Earlier quoted context omitted.
I think that the fact the world will continue to spin without twitter is exactly why the hesitated to make that type of call.
Exactly. It's Twitter; nothing of value was lost. The recreationally outraged cancel mob had a minor setback.
An update on our security incident
241–250 of 308 posts
Re: An update on our security incident
#242Re: An update on our security incident
#243Earlier quoted context omitted.
I think that the fact the world will continue to spin without twitter is exactly why the hesitated to make that type of call.
Exactly. It's Twitter; nothing of value was lost. The recreationally outraged cancel mob had a minor setback.
"The recreationally outraged cancel mob"
FWIW, I actually enjoy twitter and get plenty of value from it (by selectively following interesting, intelligent people who post about things I care about) ... but your description is pretty funny -- and probably apt, at least for a sizable % of its users.
Re: An update on our security incident
#244Earlier quoted context omitted.
>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…
What if the 8 non-verified accounts are alt-accounts used by celebs/VIPs for personal communication? Let us imagine that I am Jeff Bezos, why would I use my official account to DM people? I would rather use one where I look like everybody so that it is less likely to be the target of an attack.
Re: An update on our security incident
#245Earlier quoted context omitted.
Training is not the answer to security problems, as empirically it has no effect. The only measures that work are technological, like U2F keys.
Technical solutions can always be defeated by social engineering. Training is supposed to prevent that.
Re: An update on our security incident
#246>For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account’s information through our “Your Twitter Data” tool. Yikes. Pretty much a confirmation of the speculation that the hackers would have access to Twitter DMs. Question is, which accounts? edit: For reference, here's what's included in the "Your Twitter Data" tool [0]. There's some other info that may be o…
Re: An update on our security incident
#247Earlier quoted context omitted.
> Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. Nobody is communicating anything valuable over Twitter. This is such a ridiculous point that people bring up all the time. Scandalous relationships? Most of that will be on true messenger applications. Business deals? Business email. Many more mainstream prominent people don't even run their own account. It's not that everyone is…
> Nobody is communicating anything valuable over Twitter. This is such a ridiculous point that people bring up all the time. Scandalous relationships? Most of that will be on true messenger applications. Business deals? Business email. Many more mainstream prominent people don't even run their own account. GP was talking about the 2016 election, where Julian Assange and Roger Stone literally communicated strategies,…
Re: An update on our security incident
#248I would be very wary of using their product's DMs now. Considering most journalists use Twitter, I can only hope that no one had used DMs to contact a journalist about something which can put the source in jeopardy.
Re: An update on our security incident
#249Re: An update on our security incident
#250How did they manipulate their employees? that's the most important part don't you think?
In an interview with the hacker by Vice Motherboard, they claimed they had an employee on the inside doing all the work, and they just paid the employee to do it: https://www.vice.com/en_us/article/jgxd3d/twitter-insider-ac...