Live data from Hacker News

An update on our security incident

blog.twitter.com

231–240 of 308 posts

Re: An update on our security incident

#231
post #218

Earlier quoted context omitted.

They disabled the account that were identified to be compromised. That isn’t enough?

Disabling everything would have been quicker, and there's no way they could have been certain which accounts were compromised, certainly not so early. Even now - you have to make do with the traces the attackers leave behind, but it's unlikely you have complete certainty that some traces weren't removed, or fallback backdoors perhaps placed. Also, disabling everything would have likely been only a very short term sol…

> Disabling everything would have been quicker

How do you know?

While it affected a bunch of popular accounts it didn't really disrupt Twitter for the rest of the user base or put them at huge risk. Disabling all accounts is maybe not even that easy to do on a scale like that where maybe then you are getting overwhelmed by retries / errors from all kinds of apps and it's even harder to control the whole situation. Just disabling high profile accounts seemed like a pretty good workaround.

Re: An update on our security incident

#232
post #188

I remember that answer to "What keeps you up at night?" of a major security advisor to be "Our employees! They click everything!". Fitting video: https://www.youtube.com/watch?v=bLXW2JQ0TZk Training to prevent these social engineering leaks is definitely critical.

Training is not the answer to security problems, as empirically it has no effect. The only measures that work are technological, like U2F keys.

Do you have a source on that? Anecdotally, I'm better at recognizing threats after my company instituted annual training as well as simulated attacks.

Re: An update on our security incident

#234

To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…

twitter does not really care that much. They care enough to possibly do something is it gets enough media coverage or enough high profile people people complain about it, but otherwise it is not their problem . They have let giveaway bitcoin scammers make presumably millions since 2018 by impersonating Elon Musk and others. Social networks are not in the business of protecting their users from scams or protecting user data from hackers. The main priority is growing the platform and generating more clicks and views to sell more ads.

Re: An update on our security incident

#235
post #218

Earlier quoted context omitted.

They disabled the account that were identified to be compromised. That isn’t enough?

Disabling everything would have been quicker, and there's no way they could have been certain which accounts were compromised, certainly not so early. Even now - you have to make do with the traces the attackers leave behind, but it's unlikely you have complete certainty that some traces weren't removed, or fallback backdoors perhaps placed. Also, disabling everything would have likely been only a very short term sol…

they can do the classic fake error page or fake server overloaded page . few would suspect anything

Re: An update on our security incident

#236

I think the Bitcoin scam is a red herring.

What could it be distracting from, or what would be the purpose of running a smaller/dumber attack before the actual one?

Whenever people start speculating that some dumb crime is a small part of some mastermind plot, you can rest assured that it's probably not.

Re: An update on our security incident

#237

To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…

I think that the fact the world will continue to spin without twitter is exactly why the hesitated to make that type of call.

Exactly. It's Twitter; nothing of value was lost. The recreationally outraged cancel mob had a minor setback.

Re: An update on our security incident

#238

> Attackers were able to view personal information including email addresses and phone numbers, which are displayed to some users of our internal support tools. Can anyone explain to me why the phone number is stored in plain text for them to see?

In case you need to call them?

Re: An update on our security incident

#239

To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…

If posting memes is dangerous, it's not because of Twitter, it's because the media's only occupation nowadays is blowing things completely out of proportion with their Trump Derangement Syndrome.

I assure you that World War III will not start because of a (real or faked) Tweet by President Trump, as much as CNN et al. are praying for it.

Re: An update on our security incident

#240

I like how Twitter wrote this post. It's apologetic, transparent, and clear. I feel like Cloudflare and Twitter have been really good with communicating what has happened and that is impressive. I'm glad these companies have learned from others' mistakes. Being transparent is the starting point of gaining back lost trust.

I do believe that the point

>In cases where an account was taken over by the attacker, they may have been able to view additional information

Is kinda downplayed by wording

Post reply on HN