Live data from Hacker News

An update on our security incident

blog.twitter.com

161–170 of 308 posts

Re: An update on our security incident

#161
post #131

Earlier quoted context omitted.

For security internally, sure. Mandating that every one of your customers has a Yubikey is somewhat trickier to do in practice, and a nightmare to manage the logistics around lost keys. I personally have 3 Yubikeys, one on my keyring, one in my small first aid kit (which is kept in my backpack and usually close to me) and one that doesn't ever travel with me. We give our staff yubikeys and require them to use them fo…

> Mandating that every one of your customers has a Yubikey is somewhat trickier to do in practice, and a nightmare to manage the logistics around lost keys. Mandating that everyone that has access to your admin console has a U2F key, on the other hand, seems like a perfectly reasonable expectation for a company of Twitter's stature.

Oh yes, for sure. That makes sense even with a fairly big distributed support/safety team.

Re: An update on our security incident

#163

Earlier quoted context omitted.

There is no indication that the accounts whose data was accessed were the accounts which tweeted the crypto scam. Therefore, I'm not sure that's a straightforward explanation.

They say the attackers reset passwords on the accounts. Any competent engineering team would have a complete list of those events in logs

You can't assume competence after such an hack. Before this has happened, you would have assumed that Twitter employees wouldn't fall for social engineering on this scale.

I wonder especially how they could have bypassed their 2FA.

Unless they specifically tell you something, you can't assume it to be the case.

Re: An update on our security incident

#164
post #60

>For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account’s information through our “Your Twitter Data” tool. Yikes. Pretty much a confirmation of the speculation that the hackers would have access to Twitter DMs. Question is, which accounts? edit: For reference, here's what's included in the "Your Twitter Data" tool [0]. There's some other info that may be o…

Here's my suspicions. I may well be wrong, but this is what it feels like... I was wondering what kind of thing some actors (possibly state-based) were going to do this election cycle since the 2016 one (hacks of Republican and Democratic emails) worked so darn well. Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. And there's no big reason to think that the exfiltration of privat…

Whose private DMs would have as much impact as campaign emails did, and aren’t verified though? That’s the thing that raises so many questions for me - they only exfiltrated the data on accounts that aren’t verified.

On Trump, apparently he has more internal protections on his account than normal so it could just be that the employees they got in through didn’t have any access. https://www.nytimes.com/2020/07/16/technology/twitter-hack-i...

Re: An update on our security incident

#165

How did they manipulate their employees? that's the most important part don't you think?

Absolutely! Insofar as a post mortem will help others avoid the same fate, understanding the specifics of the social engineering hack is by far the most useful information they could share about what happened. My guess is that they won't because either a) they are lying about this being the underlying cause, or b) it is itself too sensitive to reveal (either about the company or the targeted individuals).

Yeah probably they first want to "patch" that social engineering hole which is probably quite challenging. Although I don't think Twitter is really to blame since few companies see security that critical and training on that is indeed rare. Security is almost synonymous with SSH, TLS, VPN and 2FA although this kind of attack has been published widely even before these technologies have been invented.

Re: An update on our security incident

#166
I like how Twitter wrote this post. It's apologetic, transparent, and clear. I feel like Cloudflare and Twitter have been really good with communicating what has happened and that is impressive. I'm glad these companies have learned from others' mistakes. Being transparent is the starting point of gaining back lost trust.

Re: An update on our security incident

#167

Why do companies store previous passworda, does this make my now strong passwords moot due to not being being as security conscious previously and reusing passwords?

Generally if a service was to keep them it would be to keep a history of passwords you may not use ever again. They wouldn't be available for use in authentication.

Obviously this is very implementation specific though, and can't be considered a rule.

Re: An update on our security incident

#168
post #45

Earlier quoted context omitted.

Not really, this document is clearly intended for a general public audience (They define the term "social engineering" after all). I don't think its surprising they didn't go into the details of which algorithms they use on old passwords

They could've just said "...as this is not possible" or something like that. I wasn't suggesting they need to drop in acronyms like PBKDF2 or whatever. They go out of their way to say "through the tools used in the attack" which might as well imply there are other tools through which the passwords are available...

Not possible is like unhackable; if you say it you're guaranteed to be proven wrong. Publicly.

Re: An update on our security incident

#170
post #60

Earlier quoted context omitted.

Here's my suspicions. I may well be wrong, but this is what it feels like... I was wondering what kind of thing some actors (possibly state-based) were going to do this election cycle since the 2016 one (hacks of Republican and Democratic emails) worked so darn well. Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. And there's no big reason to think that the exfiltration of privat…

Whose private DMs would have as much impact as campaign emails did, and aren’t verified though? That’s the thing that raises so many questions for me - they only exfiltrated the data on accounts that aren’t verified. On Trump, apparently he has more internal protections on his account than normal so it could just be that the employees they got in through didn’t have any access. https://www.nytimes.com/2020/07/16/tech…

>Whose private DMs would have as much impact as campaign emails did, and aren’t verified though? That’s the thing that raises so many questions for me - they only exfiltrated the data on accounts that aren’t verified.

Verified doesn't necessarily mean important people, but rather public personality/official account. There could be hundreds of lobbyists, journalists, etc. that don't use verified accounts.

Post reply on HN