Live data from Hacker News

An update on our security incident

blog.twitter.com

181–190 of 308 posts

Re: An update on our security incident

#181
post #75

Earlier quoted context omitted.

Ah, Elon, forgot about that one. I fully believe he runs his own twitter. How else is he going to control the stock market!? ;) You’re right, I assume his would be one of the accounts that was exfil’ed

He's verified though, and they claim the only exfil'd accounts weren't.

They didn’t say that only those 8 non-verified accounts had DMs accessed.

Re: An update on our security incident

#182

>For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account’s information through our “Your Twitter Data” tool. Yikes. Pretty much a confirmation of the speculation that the hackers would have access to Twitter DMs. Question is, which accounts? edit: For reference, here's what's included in the "Your Twitter Data" tool [0]. There's some other info that may be o…

> There is a lot speculation about the identity of these 8 accounts. We will only disclose this to the impacted accounts, however to address some of the speculation: none of the eight were Verified accounts.[0] [0]: https://twitter.com/TwitterSupport/status/128433914877449830...

...because the private data from the verified accounts was downloaded thorough some other means, right? Surely this must be creative lawyer wording to make the incident sound less serious than it is. To think that the hackers would have the ability to get juicy data and then not fetch it seems unlikely to me.

Re: An update on our security incident

#183
Like many of you, I watched this rolling on Wednesday night using live verified accounts link that was widely shared. I was also just looking at the 'regular people' tab without verified accounts and saw many, many, many accounts tweeting the same "double your bitcoin" link, with the same BTC address. These weren't retweets. I'd assumed these accounts had also been compromised - was I wrong? It was far more than 130 accounts.

Or was this just people copying and pasting the same message (if so why that rather than retweet)? There were so many every few seconds I assumed it was a script just running through accounts. But --- if it wasn't, what were people hoping to gain? Views on their own profile?

Re: An update on our security incident

#184
post #117

Earlier quoted context omitted.

The idea that someone would opt out of downloading Elon masks or Jeff bezos’ DMs is insane. Completely and perfectly insane. Not to mention the other people. Even if just in terms of profit, clearly the dms of the richest man in the world have enough value to just click download. It seems like the probability of this guy passing it up due to lack of interest is very small. Slightly more likely is that he was overwhel…

I'm not sure what you're thinking, but it's perfectly reasonable. People like you're talking about don't communicate anything of value over twitter. Bezos only follows his ex-wife who doesn't follow him back, barely uses twitter and would be unlikely to have any DMs at all. After the saudi hack, I would be surprised if he has much of anything installed on his phone. The only real reason to hack celebrity accounts in…

If you think Musk or Trump have any sense of restraint, much less opsec, do I ever have a bridge to sell you.

Re: An update on our security incident

#185

Earlier quoted context omitted.

> There is a lot speculation about the identity of these 8 accounts. We will only disclose this to the impacted accounts, however to address some of the speculation: none of the eight were Verified accounts.[0] [0]: https://twitter.com/TwitterSupport/status/128433914877449830...

>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…

Its absolutely ridiculous that Twitter does not have end to end encryption of DMs yet. To think that they once hired Moxie/Whisper Systems and could have been miles ahead of everyone else on this. It's purely negligence at this stage.

Re: An update on our security incident

#186

Earlier quoted context omitted.

>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…

Its absolutely ridiculous that Twitter does not have end to end encryption of DMs yet. To think that they once hired Moxie/Whisper Systems and could have been miles ahead of everyone else on this. It's purely negligence at this stage.

While I do agree with you I don't see how this would have helped unless it is encrypted with a key Twitter doesn't have (ie. encrypted in the client with something else than the password). I highly doubt we will see that happen.

Re: An update on our security incident

#187
post #132
post #117

Earlier quoted context omitted.

The idea that someone would opt out of downloading Elon masks or Jeff bezos’ DMs is insane. Completely and perfectly insane. Not to mention the other people. Even if just in terms of profit, clearly the dms of the richest man in the world have enough value to just click download. It seems like the probability of this guy passing it up due to lack of interest is very small. Slightly more likely is that he was overwhel…

Where do you think you will find more info -- the DMs of a PR account or the someone's private alt? Or the DMs of a twitter celebrity or the DMs of a hedge fund manager or member of the board of directors of a bank?

I suspect that hedge fund managers and bank board members are considerably less likely to use DMs as a means of primary communication than Twitter celebrities. Private alt accounts would be very interesting, but you'd need to know who they are....

Re: An update on our security incident

#188

I remember that answer to "What keeps you up at night?" of a major security advisor to be "Our employees! They click everything!". Fitting video: https://www.youtube.com/watch?v=bLXW2JQ0TZk Training to prevent these social engineering leaks is definitely critical.

Training is not the answer to security problems, as empirically it has no effect. The only measures that work are technological, like U2F keys.

Re: An update on our security incident

#189
post #60

Earlier quoted context omitted.

Here's my suspicions. I may well be wrong, but this is what it feels like... I was wondering what kind of thing some actors (possibly state-based) were going to do this election cycle since the 2016 one (hacks of Republican and Democratic emails) worked so darn well. Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. And there's no big reason to think that the exfiltration of privat…

The President's account might also have extra safe guards against hacks.

Just like Obama's, right?

Re: An update on our security incident

#190

> Attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack. They so carefully avoiding mentioning how they do store passwords that I have to wonder what their security practices are on that front (and the rest). What tools are they available under? You'd think they would've said "passwords are hashed and salted" to rule it out…

> "passwords are hashed and salted" Means something to you and me, but means nothing to the average Twitter user who is the audience for this blog post.

Hashed and salted is insufficient, as GPUs are extremely fast at crunching through hashes. Unless they use a memory-intensive (for GPU/FPGA résistance) algorithm like argon2 or scrypt, I would assume those credentials compromised.
Post reply on HN