Translation - it’s not fixed. Security through obscurity.
Also timeline says ‘Wednesday’ post-mortem should be accurate to the minute or second.
191–200 of 308 posts
Translation - it’s not fixed. Security through obscurity.
Also timeline says ‘Wednesday’ post-mortem should be accurate to the minute or second.
> Attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack. They so carefully avoiding mentioning how they do store passwords that I have to wonder what their security practices are on that front (and the rest). What tools are they available under? You'd think they would've said "passwords are hashed and salted" to rule it out…
In some old articles it was mentioned they used Bcrypt. Not sure if that has changed. Not so many new algos are proven to be good.
Earlier quoted context omitted.
Because it's becoming increasingly hard to explain this hack otherwise. Imagine you walk by the beach, and see that the sea has washed up a pirate treasure chest. You crack it open, and see it full of gold, jewelry, old manuscripts, letters. Would you just throw the chest back into the sea, taking only a single ring, and a nail from the chest to hang a price list on your lemonade stand with? Because that's what happe…
More like the attackers rifled through the chest to find the map of the real treasure, leaving the meaningless trinkets behind.
‘ we are deliberately limiting the detail we share on our remediation steps at this time to protect their effectiveness ’ Translation - it’s not fixed. Security through obscurity. Also timeline says ‘Wednesday’ post-mortem should be accurate to the minute or second.
The internal post mortem will no doubt be accurate down to the second.
I will use this as an ugly reminder that it's better to assume that any DMs could be public at any moment. I don't subscribe to the "nothing to fear, if you have nothing to hide", I had conversations that are not illegal, lewd or even non-politically correct jokes, but would still hate to made public by a 3rd entity; from secrets that were shared by friends, to sensitive data like addresses, or information with clien…
If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him.
Earlier quoted context omitted.
If this is true then it completely defeats the purpose of a two-factor authentication
Almost all internet companies have internal tools to disable 2FA. People destroy/break/etc their phones constantly and need it reset. 2FA is meant to protect against someone impersonating you. It is not designed to protect against malicious insider at the org you are trying to prove your identity to
The reality is the public loses credentials and keys all the time and at most companies security takes a back seat to convenience and customer service.
Earlier quoted context omitted.
Its absolutely ridiculous that Twitter does not have end to end encryption of DMs yet. To think that they once hired Moxie/Whisper Systems and could have been miles ahead of everyone else on this. It's purely negligence at this stage.
While I do agree with you I don't see how this would have helped unless it is encrypted with a key Twitter doesn't have (ie. encrypted in the client with something else than the password). I highly doubt we will see that happen.