More than 1k people at Twitter had ability to aid hack of accounts
11–20 of 238 posts
Re: More than 1k people at Twitter had ability to aid hack of accounts
#12As a developer, it frustrates the shit of out me because I can’t deploy fixes quickly or easily diagnose issues.
But yep, there are 3 people that have access to the production databases that hold account info and they aren’t developers, just managers with no clue what to do once they log in.
I also worked for a company that sold software to lawyers. We had a feature that would alert the client any time a member of our company accessed their data. I think we called the feature something like “fire call”, because if you tripped it without informing the client, you’d get a call informing you that you’d been fired.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#13This is why internal tools that can modify account settings and such need to have audit trails.
I would be really surprised if they did not have audit trails. What gives you the impression they did not? The suspicion is that the credentials were stolen via social engineering. I wonder if employees needed 2FA to log in to these tools.
https://blog.twitter.com/en_us/topics/company/2020/an-update...
Re: More than 1k people at Twitter had ability to aid hack of accounts
#14Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .
For example, education programs do squat against me attacking the employees directly (targeted malware, getting on their computer somehow, offering each of the thousands of employees $10,000 for temp access to their account). And each additional employee only strengthens my attack.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#15Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .
> Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees."
https://www.npr.org/2019/11/06/777098293/2-former-twitter-em...
1,000 people, including contractors outside the company, is not a "limited group of trained and vetted employees." It's news because they misled people about their security, again.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#16Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .
Re: More than 1k people at Twitter had ability to aid hack of accounts
#17I now understand why the bank I work for creates the separation of duties; the person who builds the system has no access to it, and the person with access has no idea how it works. As a developer, it frustrates the shit of out me because I can’t deploy fixes quickly or easily diagnose issues. But yep, there are 3 people that have access to the production databases that hold account info and they aren’t developers, j…
Just for my curiosity is this your observation or is this a company assumption?
Re: More than 1k people at Twitter had ability to aid hack of accounts
#18Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .
It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it: > Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees." https://www.npr.org/2019/11/06/777098293/2-former-twitter-em... 1,000 people, in…
That's not necessarily true. 20% of the company could fairly reasonably be deemed "limited", and there being a thousand of them doesn't mean they're not trained on their tasks.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#19Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .
It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it: > Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees." https://www.npr.org/2019/11/06/777098293/2-former-twitter-em... 1,000 people, in…
Anyway, even if they had provided a figure, I think you're taking it out of context - the quote says access to "sensitive account information" is limited, not access to account recovery options. So it's potentially someone outside of that limited group whose credentials were compromised.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#20Earlier quoted context omitted.
It probably does, and it probably wouldn't have stopped this.
> probably wouldn't have stopped this. Uh yes, that is how audit trails work
If they have logs then they can use it in the future (and it seems they do) to design better protections but only active alarms and security controls can prevent something happening in real-time.
However that does raise the question of why Twitter ever needs such access to someone's account in the first place, especially without a combination of approvals to get that access.