Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

1–10 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#3
post #2

This is why internal tools that can modify account settings and such need to have audit trails.

I would be really surprised if they did not have audit trails. What gives you the impression they did not? The suspicion is that the credentials were stolen via social engineering. I wonder if employees needed 2FA to log in to these tools.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#5
post #4
post #2

This is why internal tools that can modify account settings and such need to have audit trails.

It probably does, and it probably wouldn't have stopped this.

> probably wouldn't have stopped this.

Uh yes, that is how audit trails work

Re: More than 1k people at Twitter had ability to aid hack of accounts

#7
post #5
post #4

Earlier quoted context omitted.

It probably does, and it probably wouldn't have stopped this.

> probably wouldn't have stopped this. Uh yes, that is how audit trails work

How does auditing itself prevent a present or future attack? Auditing and what you fix during audits are reactive.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#8
post #5
post #4

Earlier quoted context omitted.

It probably does, and it probably wouldn't have stopped this.

> probably wouldn't have stopped this. Uh yes, that is how audit trails work

Can we do without the condescending "Uh" and "Um" on HN?

An audit trail would tell you who was social-engineered, but it wouldn't have prevented the attack in the same way Wikipedia's revision history doesn't keep you from vandalizing it.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#9
post #5
post #4

Earlier quoted context omitted.

It probably does, and it probably wouldn't have stopped this.

> probably wouldn't have stopped this. Uh yes, that is how audit trails work

And in today's "Pompous Commenter That Didn't Read the Article News":

>But while logging helps with investigations, only alarms or constant reviews can turn logs into something that can prevent breaches.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#10
post #7
post #5

Earlier quoted context omitted.

> probably wouldn't have stopped this. Uh yes, that is how audit trails work

How does auditing itself prevent a present or future attack? Auditing and what you fix during audits are reactive.

It's like saying a boat's wake slows down the boat. Sometimes you've just got to wonder what people are thinking
Post reply on HN