Earlier quoted context omitted.
The President's account might also have extra safe guards against hacks.
Just like Obama's, right?
An update on our security incident
201–210 of 308 posts
Re: An update on our security incident
#202Re: An update on our security incident
#203Earlier quoted context omitted.
Why do we assume it's a young person doing the hacking?
Because it's becoming increasingly hard to explain this hack otherwise. Imagine you walk by the beach, and see that the sea has washed up a pirate treasure chest. You crack it open, and see it full of gold, jewelry, old manuscripts, letters. Would you just throw the chest back into the sea, taking only a single ring, and a nail from the chest to hang a price list on your lemonade stand with? Because that's what happe…
The hacker managed to get an amazing level of access, but exploiting that, and extracting value from it, and getting away clean is probably really hard. So they sold the access to whoever was willing to pay for it for a guaranteed return. That also gives you an extra middleman that law enforcement has to get past before they get to you, and confusing the trail between the middleman and you might be easier than confusing the trail between your targets and you.
Except whoever paid for the access and used the exploit just didn't have the imagination to do something that made as full use of the hack as they might have done. And now dozens of other criminals are facepalming themselves to death for not having been the ones to have bought this opportunity for their own ends, which they think would have been much more epic.
[0] https://krebsonsecurity.com/2020/07/whos-behind-wednesdays-e...
Re: An update on our security incident
#204To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…
Re: An update on our security incident
#205I remember that answer to "What keeps you up at night?" of a major security advisor to be "Our employees! They click everything!". Fitting video: https://www.youtube.com/watch?v=bLXW2JQ0TZk Training to prevent these social engineering leaks is definitely critical.
Training is not the answer to security problems, as empirically it has no effect. The only measures that work are technological, like U2F keys.
Re: An update on our security incident
#206Earlier quoted context omitted.
very poorly is a bit much. Yes yubikey would be much better, but its not exactly standard across the industry yet. For something to reflect very poorly on twitter opsec, I would expect it to be something that is below what the average tech company was doing. e.g. There was some news article claiming [Without a whole lot of evidence] that the compromised tool used a shared password that was posted as the topic of a sl…
Twitter is not an average company. As one of the top 40 internet companies, they are in the position of setting industry standards. I think it's fair to expect more than what the average company does from Twitter.
Re: An update on our security incident
#207To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…
Re: An update on our security incident
#208>For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account’s information through our “Your Twitter Data” tool. Yikes. Pretty much a confirmation of the speculation that the hackers would have access to Twitter DMs. Question is, which accounts? edit: For reference, here's what's included in the "Your Twitter Data" tool [0]. There's some other info that may be o…
> There is a lot speculation about the identity of these 8 accounts. We will only disclose this to the impacted accounts, however to address some of the speculation: none of the eight were Verified accounts.[0] [0]: https://twitter.com/TwitterSupport/status/128433914877449830...
Nowhere they say DMs of the celebrities were not accessed. Some sort of lying by omission.
Re: An update on our security incident
#209https://blog.twitter.com/developer/en_us/topics/tools/2020/i...
Re: An update on our security incident
#210Earlier quoted context omitted.
You can look at the blockchain how much money people lost, and for how long the scam went on. Or you can just read Twitter's announcement: they did nothing to mitigate the scam. I remember being scammed for about $200 when I was a teenager and it was awful. I was ashamed of myself.
Has anyone stepped forward and claimed they were scammed yet? It's normal for scammers to pay themselves to make their scam look more legitimate. If no one steps forward... it's not impossible that they actually didn't manage to scam anyone.
Leaving those messages up for so much time (at least an hour) was unacceptable anyways. When I was holding a pager for a product that impacted millions of people, my job was to mitigate all problems that could affect them as soon as I could.