Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

51–60 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#51

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

I once had to restore my Authy 2FAs from a backup, and didn't have access to the original device. Restoring it took 24 hours, during which I got bombarded with text messages and emails warning me that someone was restoring my backup, and that if it wasn't me, I should immediately click or reply to prevent it from happening. Seems like that might help - a 24 hour waiting period on any significant account changes for v…

I actually had a similar idea for fighting SIM swaps—we should be able to ask telecoms "hey, when's the last time this phone number was moved to another device/changed IMEI numbers?" and distrust the number if it's been changed less than 48 hours ago.

I've looked but as far as I can tell, such an API does not exist, alas.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#52
post #48

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

That just won’t work. Just target the attack in the middle of the night or lunch hour. Furthermore, the next attack will probably be automated and be against far, far more accounts.

Yeah, response time might be slower in the middle of the night, but a falsified tweet on a celebrity account in the middle of the night is also likely proportionally less damaging.

Response time during lunch hour might be slower initially, but after responding to the first compromised account I don't think they'd be any slower.

If an admin account is only supposed to be for use by a human employee, it should have a rate-limit tripwire that automatically suspends the account and alerts the security team.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#53
post #48

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

That just won’t work. Just target the attack in the middle of the night or lunch hour. Furthermore, the next attack will probably be automated and be against far, far more accounts.

Twitter is a big company - they’ll have someone available 24/7

Re: More than 1k people at Twitter had ability to aid hack of accounts

#55

Earlier quoted context omitted.

I once had to restore my Authy 2FAs from a backup, and didn't have access to the original device. Restoring it took 24 hours, during which I got bombarded with text messages and emails warning me that someone was restoring my backup, and that if it wasn't me, I should immediately click or reply to prevent it from happening. Seems like that might help - a 24 hour waiting period on any significant account changes for v…

I actually had a similar idea for fighting SIM swaps—we should be able to ask telecoms "hey, when's the last time this phone number was moved to another device/changed IMEI numbers?" and distrust the number if it's been changed less than 48 hours ago. I've looked but as far as I can tell, such an API does not exist, alas.

Something like Require-Recipient-Valid-Since from SMTP? That would be neat. Does SMS have the necessary protocol flexibility to allow that to be added?

Re: More than 1k people at Twitter had ability to aid hack of accounts

#56

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

There are already organisations that have to control employee access to ‘customer’ data very tightly. Law enforcement. Law enforcement agencies have access to large databases full of people along with a huge amount of very sensitive data (both confidential personal data, and stuff like information about ongoing and typically covert investigations).

I’ve worked with several of these types of organisations and the ones that actually want to manage that access well, typically do a pretty good job (though some of them actually want to do it badly, or just don’t care).

Locking down access to sensitive admin consoles isn’t tremendously difficult, requiring additional approval workflows for highly sensitive operations isn’t particularly difficult, and in that context non-repudiation is rather simply to address.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#57
post #15

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it: > Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees." https://www.npr.org/2019/11/06/777098293/2-former-twitter-em... 1,000 people, in…

> 1,000 people, including contractors outside the company, is not a "limited group of trained and vetted employees." It's news because they misled people about their security, again.

I don't think this is misleading at all. Your bank probably has thousands of people who can get equivalent access to your account, and they serve a lot less people than Twitter, and mostly during business hours, in one language, in one country.

1000 people in total when they have to have some available 24/7 isn't many.

Say 200 of them are individual technical staff with access for specific debugging purposes. Then it's only 200 people per 8 hour shift.

There's probably requirements for specific language support too, which increases the head count. There was a period of time some years ago when Twitter's peak usage was from Japan, in Japanese hours, in Japanese language.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#58
post #15

Earlier quoted context omitted.

It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it: > Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees." https://www.npr.org/2019/11/06/777098293/2-former-twitter-em... 1,000 people, in…

> 1,000 people, including contractors outside the company, is not a "limited group of trained and vetted employees." That's not necessarily true. 20% of the company could fairly reasonably be deemed "limited", and there being a thousand of them doesn't mean they're not trained on their tasks.

Everyone having access but James the Janitor is technically limited access too.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#59

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

How about we don’t start wars based off a twitter feed?

Re: More than 1k people at Twitter had ability to aid hack of accounts

#60

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

How about we don’t start wars based off a twitter feed?

In an ideal world, world leaders would all have restrained enough Twitter habits such that anything that inflammatory would be seen as an obvious signal that their account was compromised.
Post reply on HN