Earlier quoted context omitted.
There are already organisations that have to control employee access to ‘customer’ data very tightly. Law enforcement. Law enforcement agencies have access to large databases full of people along with a huge amount of very sensitive data (both confidential personal data, and stuff like information about ongoing and typically covert investigations). I’ve worked with several of these types of organisations and the ones…
> There are already organisations that have to control employee access to ‘customer’ data very tightly. How about... anybody who has customers in the EU?
More than 1k people at Twitter had ability to aid hack of accounts
81–90 of 238 posts
Re: More than 1k people at Twitter had ability to aid hack of accounts
#82Earlier quoted context omitted.
I actually had a similar idea for fighting SIM swaps—we should be able to ask telecoms "hey, when's the last time this phone number was moved to another device/changed IMEI numbers?" and distrust the number if it's been changed less than 48 hours ago. I've looked but as far as I can tell, such an API does not exist, alas.
The problem is with POTS, you dont have that kind of capability in the protocol, even Caller ID cannot be verified. Most network will trust whatever is being sent. It is like SMTP it was designed in era where security was simply not there.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#83Earlier quoted context omitted.
> there are 3 people that have access to the production databases that hold account info and they aren’t developers, just managers with no clue what to do once they log in. Just for my curiosity is this your observation or is this a company assumption?
Hmm I think it’s just our group, we have a Production support team that holds the keys, and there’s only 3 of them that can access my app. For example, if I want to change an environment variable, I can’t just log into the cloud console or run a cli command. God no. That would be too easy. I have to write a script for this team to run. This script is entered into an authorization app where a few parties “sign off”, a…
Re: More than 1k people at Twitter had ability to aid hack of accounts
#84Earlier quoted context omitted.
I once had to restore my Authy 2FAs from a backup, and didn't have access to the original device. Restoring it took 24 hours, during which I got bombarded with text messages and emails warning me that someone was restoring my backup, and that if it wasn't me, I should immediately click or reply to prevent it from happening. Seems like that might help - a 24 hour waiting period on any significant account changes for v…
I actually had a similar idea for fighting SIM swaps—we should be able to ask telecoms "hey, when's the last time this phone number was moved to another device/changed IMEI numbers?" and distrust the number if it's been changed less than 48 hours ago. I've looked but as far as I can tell, such an API does not exist, alas.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#85Earlier quoted context omitted.
It's very easy to avoid being spear phished: do not trust any unsolicited message over any medium. Email/text/phone message/popup window purporting to be from your registrar with an urgent call to action? Ignore said call and contact them directly via known good number, email address, URL, etc. EDIT: Voice mimicry scam? Verify via known channel before taking action.
The question isn't how you and I can individually avoid being spear phished, but what policies can be implemented across an organization to prevent it. Even the most trusted security teams aren't going to be allowed to summarily fire everyone who fails the test. I also think this is a much stricter standard than you're recognizing. In my company's last spearphishing test, they sent out a link purporting to be a compa…
Re: More than 1k people at Twitter had ability to aid hack of accounts
#86Re: More than 1k people at Twitter had ability to aid hack of accounts
#87Title corrected : More than 1k people at Twitter had ability to aid hack and chose not to.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#88Re: More than 1k people at Twitter had ability to aid hack of accounts
#89Re: More than 1k people at Twitter had ability to aid hack of accounts
#90Earlier quoted context omitted.
I think the long tail was in undoing the actions made by the attackers. Resetting passwords, emails, etc.,.
No, according to The Block, @elonmusk repeatedly tweeted the scam at 4:17pm, 5:19pm, and 5:32pm, a span of 90 minutes, and the final scam tweet was at 6:05pm from @KimKardashian. An hour after @elonmusk's first scam tweet, 7 celebrity or corporate accounts had tweeted the scam, all with the same Bitcoin address. With the two-click system I described, how many compromised admin accounts would you expect the security t…
Sure, it's a sucky position to be in, but I can see why they might have been hesitant to dive right in and start trying to undo damage before understanding what had happened.