Earlier quoted context omitted.
Technical solutions can always be defeated by social engineering. Training is supposed to prevent that.
How do you socially engineer someone to compromise their U2F-based dongle?
An update on our security incident
251–260 of 308 posts
Re: An update on our security incident
#252They seem to be tiptoeing around without providing actual extent of the hack. They mentioned data exports being used for 8 non verified accounts, but haven't mentioned "direct messages" as the thing that were not accessed for other accounts. Twitter tracks user engagement, so it should be possible for them to have this information either from logs/user analytics. I would be very wary of using their product's DMs now.…
Re: An update on our security incident
#253I will use this as an ugly reminder that it's better to assume that any DMs could be public at any moment. I don't subscribe to the "nothing to fear, if you have nothing to hide", I had conversations that are not illegal, lewd or even non-politically correct jokes, but would still hate to made public by a 3rd entity; from secrets that were shared by friends, to sensitive data like addresses, or information with clien…
Good start, but you need to go much further. You should consider anything on an Internet-connected device could be public at any moment. As we are reminded weekly, there is no such thing as computer security in 2020.
Re: An update on our security incident
#254They seem to be tiptoeing around without providing actual extent of the hack. They mentioned data exports being used for 8 non verified accounts, but haven't mentioned "direct messages" as the thing that were not accessed for other accounts. Twitter tracks user engagement, so it should be possible for them to have this information either from logs/user analytics. I would be very wary of using their product's DMs now.…
They don't want to say what happened. It sounds like the problem is negligence in security design and not just a few employees who were manipulated.
I don't know how people use DMs on Twitter but if they are anywhere close to the general usage of Signal/WhatsApp/iMessage/Messenger etc. It is incredibly bad for them and something which can kill the platform unless they rethink that completely considering they don't even have E2E.
Re: An update on our security incident
#255Earlier quoted context omitted.
> There is a lot speculation about the identity of these 8 accounts. We will only disclose this to the impacted accounts, however to address some of the speculation: none of the eight were Verified accounts.[0] [0]: https://twitter.com/TwitterSupport/status/128433914877449830...
>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…
Re: An update on our security incident
#256Earlier quoted context omitted.
I'm not sure what you're thinking, but it's perfectly reasonable. People like you're talking about don't communicate anything of value over twitter. Bezos only follows his ex-wife who doesn't follow him back, barely uses twitter and would be unlikely to have any DMs at all. After the saudi hack, I would be surprised if he has much of anything installed on his phone. The only real reason to hack celebrity accounts in…
> Bezos only follows his ex-wife who doesn't follow him back I honestly didn't believe you. But it's true. That's... kinda weird.
Re: An update on our security incident
#257Earlier quoted context omitted.
That is exactly my worry the moment I saw they were not verified. Nation state could drop a grand per account and get data on 8 activists no problem.
Not $8k right? $1k per hacked account - which would thousands + the narrow targets?
Re: An update on our security incident
#258‘ we are deliberately limiting the detail we share on our remediation steps at this time to protect their effectiveness ’ Translation - it’s not fixed. Security through obscurity. Also timeline says ‘Wednesday’ post-mortem should be accurate to the minute or second.
That's because it took them almost two hours to stop the attack - doesn't look good.
Re: An update on our security incident
#259‘ we are deliberately limiting the detail we share on our remediation steps at this time to protect their effectiveness ’ Translation - it’s not fixed. Security through obscurity. Also timeline says ‘Wednesday’ post-mortem should be accurate to the minute or second.
Re: An update on our security incident
#260> did the attackers see any of my private information? For the vast majority of people, we believe the answer is, no. This is such a weasel-y answer. “Yes, most of Earth’s population was not affected by this breach” - sure, but those that were affected, how would you be certain that they didn’t have their private information, such as DMs, pulled?
Also, the initial question is about "me". I also never considered that my own data would have been accessible in this attack, I thought they would be discussing about the targeted accounts.