Live data from Hacker News

An update on our security incident

blog.twitter.com

261–270 of 308 posts

Re: An update on our security incident

#261

>For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account’s information through our “Your Twitter Data” tool. Yikes. Pretty much a confirmation of the speculation that the hackers would have access to Twitter DMs. Question is, which accounts? edit: For reference, here's what's included in the "Your Twitter Data" tool [0]. There's some other info that may be o…

maybe a girlfriend or ex girlfriend . or a rival hacker. or someone who is believed to own a lot of crypto and is low profile.

Maybe they discovered Satoshi Nakamoto's Twitter account :D

Re: An update on our security incident

#262

Earlier quoted context omitted.

Technical solutions can always be defeated by social engineering. Training is supposed to prevent that.

How do you socially engineer someone to compromise their U2F-based dongle?

When U2F is widely used, there will be more social engineering tricks - like, visit this attacker website or download this tool/browser extension, put cursor in box, now please touch your key to verify your identity.

Countless creative ways will be tried and discovered.

Re: An update on our security incident

#263
post #183

Like many of you, I watched this rolling on Wednesday night using live verified accounts link that was widely shared. I was also just looking at the 'regular people' tab without verified accounts and saw many, many, many accounts tweeting the same "double your bitcoin" link, with the same BTC address. These weren't retweets. I'd assumed these accounts had also been compromised - was I wrong? It was far more than 130…

>Or was this just people copying and pasting the same message (if so why that rather than retweet)? There were so many every few seconds I assumed it was a script just running through accounts. But --- if it wasn't, what were people hoping to gain? Views on their own profile?

Cashing in on the public attention. Social media is filled with people who would debase themselves for a little bit of attention or likes. The hack caused a lot of uproar, what better way than pretending you're were high-profile enough to be hacked too?

Re: An update on our security incident

#264

I think the Bitcoin scam is a red herring.

What could it be distracting from, or what would be the purpose of running a smaller/dumber attack before the actual one?

That kinda depends on the "up to eight accounts" the attacker downloaded the data for.

Re: An update on our security incident

#265

Earlier quoted context omitted.

I'm not sure what you're thinking, but it's perfectly reasonable. People like you're talking about don't communicate anything of value over twitter. Bezos only follows his ex-wife who doesn't follow him back, barely uses twitter and would be unlikely to have any DMs at all. After the saudi hack, I would be surprised if he has much of anything installed on his phone. The only real reason to hack celebrity accounts in…

I always thought high profile accounts are run by media teams. I doubt the account owners know the credentials themselves or have direct access in most cases.

I’m pretty positive Elon’s account is NOT run by a media team :D

Re: An update on our security incident

#266
post #241
post #237

Earlier quoted context omitted.

Exactly. It's Twitter; nothing of value was lost. The recreationally outraged cancel mob had a minor setback.

If the hackers had access to the DMs, stuff of value could have been lost.

I have received multiple requests for opening my DMs to people and I always tell them to mail me. I don't consider Twitter capable of storing sensitive data.

Re: An update on our security incident

#267
post #218

Earlier quoted context omitted.

Disabling everything would have been quicker, and there's no way they could have been certain which accounts were compromised, certainly not so early. Even now - you have to make do with the traces the attackers leave behind, but it's unlikely you have complete certainty that some traces weren't removed, or fallback backdoors perhaps placed. Also, disabling everything would have likely been only a very short term sol…

> How many people saw the tweets and transferred bitcoins during the period in which twitter likely could have turned off everthing, but not yet blocked access to the respective accounts At most 475 greedy idiots, average $266 each https://www.coindesk.com/chainalysis-says-bitcoin-scammed-fr... "The most prevalent address received $120,000 in bitcoin from 375 transactions. Secondary addresses received $6,700 in bitco…

The fact that the damage was minimal did not mean it had to stay minimal. That's like saying let's not raise the dikes because this time we didn't flood everywhere.

Re: An update on our security incident

#268

To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…

it is unlikely but not inconceivable that a bunch of accounts would tweet a similar solicitation, so obviously they needed enough data before knowing for sure twitter was under attack.So that meant the attacker probably had a solid 30-60 minutes of being undeterred. Even if a considerable number of people get scammed, the lost ad revenue would from shutting down the site would vastly exceed the cost of some users lea…

Sorry, but no. Even after the first tweet that I saw from Gates' account I immediately told people there is a hack in progress. Simply because the contents of the tweet did not make sense. Bill Gates is not going to ruin his reputation like that and asking for $1000 to send $2000 back is nonsense, a $.01 would have been enough to signal intent, $1000 is a clear indication you're being had.

Re: An update on our security incident

#269

To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…

If total shutdown you suggest was done, I'd consider it a successful DoS attack.

That would have been fine. A DoS is not nearly as bad a what could have happened had the attackers pressed their luck or been more malicious.

Re: An update on our security incident

#270

To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…

I think that the fact the world will continue to spin without twitter is exactly why the hesitated to make that type of call.

There is a scene in The Simpsons where TV stops working and the children suddenly have to go outside and play. Great happiness ensues. That is exactly the scene I imagine if Twitter were turned off.
Post reply on HN