Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

71–80 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#71

Earlier quoted context omitted.

Thousands of employees, each with their own financial problems and dreams...you're bound to find a taker. Money moves mountains

Which is why once your company is big enough, you should need 2 employees who are unfamiliar to each other to sign off on high value operations.

Bingo. Corrupting two is much less likely.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#72

Ha! Did you see in that article that the head of cyber security for AT&T added his two cents in shaming Twitter? AT&T was just in the news recently where employees were accepting bribes that allowed criminals to swap SIMs steal bitcoins from AT&T customers. Unbelievable.

I have a lot of sympathy for the telcos on this.

They did not volunteer telephone numbers as universal proof of ID. So their threat model was proportional to their intended purpose of the identifier. If bad guys steal your phone number and run up $100 of calls, the phone company would eat the charges and get the number back. Of course nobody did that because it wasn't worth it.

Imagine you own a medium-sized residential building, maybe 20 households live there. You issue them all with front door keys. You use pretty good locks, from a no-duplicate series that isn't trivially picked by amateurs. You figure that picking the door or forging a key would be pretty hard so there's no way it's worth it when someone could just kick it down.

Then, to your astonishment, a local jewellery store announces that anyone who has one of your front door keys can now store up to $1M of valuables in safes they've made accessible from the street. "It's totally safe" they assure your residents, "because how could anybody else get one of these front door keys? That'd be impossible".

Um. What? Before you know what's happening, one of your residents is trying to sue you for a million dollars because they proudly used a safe to store their $1M of Bitcoins for some crazy reason and (duh) somebody just got a duplicate key easily enough for way less than $1M and stole them.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#73
post #15

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it: > Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees." https://www.npr.org/2019/11/06/777098293/2-former-twitter-em... 1,000 people, in…

1000 people absolutely is limited - it's not everyone at the company! I'm sure they did their annual security training, like everyone here, and they might have even passed an additional screening and another training session for account access.

You have unreasonable expectations for what "limited group of trained and vetted employees" means in a CSR environment for millions of customers.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#74

Earlier quoted context omitted.

> 1,000 people, including contractors outside the company, is not a "limited group of trained and vetted employees." That's not necessarily true. 20% of the company could fairly reasonably be deemed "limited", and there being a thousand of them doesn't mean they're not trained on their tasks.

Today I learned that Twitter has 4,600 employees. What are they all doing?

Support, operations, legal, purchasing, finance, marketing, development, and management.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#75

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

‘Two people’ misses the entire problem here.

If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this address arrived on this date containing that token, establishing that this person had control over that email address on that date’.

If random twitter admins can change the email address and disable 2fa on verified twitter accounts, and those accounts can still publish tweets without them going into a ‘held pending verification that the blue check mark still applies to the person now in control of that account’ queue, then twitter verification doesn’t mean much.

Which might be of interest to organizations like the SEC who hold that communications over a verified twitter account count as official corporate notices, and various public safety organizations that have let it be known that messages on their twitter can be relied on as a source of official information during natural disasters...

Twitter needs to get serious about blue checks.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#76

Ha! Did you see in that article that the head of cyber security for AT&T added his two cents in shaming Twitter? AT&T was just in the news recently where employees were accepting bribes that allowed criminals to swap SIMs steal bitcoins from AT&T customers. Unbelievable.

I have a lot of sympathy for the telcos on this. They did not volunteer telephone numbers as universal proof of ID. So their threat model was proportional to their intended purpose of the identifier. If bad guys steal your phone number and run up $100 of calls, the phone company would eat the charges and get the number back. Of course nobody did that because it wasn't worth it. Imagine you own a medium-sized resident…

I cannot find fault in that analogy.

Maybe only add that the whole city starts to run on your keys and you have been seeing this for years already.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#77

Earlier quoted context omitted.

Which is why once your company is big enough, you should need 2 employees who are unfamiliar to each other to sign off on high value operations.

Bingo. Corrupting two is much less likely.

The key trick isn't so much the two as that they're randomly selected.

I moved a large amount of money a few years back to buy my home (I do not like debt, so I saved up until I could afford somewhere to live, then I bought it)

The bank's web site lets you type in any amount of money but then it says politely that you can't do this from the web site, please call the bank.

I called the bank (they always pick up in 2-3 rings, I've worked with one of their founders, ensuring this was one of the key ideas behind the bank) and explained what I wanted to do. The nice lady took down all the details and then she explained that now one of her colleagues would be randomly selected to call me back and confirm everything and we hung up.

Sure enough, less than a minute later another of the people from the bank called (with the agreed password for when the bank calls me) and had me read out all the transaction details again, at which point the transaction was confirmed.

Think about that scenario as a bad guy trying to corrupt it. You bribe one employee to pretend someone called and authorised a huge transfer. OK. But then a different random employee has to confirm it. How do you bribe them? You have no way to know who it will be! Do you try just bribing every single employee who works the phones? Not very practical.

The other thing banks do is they background check employees. You can't test for "willing to take bribes" but you can weed out potential hires with previous convictions for financial crime, or debt problems. I've had checks like that for jobs touching sensitive personal information.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#78
post #60

Earlier quoted context omitted.

How about we don’t start wars based off a twitter feed?

In an ideal world, world leaders would all have restrained enough Twitter habits such that anything that inflammatory would be seen as an obvious signal that their account was compromised.

It is not about bad habits, it's a systemic problem.

World leaders are also politicians that need to maintain their internal position (even dictators need to at least prevent a coup). So when they spew inflammatory rubbish it's often to appear tough to their internal audience, often at the cost of the interest of their own country.

This ideal world has to figure out how to deal with this conflict of interest.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#79
For comparison, at Google in 2011, I was one of ~10 or so engineers that had the ability to view private Gmail or Gplus data (access that was heavily documented and audited).

That being said, Google did have to go through it's own public humiliation [1] to put a system like that in place.

https://gawker.com/5637234/gcreep-google-engineer-stalked-te...

Re: More than 1k people at Twitter had ability to aid hack of accounts

#80
post #33

Earlier quoted context omitted.

> The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools. Spear-phishing by its very definition is a highly targeted attack. I wouldn't count on any level of training to prevent someone from getting phished. Given some of the spear phishing campaigns I've seen, I wouldn't trust even myself not to fall for them. It's a problem that n…

It's very easy to avoid being spear phished: do not trust any unsolicited message over any medium. Email/text/phone message/popup window purporting to be from your registrar with an urgent call to action? Ignore said call and contact them directly via known good number, email address, URL, etc. EDIT: Voice mimicry scam? Verify via known channel before taking action.

The question isn't how you and I can individually avoid being spear phished, but what policies can be implemented across an organization to prevent it. Even the most trusted security teams aren't going to be allowed to summarily fire everyone who fails the test.

I also think this is a much stricter standard than you're recognizing. In my company's last spearphishing test, they sent out a link purporting to be a company survey immediately after an all-hands meeting announcing there'd be a survey (the real survey link came a few hours later). Expecting that nobody will be distracted enough to fall for such a thing seems unrealistic no matter how well you train them.

Post reply on HN