Live data from Hacker News

An update on our security incident

blog.twitter.com

201–210 of 308 posts

Re: An update on our security incident

#201

Earlier quoted context omitted.

The President's account might also have extra safe guards against hacks.

Just like Obama's, right?

The risk of compromise of the sitting president's account poses a much greater threat than does that of a former one. Also, the prominence of Twitter as a means for a head of state to communicate official policy came much further in prominence during the current president's term than before.

Re: An update on our security incident

#203
post #120

Earlier quoted context omitted.

Why do we assume it's a young person doing the hacking?

Because it's becoming increasingly hard to explain this hack otherwise. Imagine you walk by the beach, and see that the sea has washed up a pirate treasure chest. You crack it open, and see it full of gold, jewelry, old manuscripts, letters. Would you just throw the chest back into the sea, taking only a single ring, and a nail from the chest to hang a price list on your lemonade stand with? Because that's what happe…

After reading Krebs' initial take on the incident[0], I think a plausible explanation is that whoever created the hack isn't the person who exploited the hack.

The hacker managed to get an amazing level of access, but exploiting that, and extracting value from it, and getting away clean is probably really hard. So they sold the access to whoever was willing to pay for it for a guaranteed return. That also gives you an extra middleman that law enforcement has to get past before they get to you, and confusing the trail between the middleman and you might be easier than confusing the trail between your targets and you.

Except whoever paid for the access and used the exploit just didn't have the imagination to do something that made as full use of the hack as they might have done. And now dozens of other criminals are facepalming themselves to death for not having been the ones to have bought this opportunity for their own ends, which they think would have been much more epic.

[0] https://krebsonsecurity.com/2020/07/whos-behind-wednesdays-e...

Re: An update on our security incident

#204

To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…

They disabled the account that were identified to be compromised. That isn’t enough?

Re: An update on our security incident

#205
post #188

I remember that answer to "What keeps you up at night?" of a major security advisor to be "Our employees! They click everything!". Fitting video: https://www.youtube.com/watch?v=bLXW2JQ0TZk Training to prevent these social engineering leaks is definitely critical.

Training is not the answer to security problems, as empirically it has no effect. The only measures that work are technological, like U2F keys.

Technical solutions can always be defeated by social engineering. Training is supposed to prevent that.

Re: An update on our security incident

#206
post #63

Earlier quoted context omitted.

very poorly is a bit much. Yes yubikey would be much better, but its not exactly standard across the industry yet. For something to reflect very poorly on twitter opsec, I would expect it to be something that is below what the average tech company was doing. e.g. There was some news article claiming [Without a whole lot of evidence] that the compromised tool used a shared password that was posted as the topic of a sl…

Twitter is not an average company. As one of the top 40 internet companies, they are in the position of setting industry standards. I think it's fair to expect more than what the average company does from Twitter.

Arguably top 10, no?

Re: An update on our security incident

#207

To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…

I think that the fact the world will continue to spin without twitter is exactly why the hesitated to make that type of call.

Re: An update on our security incident

#208

>For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account’s information through our “Your Twitter Data” tool. Yikes. Pretty much a confirmation of the speculation that the hackers would have access to Twitter DMs. Question is, which accounts? edit: For reference, here's what's included in the "Your Twitter Data" tool [0]. There's some other info that may be o…

> There is a lot speculation about the identity of these 8 accounts. We will only disclose this to the impacted accounts, however to address some of the speculation: none of the eight were Verified accounts.[0] [0]: https://twitter.com/TwitterSupport/status/128433914877449830...

Well, it could also be that they downloaded the DMs of the other accounts through the web, and not through "Download your data" tool.

Nowhere they say DMs of the celebrities were not accessed. Some sort of lying by omission.

Re: An update on our security incident

#210
post #179

Earlier quoted context omitted.

You can look at the blockchain how much money people lost, and for how long the scam went on. Or you can just read Twitter's announcement: they did nothing to mitigate the scam. I remember being scammed for about $200 when I was a teenager and it was awful. I was ashamed of myself.

Has anyone stepped forward and claimed they were scammed yet? It's normal for scammers to pay themselves to make their scam look more legitimate. If no one steps forward... it's not impossible that they actually didn't manage to scam anyone.

You're right, but it's also normal for people to be ashamed of getting scammed and not come forward. I have a friend who got scammed by altcoiners and lost most of his BTC even though I warned him many times. He didn't tell me this for many years because he was ashamed. At this time he doesn't have any chance of buying so many Bitcoins again ever in his life.

Leaving those messages up for so much time (at least an hour) was unacceptable anyways. When I was holding a pager for a product that impacted millions of people, my job was to mitigate all problems that could affect them as soon as I could.

Post reply on HN