Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

31–40 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#31

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

> The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools. Spear-phishing by its very definition is a highly targeted attack. I wouldn't count on any level of training to prevent someone from getting phished. Given some of the spear phishing campaigns I've seen, I wouldn't trust even myself not to fall for them. It's a problem that n…

FWIW, this is actually quantifiable. We contract with a firm that tests employees' response to spear phishing about once a quarter with varying degrees of "difficulty". Part of an overall scheme that also identifies people who blindly click on things for, uh, further email education.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#32

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

> The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools. Spear-phishing by its very definition is a highly targeted attack. I wouldn't count on any level of training to prevent someone from getting phished. Given some of the spear phishing campaigns I've seen, I wouldn't trust even myself not to fall for them. It's a problem that n…

It’s only going to get worse. Imagine your boss calling you and telling you to provide him some info: https://www.wsj.com/articles/fraudsters-use-ai-to-mimic-ceos...

Re: More than 1k people at Twitter had ability to aid hack of accounts

#33

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

> The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools. Spear-phishing by its very definition is a highly targeted attack. I wouldn't count on any level of training to prevent someone from getting phished. Given some of the spear phishing campaigns I've seen, I wouldn't trust even myself not to fall for them. It's a problem that n…

It's very easy to avoid being spear phished: do not trust any unsolicited message over any medium. Email/text/phone message/popup window purporting to be from your registrar with an urgent call to action? Ignore said call and contact them directly via known good number, email address, URL, etc.

EDIT: Voice mimicry scam? Verify via known channel before taking action.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#34

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

There's a difference though. The money you lost can be returned in the case of theft, which happens a lot. But Twitter cannot undo what happened here.

Also I don't think thousands of call center people typically have sole ability to directly overwrite bank and brokerage key data fields.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#35

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

i dont think spear-phishing training is the solution here; especially given the possibility of collaborating insiders. Short social media usernames are bizarrely coveted and so there's an entire cottage industry based on illicitly commandeering accounts and these operations have used insiders working for cellular telephone companies who are paid to grease along processes like unauthorized SIM-swaps/porting.

For operations on accounts where illicit access can cause massive irreversible damage -- either by exfiltrating private information (emails, DMs/PMs, posts on locked accounts, etc) or by making a post that appears authorized (the more notable the victim the worse it gets) -- there has got to be some sort of two-man rule (https://en.wikipedia.org/wiki/Two-man_rule) integrated into the system that can't be bypassed by the people with authority to make changes to accounts. Otherwise any insider / careless spear-phishing victim will make the changes they want, and theres no reason the adversary will limit themselves to posting shoddily-executed (they used the same address instead of generating one per victim!) bitcoin scams.

Furthermore, i'd really like there a way for any user (not just bluechecks) to opt-in to some sort of feature where Twitter enforces more stringent requirements/documentation/delays for the email/phone-change / password-reset processes -- at the cost of accepting higher delays or maybe even monetary payment.

There's no reason i need such critical account procedures to happen on twitter (or my email accounts, for that matter) to happen in real-time, and i would happily give that up in order to require that such a procedure only happen after, like, a week of enforced, non-bypassable delay where they contact me with details of the change on all my phone-numbers and emails every day.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#36
post #5

Earlier quoted context omitted.

> probably wouldn't have stopped this. Uh yes, that is how audit trails work

Can we do without the condescending "Uh" and "Um" on HN? An audit trail would tell you who was social-engineered, but it wouldn't have prevented the attack in the same way Wikipedia's revision history doesn't keep you from vandalizing it.

It wouldn't even necessarily tell you who was social-engineered. My understanding of this case was that CS tool credentials were posted globally in their Slack.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#37
accounts with more than 10,000 followers should at least need two people to change key settings

For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me.

To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to the profile of the admin responsible, and a button to suspend that admin account with one click.

This way, the security team could've seen that Elon Musk's account had just been reset by J. Random Employee minutes before tweeting the suspicious bitcoin tweet, messaged J. on Slack to be like "hey did you do that?", and suspended the compromised admin account within minutes.

Sure, some accounts might be briefly compromised initially, but it would be resolved in minutes and not the hours that it took Twitter, right? That seems fine for what should be a relatively low-likelihood, high-expense attack like compromised admin account (of course, you have to ensure that is the case).

Re: More than 1k people at Twitter had ability to aid hack of accounts

#38
post #15

Earlier quoted context omitted.

It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it: > Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees." https://www.npr.org/2019/11/06/777098293/2-former-twitter-em... 1,000 people, in…

> 1,000 people, including contractors outside the company, is not a "limited group of trained and vetted employees." That's not necessarily true. 20% of the company could fairly reasonably be deemed "limited", and there being a thousand of them doesn't mean they're not trained on their tasks.

Today I learned that Twitter has 4,600 employees. What are they all doing?

Re: More than 1k people at Twitter had ability to aid hack of accounts

#39

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

I think the long tail was in undoing the actions made by the attackers. Resetting passwords, emails, etc.,.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#40

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

I once had to restore my Authy 2FAs from a backup, and didn't have access to the original device.

Restoring it took 24 hours, during which I got bombarded with text messages and emails warning me that someone was restoring my backup, and that if it wasn't me, I should immediately click or reply to prevent it from happening.

Seems like that might help - a 24 hour waiting period on any significant account changes for verified accounts.

Post reply on HN