Earlier quoted context omitted.
Not really, this document is clearly intended for a general public audience (They define the term "social engineering" after all). I don't think its surprising they didn't go into the details of which algorithms they use on old passwords
They could've just said "...as this is not possible" or something like that. I wasn't suggesting they need to drop in acronyms like PBKDF2 or whatever. They go out of their way to say "through the tools used in the attack" which might as well imply there are other tools through which the passwords are available...
An update on our security incident
141–150 of 308 posts
Re: An update on our security incident
#142Re: An update on our security incident
#143Earlier quoted context omitted.
> There is a lot speculation about the identity of these 8 accounts. We will only disclose this to the impacted accounts, however to address some of the speculation: none of the eight were Verified accounts.[0] [0]: https://twitter.com/TwitterSupport/status/128433914877449830...
>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…
Re: An update on our security incident
#144This is pathetic. How the hell did a comapny as rich as Twitter not have a break-glass around accessing this data. No one person should have had this level of access. No TWO people should have had this level of access. Unbelievable.
Re: An update on our security incident
#145Earlier quoted context omitted.
I'm not sure what you're thinking, but it's perfectly reasonable. People like you're talking about don't communicate anything of value over twitter. Bezos only follows his ex-wife who doesn't follow him back, barely uses twitter and would be unlikely to have any DMs at all. After the saudi hack, I would be surprised if he has much of anything installed on his phone. The only real reason to hack celebrity accounts in…
I wouldn't be so sure with Musk, for example. He even met his partner via DM.
Re: An update on our security incident
#146Earlier quoted context omitted.
very poorly is a bit much. Yes yubikey would be much better, but its not exactly standard across the industry yet. For something to reflect very poorly on twitter opsec, I would expect it to be something that is below what the average tech company was doing. e.g. There was some news article claiming [Without a whole lot of evidence] that the compromised tool used a shared password that was posted as the topic of a sl…
Google has made it a requirement to use hardware keys internally since early 2017 and has noted there have been zero successful phishing attempts since. Twitter would have done the same if they had competent security staff.
Google embarked on their BeyondCorp/zero-trust initiative after the 2009 Chinese APT breach. The teams working on their internal security had firepower and support from the very top of the organisation - and it took them seven years to get from "we want to make entire classes of attacks impossible" to "we can now enforce it".
The disappointing truth in tech is that - apart from a few exceptions - security gets only superficial attention, because doing it right is a long-term investment. You need to be reliably profitable for that.
Re: An update on our security incident
#147They don't write about the fact that they let the scam going on for hours destroying lives of people. Locking down the accounts actually helped.the scammers, as the owners of the accounts or other Twitter employees weren't able to delete the scam messages.
Re: An update on our security incident
#148Earlier quoted context omitted.
"plain text" is also a technical term. Ask the average joe what it means for something to be in "plain text" and you'd probably get the answer "Oh that's simple, they didn't write it out in cursive!"
I think the average non-technical reader could figure out that "plain text" refers to some variant of "········" rather than "password," even if the understanding is lacking technical depth.
Re: An update on our security incident
#149> None of the eight were verified accounts. So.... Lowerclass plebs we don't care about as much? It's funny they admit this.
Re: An update on our security incident
#150,,We became aware of the attackers’ action on Wednesday, and moved quickly to lock down and regain control of the compromised accounts.'' They don't write about the fact that they let the scam going on for hours destroying lives of people. Locking down the accounts actually helped.the scammers, as the owners of the accounts or other Twitter employees weren't able to delete the scam messages.
Source?