional checks or 2FA codes? Did the attacker…

I wonder if it was something like DUO and employees were told to just hit approve. Get employee's password Call employee "Hey [employee], I'm [coworker] from the security team and we noticed your DUO was locked. I just enabled it, but we want to make sure it works. Hit Approve when you get a notification." Log in with password Wait for employee to hit Approve.

That's why you need a phishing-resistant method of 2FA. U2F is phishing resistant. Any type of OTP, or anything that doesn't bind the user action to the url bar is susceptible to phishing. U2F has the computer verify the url bar so it's phishing-resistant.

Re: An update on our security incident

#123
post #69

Earlier quoted context omitted.

I think it likely varies on the person we're talking about. Is Obama personally tweeting and sending private memes in his DMs? Doubtful. Kanye or Elon Musk? I'd guess yes, actually.

Kanye West and Elon Musk have absolutely nothing of value in their DMs. Anything you could do with access to Musk's DMs you could do better just by tweeting as Musk. There is no value in Twitter DMs.

I'm sure the folks shorting TSLA would disagree on Elon's DMs.

Maybe Kanye's DMs would reveal he's really just fucking with everyone and hasn't actually completely lost it.

Well... Maybe just the former.

Re: An update on our security incident

#124
post #117

Earlier quoted context omitted.

This is by far the most eyebrow-raising part of the update. To take over such a large number of verified accounts and then run a download on only eight non-verified ones seems almost impossible to have been anything other than targeted. The original idea that the bitcoin scam was a diversion starts to look more plausible in this light, but in the absence of any information about the downloaded accounts, there’s reall…

The idea that someone would opt out of downloading Elon masks or Jeff bezos’ DMs is insane. Completely and perfectly insane. Not to mention the other people. Even if just in terms of profit, clearly the dms of the richest man in the world have enough value to just click download. It seems like the probability of this guy passing it up due to lack of interest is very small. Slightly more likely is that he was overwhel…

the it's even weirder because this looks something that required a certain amount of planning

Re: An update on our security incident

#125

Earlier quoted context omitted.

> "passwords are hashed and salted" Means something to you and me, but means nothing to the average Twitter user who is the audience for this blog post.

"plain text" is also a technical term. Ask the average joe what it means for something to be in "plain text" and you'd probably get the answer "Oh that's simple, they didn't write it out in cursive!"

I think the average non-technical reader could figure out that "plain text" refers to some variant of "········" rather than "password," even if the understanding is lacking technical depth.

Re: An update on our security incident

#126
post #117

Earlier quoted context omitted.

This is by far the most eyebrow-raising part of the update. To take over such a large number of verified accounts and then run a download on only eight non-verified ones seems almost impossible to have been anything other than targeted. The original idea that the bitcoin scam was a diversion starts to look more plausible in this light, but in the absence of any information about the downloaded accounts, there’s reall…

The idea that someone would opt out of downloading Elon masks or Jeff bezos’ DMs is insane. Completely and perfectly insane. Not to mention the other people. Even if just in terms of profit, clearly the dms of the richest man in the world have enough value to just click download. It seems like the probability of this guy passing it up due to lack of interest is very small. Slightly more likely is that he was overwhel…

I'm not sure what you're thinking, but it's perfectly reasonable.

People like you're talking about don't communicate anything of value over twitter. Bezos only follows his ex-wife who doesn't follow him back, barely uses twitter and would be unlikely to have any DMs at all. After the saudi hack, I would be surprised if he has much of anything installed on his phone.

The only real reason to hack celebrity accounts in this instance, and which they should have done, would be to deflect attention from the accounts they actually went after.

Re: An update on our security incident

#127
post #109

We need the guys at CMU (who also operate CERT) to engineer a replacement and setup a program for interns to operate it as a private non-profit for the rest of time. The system that is out there now has been a running technological joke since it was (sort of) running on Windows and it would be My_ dust now if it weren't for the President who they now (rightly or wrongly) scorn. Some seriously bad things can (and prob…

Could you provide more context?

Re: An update on our security incident

#128

I don’t understand the hubbub. It’s just a stupid messaging network. Not our emails that got hacked. I think this is relevant here - https://m.youtube.com/watch?feature=emb_title&v=MjufyLPKsEw

It's indeed a stupid messaging network, but having seen doctors and lawyers happily exchange documents and other sensitive data about their patients and clients through Facebook and Whatsapp, I wouldn't be surprised at all if it turns out that Twitter is being used for sensitive information as well.

Scanning a document and sending it through mail has been swapped with taking a photo with the cellphone and sending it through Whatsapp, and whoever took the photo very often forgets about it, so we have thousands of people out there with their phones loaded with sensitive data about their clients in the same directories they keep photos of their cats. Want to get sensitive data about someone? Just know where his doctor/lawyer lives or works, then open a cellphone repair shop nearby and be ready to copy everything when they bring you the terminal for screen/battery replacement or other problems, probably at least twice a year overall.

Re: An update on our security incident

#129
post #117

Earlier quoted context omitted.

The idea that someone would opt out of downloading Elon masks or Jeff bezos’ DMs is insane. Completely and perfectly insane. Not to mention the other people. Even if just in terms of profit, clearly the dms of the richest man in the world have enough value to just click download. It seems like the probability of this guy passing it up due to lack of interest is very small. Slightly more likely is that he was overwhel…

I'm not sure what you're thinking, but it's perfectly reasonable. People like you're talking about don't communicate anything of value over twitter. Bezos only follows his ex-wife who doesn't follow him back, barely uses twitter and would be unlikely to have any DMs at all. After the saudi hack, I would be surprised if he has much of anything installed on his phone. The only real reason to hack celebrity accounts in…

I wouldn't be so sure with Musk, for example. He even met his partner via DM.

Re: An update on our security incident

#130
post #120

Earlier quoted context omitted.

I could imagine a teenage hacker downloading his friend's or enemy's DMs. People the hacker knows in real life may be more interesting for him.

Why do we assume it's a young person doing the hacking?

Because it's becoming increasingly hard to explain this hack otherwise.

Imagine you walk by the beach, and see that the sea has washed up a pirate treasure chest. You crack it open, and see it full of gold, jewelry, old manuscripts, letters. Would you just throw the chest back into the sea, taking only a single ring, and a nail from the chest to hang a price list on your lemonade stand with?

Because that's what happened here. The attackers hit gold, and threw it all away.

Post reply on HN