Live data from Hacker News

An update on our security incident

blog.twitter.com

251–260 of 308 posts

Re: An update on our security incident

#251

Earlier quoted context omitted.

Technical solutions can always be defeated by social engineering. Training is supposed to prevent that.

How do you socially engineer someone to compromise their U2F-based dongle?

"Hi I'm from tech support, I need you to go and generate some new backup codes. Now read them to me. Thanks!"

Re: An update on our security incident

#252

They seem to be tiptoeing around without providing actual extent of the hack. They mentioned data exports being used for 8 non verified accounts, but haven't mentioned "direct messages" as the thing that were not accessed for other accounts. Twitter tracks user engagement, so it should be possible for them to have this information either from logs/user analytics. I would be very wary of using their product's DMs now.…

They don't want to say what happened. It sounds like the problem is negligence in security design and not just a few employees who were manipulated.

Re: An update on our security incident

#253
post #33

I will use this as an ugly reminder that it's better to assume that any DMs could be public at any moment. I don't subscribe to the "nothing to fear, if you have nothing to hide", I had conversations that are not illegal, lewd or even non-politically correct jokes, but would still hate to made public by a 3rd entity; from secrets that were shared by friends, to sensitive data like addresses, or information with clien…

> I will use this as an ugly reminder that it's better to assume that any DMs could be public at any moment.

Good start, but you need to go much further. You should consider anything on an Internet-connected device could be public at any moment. As we are reminded weekly, there is no such thing as computer security in 2020.

Re: An update on our security incident

#254

They seem to be tiptoeing around without providing actual extent of the hack. They mentioned data exports being used for 8 non verified accounts, but haven't mentioned "direct messages" as the thing that were not accessed for other accounts. Twitter tracks user engagement, so it should be possible for them to have this information either from logs/user analytics. I would be very wary of using their product's DMs now.…

They don't want to say what happened. It sounds like the problem is negligence in security design and not just a few employees who were manipulated.

Yeah, I can understand why they wouldn't want to say much as something like your DMs were accessed will lead to a lot of bad press; but they can't really keep hiding behind that. The less they say, the more the people who are privacy/security conscious will doubt their product.

I don't know how people use DMs on Twitter but if they are anywhere close to the general usage of Signal/WhatsApp/iMessage/Messenger etc. It is incredibly bad for them and something which can kill the platform unless they rethink that completely considering they don't even have E2E.

Re: An update on our security incident

#255

Earlier quoted context omitted.

> There is a lot speculation about the identity of these 8 accounts. We will only disclose this to the impacted accounts, however to address some of the speculation: none of the eight were Verified accounts.[0] [0]: https://twitter.com/TwitterSupport/status/128433914877449830...

>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…

Verified accounts probably require a waiting time before downloading the data. I guess the attackers ran a web scraper on the verified accounts.

Re: An update on our security incident

#256

Earlier quoted context omitted.

I'm not sure what you're thinking, but it's perfectly reasonable. People like you're talking about don't communicate anything of value over twitter. Bezos only follows his ex-wife who doesn't follow him back, barely uses twitter and would be unlikely to have any DMs at all. After the saudi hack, I would be surprised if he has much of anything installed on his phone. The only real reason to hack celebrity accounts in…

> Bezos only follows his ex-wife who doesn't follow him back I honestly didn't believe you. But it's true. That's... kinda weird.

Probably a dead account he no longer access it before divorce, hence the awkward status

Re: An update on our security incident

#257
post #95

Earlier quoted context omitted.

That is exactly my worry the moment I saw they were not verified. Nation state could drop a grand per account and get data on 8 activists no problem.

Not $8k right? $1k per hacked account - which would thousands + the narrow targets?

The NYTb article says they were selling accounts initially for $1-1.5k before trying the Bitcoin scam

Re: An update on our security incident

#258

‘ we are deliberately limiting the detail we share on our remediation steps at this time to protect their effectiveness ’ Translation - it’s not fixed. Security through obscurity. Also timeline says ‘Wednesday’ post-mortem should be accurate to the minute or second.

> Also timeline says ‘Wednesday’ post-mortem should be accurate to the minute or second.

That's because it took them almost two hours to stop the attack - doesn't look good.

Re: An update on our security incident

#259

‘ we are deliberately limiting the detail we share on our remediation steps at this time to protect their effectiveness ’ Translation - it’s not fixed. Security through obscurity. Also timeline says ‘Wednesday’ post-mortem should be accurate to the minute or second.

if I were pwned as badly as this, esp via social engineering, I would be extremely hesitant to say anything was fixed within days. be reasonable.

Re: An update on our security incident

#260
post #9

> did the attackers see any of my private information? For the vast majority of people, we believe the answer is, no. This is such a weasel-y answer. “Yes, most of Earth’s population was not affected by this breach” - sure, but those that were affected, how would you be certain that they didn’t have their private information, such as DMs, pulled?

Yes, I also thought that part is fishy. They also said "don't worry, no passwords were visible" (I don't think any tech person would expect them to store passwords in plain text), then continue saying that email address, phone number and possibly other personal info was accessible. So, the answer should be yes?

Also, the initial question is about "me". I also never considered that my own data would have been accessible in this attack, I thought they would be discussing about the targeted accounts.

Post reply on HN