Live data from Hacker News

An update on our security incident

blog.twitter.com

241–250 of 308 posts

Re: An update on our security incident

#241
post #237

Earlier quoted context omitted.

I think that the fact the world will continue to spin without twitter is exactly why the hesitated to make that type of call.

Exactly. It's Twitter; nothing of value was lost. The recreationally outraged cancel mob had a minor setback.

If the hackers had access to the DMs, stuff of value could have been lost.

Re: An update on our security incident

#243
post #237

Earlier quoted context omitted.

I think that the fact the world will continue to spin without twitter is exactly why the hesitated to make that type of call.

Exactly. It's Twitter; nothing of value was lost. The recreationally outraged cancel mob had a minor setback.

hah!

"The recreationally outraged cancel mob"

FWIW, I actually enjoy twitter and get plenty of value from it (by selectively following interesting, intelligent people who post about things I care about) ... but your description is pretty funny -- and probably apt, at least for a sizable % of its users.

Re: An update on our security incident

#244
post #230

Earlier quoted context omitted.

>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…

What if the 8 non-verified accounts are alt-accounts used by celebs/VIPs for personal communication? Let us imagine that I am Jeff Bezos, why would I use my official account to DM people? I would rather use one where I look like everybody so that it is less likely to be the target of an attack.

Would having access to the verified account somehow tell you what the alt account name is though?

Re: An update on our security incident

#245
post #188

Earlier quoted context omitted.

Training is not the answer to security problems, as empirically it has no effect. The only measures that work are technological, like U2F keys.

Technical solutions can always be defeated by social engineering. Training is supposed to prevent that.

How do you socially engineer someone to compromise their U2F-based dongle?

Re: An update on our security incident

#246

>For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account’s information through our “Your Twitter Data” tool. Yikes. Pretty much a confirmation of the speculation that the hackers would have access to Twitter DMs. Question is, which accounts? edit: For reference, here's what's included in the "Your Twitter Data" tool [0]. There's some other info that may be o…

maybe a girlfriend or ex girlfriend . or a rival hacker. or someone who is believed to own a lot of crypto and is low profile.

Re: An update on our security incident

#247
post #73
post #65

Earlier quoted context omitted.

> Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. Nobody is communicating anything valuable over Twitter. This is such a ridiculous point that people bring up all the time. Scandalous relationships? Most of that will be on true messenger applications. Business deals? Business email. Many more mainstream prominent people don't even run their own account. It's not that everyone is…

> Nobody is communicating anything valuable over Twitter. This is such a ridiculous point that people bring up all the time. Scandalous relationships? Most of that will be on true messenger applications. Business deals? Business email. Many more mainstream prominent people don't even run their own account. GP was talking about the 2016 election, where Julian Assange and Roger Stone literally communicated strategies,…

Just wondering, how do you prove the authenticity of the DMs if they have no cryptographic signatures? I'd be very hard. Even is some are authentic, some messages could be altered / planted, there is no way you could trust screenshots too.

Re: An update on our security incident

#248
They seem to be tiptoeing around without providing actual extent of the hack. They mentioned data exports being used for 8 non verified accounts, but haven't mentioned "direct messages" as the thing that were not accessed for other accounts. Twitter tracks user engagement, so it should be possible for them to have this information either from logs/user analytics.

I would be very wary of using their product's DMs now. Considering most journalists use Twitter, I can only hope that no one had used DMs to contact a journalist about something which can put the source in jeopardy.

Re: An update on our security incident

#250

How did they manipulate their employees? that's the most important part don't you think?

In an interview with the hacker by Vice Motherboard, they claimed they had an employee on the inside doing all the work, and they just paid the employee to do it: https://www.vice.com/en_us/article/jgxd3d/twitter-insider-ac...

Like the other commenter, I am also skeptical of this. This has to be a big amount and in some untraceable account otherwise why would a well paid Twitter employee put his career in jeopardy over something like this. You can look at audit trail and pretty much nail the person who did this, and then after that good luck with the criminal charges and making yourself unemployable.
Post reply on HN