>For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account’s information through our “Your Twitter Data” tool. Yikes. Pretty much a confirmation of the speculation that the hackers would have access to Twitter DMs. Question is, which accounts? edit: For reference, here's what's included in the "Your Twitter Data" tool [0]. There's some other info that may be o…
maybe a girlfriend or ex girlfriend . or a rival hacker. or someone who is believed to own a lot of crypto and is low profile.
An update on our security incident
261–270 of 308 posts
Re: An update on our security incident
#262Earlier quoted context omitted.
Technical solutions can always be defeated by social engineering. Training is supposed to prevent that.
How do you socially engineer someone to compromise their U2F-based dongle?
Countless creative ways will be tried and discovered.
Re: An update on our security incident
#263Like many of you, I watched this rolling on Wednesday night using live verified accounts link that was widely shared. I was also just looking at the 'regular people' tab without verified accounts and saw many, many, many accounts tweeting the same "double your bitcoin" link, with the same BTC address. These weren't retweets. I'd assumed these accounts had also been compromised - was I wrong? It was far more than 130…
Cashing in on the public attention. Social media is filled with people who would debase themselves for a little bit of attention or likes. The hack caused a lot of uproar, what better way than pretending you're were high-profile enough to be hacked too?
Re: An update on our security incident
#264Re: An update on our security incident
#265Earlier quoted context omitted.
I'm not sure what you're thinking, but it's perfectly reasonable. People like you're talking about don't communicate anything of value over twitter. Bezos only follows his ex-wife who doesn't follow him back, barely uses twitter and would be unlikely to have any DMs at all. After the saudi hack, I would be surprised if he has much of anything installed on his phone. The only real reason to hack celebrity accounts in…
I always thought high profile accounts are run by media teams. I doubt the account owners know the credentials themselves or have direct access in most cases.
Re: An update on our security incident
#266Earlier quoted context omitted.
Exactly. It's Twitter; nothing of value was lost. The recreationally outraged cancel mob had a minor setback.
If the hackers had access to the DMs, stuff of value could have been lost.
Re: An update on our security incident
#267Earlier quoted context omitted.
Disabling everything would have been quicker, and there's no way they could have been certain which accounts were compromised, certainly not so early. Even now - you have to make do with the traces the attackers leave behind, but it's unlikely you have complete certainty that some traces weren't removed, or fallback backdoors perhaps placed. Also, disabling everything would have likely been only a very short term sol…
> How many people saw the tweets and transferred bitcoins during the period in which twitter likely could have turned off everthing, but not yet blocked access to the respective accounts At most 475 greedy idiots, average $266 each https://www.coindesk.com/chainalysis-says-bitcoin-scammed-fr... "The most prevalent address received $120,000 in bitcoin from 375 transactions. Secondary addresses received $6,700 in bitco…
Re: An update on our security incident
#268To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…
it is unlikely but not inconceivable that a bunch of accounts would tweet a similar solicitation, so obviously they needed enough data before knowing for sure twitter was under attack.So that meant the attacker probably had a solid 30-60 minutes of being undeterred. Even if a considerable number of people get scammed, the lost ad revenue would from shutting down the site would vastly exceed the cost of some users lea…
Re: An update on our security incident
#269To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…
If total shutdown you suggest was done, I'd consider it a successful DoS attack.
Re: An update on our security incident
#270To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…
I think that the fact the world will continue to spin without twitter is exactly why the hesitated to make that type of call.