Live data from Hacker News

An update on our security incident

blog.twitter.com

281–290 of 308 posts

Re: An update on our security incident

#281

Earlier quoted context omitted.

> Bezos only follows his ex-wife who doesn't follow him back I honestly didn't believe you. But it's true. That's... kinda weird.

Probably a dead account he no longer access it before divorce, hence the awkward status

Hmm, I don't think so. The account has tweeted as recently as Feb of this year, but his divorce was finalized in July 2019.

Re: An update on our security incident

#282

Earlier quoted context omitted.

This is by far the most eyebrow-raising part of the update. To take over such a large number of verified accounts and then run a download on only eight non-verified ones seems almost impossible to have been anything other than targeted. The original idea that the bitcoin scam was a diversion starts to look more plausible in this light, but in the absence of any information about the downloaded accounts, there’s reall…

> in the absence of any information about the downloaded accounts, there’s really no way to guess what their value may have been and to whom One possibility I can think of is that a state actor, such as China, was investigating state enemies, such as suspected dissidents. They wanted to get the DMs, but also didn't want the general public to catch on. So they set things up so public discourse would be centered around…

If it was a state actor, they'd definitely want access to elon musk's DMs. He hasn't showed a ton of restraint in social media, and he's the CEO of a rocket company that has done some classified launches. And many of these verified users that were hacked have significant roles internationally, whether in trade like with amazon or politically like biden, or with international aid organizations like gates.

Re: An update on our security incident

#283
post #260
post #9

> did the attackers see any of my private information? For the vast majority of people, we believe the answer is, no. This is such a weasel-y answer. “Yes, most of Earth’s population was not affected by this breach” - sure, but those that were affected, how would you be certain that they didn’t have their private information, such as DMs, pulled?

Yes, I also thought that part is fishy. They also said "don't worry, no passwords were visible" (I don't think any tech person would expect them to store passwords in plain text), then continue saying that email address, phone number and possibly other personal info was accessible. So, the answer should be yes? Also, the initial question is about "me". I also never considered that my own data would have been accessib…

They need to write this for their entire audience, most of whom has no idea what plain text even means. Also it was only a year ago that Facebook was found to have stored passwords in plain text so it's definitely a concern. Twitter has an excellent engineering blog so I'm looking forward to reading more technical details there if they publish any.

Re: An update on our security incident

#284

Earlier quoted context omitted.

> There is a lot speculation about the identity of these 8 accounts. We will only disclose this to the impacted accounts, however to address some of the speculation: none of the eight were Verified accounts.[0] [0]: https://twitter.com/TwitterSupport/status/128433914877449830...

>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…

Hmmm, if we want to assume this is still related to high-profile blackmail material, it's possible they were downloading the DMs from accounts messaged by verified accounts.

AFAIK, deleting Twitter DMs only deletes the conversation from your end, so if the verified user, worried about this exact situation, periodically deletes their DMs, but the unverified user, not nearly so worried, doesn't...

Re: An update on our security incident

#285

Earlier quoted context omitted.

I always thought high profile accounts are run by media teams. I doubt the account owners know the credentials themselves or have direct access in most cases.

I’m pretty positive Elon’s account is NOT run by a media team :D

His media team works behind the counter at the pot dispensary.

Re: An update on our security incident

#286

I like how Twitter wrote this post. It's apologetic, transparent, and clear. I feel like Cloudflare and Twitter have been really good with communicating what has happened and that is impressive. I'm glad these companies have learned from others' mistakes. Being transparent is the starting point of gaining back lost trust.

Agree, this is transparent, self aware, and takes responsibility. Kudos to Twitter. It's in stark contrast to how FB wrote the post this week about their SDK crashing a bunch of third party apps. Some PR firm did all sorts of verbal gymnastics to avoid actually apologizing and taking real responsibility by shifting blame. [1] [1] https://news.ycombinator.com/item?id=23827885

I've been a big fan of Twitter's engineering blog and how they're able to give historical context for why they made certain decisions. For example this recent post about search indexing could have been a university lecture:

https://blog.twitter.com/engineering/en_us/topics/infrastruc...

Re: An update on our security incident

#287

Earlier quoted context omitted.

> in the absence of any information about the downloaded accounts, there’s really no way to guess what their value may have been and to whom One possibility I can think of is that a state actor, such as China, was investigating state enemies, such as suspected dissidents. They wanted to get the DMs, but also didn't want the general public to catch on. So they set things up so public discourse would be centered around…

If it was a state actor, they'd definitely want access to elon musk's DMs. He hasn't showed a ton of restraint in social media, and he's the CEO of a rocket company that has done some classified launches. And many of these verified users that were hacked have significant roles internationally, whether in trade like with amazon or politically like biden, or with international aid organizations like gates.

Depends on the organization I guess. I can imagine some orgs only caring about internal affairs and not gathering international Intel.

Re: An update on our security incident

#288

Earlier quoted context omitted.

>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…

This is by far the most eyebrow-raising part of the update. To take over such a large number of verified accounts and then run a download on only eight non-verified ones seems almost impossible to have been anything other than targeted. The original idea that the bitcoin scam was a diversion starts to look more plausible in this light, but in the absence of any information about the downloaded accounts, there’s reall…

What if the 8 accounts were people who might plausibly know who Satoshi is.

Re: An update on our security incident

#289
post #258

Earlier quoted context omitted.

> Also timeline says ‘Wednesday’ post-mortem should be accurate to the minute or second. That's because it took them almost two hours to stop the attack - doesn't look good.

is two hours really that long?

When you have heads of state making insane executive proclamations via your platform, and you know that your weak sauce security is compromised — yes, it’s way too long.

Re: An update on our security incident

#290
post #237

Earlier quoted context omitted.

Exactly. It's Twitter; nothing of value was lost. The recreationally outraged cancel mob had a minor setback.

hah! "The recreationally outraged cancel mob" FWIW, I actually enjoy twitter and get plenty of value from it (by selectively following interesting, intelligent people who post about things I care about) ... but your description is pretty funny -- and probably apt, at least for a sizable % of its users.

I personally had to leave twitter. I found a lot of value from it but despite keeping what I followed to a strict curated list, the 'outrage mob' seemed to always bleed into feed. Unfortunately it wasn't worth the value I got out of Twitter
Post reply on HN