Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

41–50 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#41
post #15

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it: > Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees." https://www.npr.org/2019/11/06/777098293/2-former-twitter-em... 1,000 people, in…

I'm sure they took a web training before being handed the keys to the kingdom.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#42

I now understand why the bank I work for creates the separation of duties; the person who builds the system has no access to it, and the person with access has no idea how it works. As a developer, it frustrates the shit of out me because I can’t deploy fixes quickly or easily diagnose issues. But yep, there are 3 people that have access to the production databases that hold account info and they aren’t developers, j…

It's actually fine to have multiple people get access to production databases, if you have an automated change management system.

Change Management authorize sactions which could be problematic by vetting them through a process. The end result of the process is more confidence in the change: we know who's making it, when, where, why, what the impact will be, what we'll do if it goes wrong, etc. If the change looks stupid, dangerous, or uncertain, it gets rejected. If it looks good, it gets approved. The appropriate access is doled out temporarily to make the change. In this way, Larry the Janitor can deploy changes to your prod db, and you can be just as certain (maybe more so?) about the outcome than if your 10x developer were doing it.

Just one example of this is Terraform applies. By loading your changes into a .plan file and requiring approval of the .plan, you know for certain what actions are going to be taken and approve only those. (That doesn't stop Terraform from totally hosing your system due to all the ways it can't predict the outcome of its actions, but at least you know what the intention was)

Re: More than 1k people at Twitter had ability to aid hack of accounts

#43

Earlier quoted context omitted.

> 1,000 people, including contractors outside the company, is not a "limited group of trained and vetted employees." That's not necessarily true. 20% of the company could fairly reasonably be deemed "limited", and there being a thousand of them doesn't mean they're not trained on their tasks.

Today I learned that Twitter has 4,600 employees. What are they all doing?

They have 35 offices, I assume it adds up.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#44

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

Also have a Slack channel for automated bot notes of high-value targets having their passwords reset, or something similar.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#45
post #15

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it: > Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees." https://www.npr.org/2019/11/06/777098293/2-former-twitter-em... 1,000 people, in…

It can be every employee except one and still be called "limited group of trained and vetted employees". It's written that way so that they covered their ass, it's not a statement of security.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#46

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

Yes but it's missing the fact that you can't actually drain an account even with access. The overall network is designed for rollbacks, but more importantly, they're internally insured. My money will be put back if someone inside steals it (outside is completely different).

With twitter, the damage is not practically reversible since it was a bitcoin scam.

The analogy/comparison works to a degree, but misses some key differences as to why this is actually worse with twitter than a bank.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#47
Ha!

Did you see in that article that the head of cyber security for AT&T added his two cents in shaming Twitter?

AT&T was just in the news recently where employees were accepting bribes that allowed criminals to swap SIMs steal bitcoins from AT&T customers.

Unbelievable.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#48

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

That just won’t work. Just target the attack in the middle of the night or lunch hour.

Furthermore, the next attack will probably be automated and be against far, far more accounts.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#49
post #39

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

I think the long tail was in undoing the actions made by the attackers. Resetting passwords, emails, etc.,.

No, according to The Block, @elonmusk repeatedly tweeted the scam at 4:17pm, 5:19pm, and 5:32pm, a span of 90 minutes, and the final scam tweet was at 6:05pm from @KimKardashian.

An hour after @elonmusk's first scam tweet, 7 celebrity or corporate accounts had tweeted the scam, all with the same Bitcoin address. With the two-click system I described, how many compromised admin accounts would you expect the security team to have been able to suspend by then?

8 more celebrity accounts went on to tweet the scam, plus @elonmusk and @kanyewest repeating the scam tweets.

https://www.theblockcrypto.com/post/71906/twitter-account-ha...

Re: More than 1k people at Twitter had ability to aid hack of accounts

#50
post #29

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

"There's thousands of people that have the ability to drain your bank account right now" Do you have some data to back that up? Sounds implausible

Certainly it will depend on who you bank with, but JPMorganChase has 250,000 employees[1]. If even 1% of them are customer service representatives, bank tellers, or in other positions with direct access to your account (which I hope we can agree is an underestimate), that's 2,500 people right there.

[1]: https://www.google.com/search?q=chase+employees

Post reply on HN