Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

21–30 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#21

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

Do they? There are usually levels of access and the bigger the change the more approval you need. Some things can only be done by an entirely separate team with manager sign off and other oversight.

It seems like Twitter has none of this, and while you can argue it's not the same a banking, there are still sensitive communications and there's no real reason why anyone should be able to post new tweets or access private messages without several approvals.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#22

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

[deleted]

Re: More than 1k people at Twitter had ability to aid hack of accounts

#23
post #7
post #5

Earlier quoted context omitted.

> probably wouldn't have stopped this. Uh yes, that is how audit trails work

How does auditing itself prevent a present or future attack? Auditing and what you fix during audits are reactive.

100%. My work has really great auditing tools. I use them often to understand actions by other that are routine. It still doesn't prevent a employee emailing a datacenter to rack a malicious device or give someone service without paying. Record trails are not auditing. They are records.

Auditing, post mortems, whatever diagnose the situation afterwards.

At the end of the day Uber can't stop a driver from kidnapping people, but it can provide documentation and gps coordinates to police.

My point is companies need reasonable records and audit policies and when _really bad stuff happens_ you call in the big guns for the arm of the law.

At some point you also need to trust staff and weigh that against mistakes and malicious intent.

In short, security remains an imperfect balance of practicality

Re: More than 1k people at Twitter had ability to aid hack of accounts

#24

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

Do they? There are usually levels of access and the bigger the change the more approval you need. Some things can only be done by an entirely separate team with manager sign off and other oversight. It seems like Twitter has none of this, and while you can argue it's not the same a banking, there are still sensitive communications and there's no real reason why anyone should be able to post new tweets or access priva…

> and there's no real reason why anyone should be able to post new tweets or access private messages without several approvals.

Unless new information has emerged recently, this wasn't the attack vector. The attack was resetting account emails/passwords and turning off 2FA.

I agree that there should have been more protections around this, but it's hardly newsworthy that Twitter employs a large support team to support their large userbase - my main gripe is with how the headline is framed.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#25
twitter, seems to have a cowboy engineering culture. that's why one of their exec's blamed rails for their failure to combat harassment[0]. n I bet now, if they still ran rails, it would've been blamed lol.

[0]: https://char.gd/recharged/daily/twitter-blames-ruby-on-rails...

Re: More than 1k people at Twitter had ability to aid hack of accounts

#26
post #25

twitter, seems to have a cowboy engineering culture. that's why one of their exec's blamed rails for their failure to combat harassment[0]. n I bet now, if they still ran rails, it would've been blamed lol. [0]: https://char.gd/recharged/daily/twitter-blames-ruby-on-rails...

"...a rudimentary web-application framework that made it nearly impossible to find a technical solution to the harassment problem"

To me, this is analogous to the perhaps undeserved "the internet is a series of tubes" lampooning, but I'm still chuckling how they managed to word that so poorly.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#27

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

> The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools.

Spear-phishing by its very definition is a highly targeted attack. I wouldn't count on any level of training to prevent someone from getting phished. Given some of the spear phishing campaigns I've seen, I wouldn't trust even myself not to fall for them.

It's a problem that needs to be solved with technical solutions like hardware U2F, locked-down customer support devices (e.g. Chrome enterprise policy managed ChromeOS devices), and special account VIP/anomaly locking and auto-escalation.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#28

Earlier quoted context omitted.

Do they? There are usually levels of access and the bigger the change the more approval you need. Some things can only be done by an entirely separate team with manager sign off and other oversight. It seems like Twitter has none of this, and while you can argue it's not the same a banking, there are still sensitive communications and there's no real reason why anyone should be able to post new tweets or access priva…

> and there's no real reason why anyone should be able to post new tweets or access private messages without several approvals. Unless new information has emerged recently, this wasn't the attack vector. The attack was resetting account emails/passwords and turning off 2FA. I agree that there should have been more protections around this, but it's hardly newsworthy that Twitter employs a large support team to support…

There's not much detail but how would they gain access from a password reset if they didn't have access to the email account? And if they had email access then they already have everything.

The reset via admin tools must have bypassed the normal email workflow.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#29

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

"There's thousands of people that have the ability to drain your bank account right now"

Do you have some data to back that up?

Sounds implausible

Re: More than 1k people at Twitter had ability to aid hack of accounts

#30
post #15

Earlier quoted context omitted.

It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it: > Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees." https://www.npr.org/2019/11/06/777098293/2-former-twitter-em... 1,000 people, in…

> 1,000 people, including contractors outside the company, is not a "limited group of trained and vetted employees." That's not necessarily true. 20% of the company could fairly reasonably be deemed "limited", and there being a thousand of them doesn't mean they're not trained on their tasks.

We'll have to agree to disagree on what we consider fairly reasonable to call "limited".
Post reply on HN