Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

91–100 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#91
On a different note, online presence is becoming very important and with remote work culture gaining traction, having a good online presence has become a must have asset.

I bought a course on building Twitter audience and been able to improve my following significantly from past 2 months.

Twitter link: https://twitter.com/sunilc_

If you're looking to increase your social presence too, here's the course that I found very useful:

https://gumroad.com/a/238777459/PBkrO

Re: More than 1k people at Twitter had ability to aid hack of accounts

#92

Earlier quoted context omitted.

> and there's no real reason why anyone should be able to post new tweets or access private messages without several approvals. Unless new information has emerged recently, this wasn't the attack vector. The attack was resetting account emails/passwords and turning off 2FA. I agree that there should have been more protections around this, but it's hardly newsworthy that Twitter employs a large support team to support…

There's not much detail but how would they gain access from a password reset if they didn't have access to the email account? And if they had email access then they already have everything. The reset via admin tools must have bypassed the normal email workflow.

Admin tools used to change account email address to one attacker controlled, then password reset requested which now sends to the attacker controlled email address

Re: More than 1k people at Twitter had ability to aid hack of accounts

#94
post #29

Earlier quoted context omitted.

"There's thousands of people that have the ability to drain your bank account right now" Do you have some data to back that up? Sounds implausible

Certainly it will depend on who you bank with, but JPMorganChase has 250,000 employees[1]. If even 1% of them are customer service representatives, bank tellers, or in other positions with direct access to your account (which I hope we can agree is an underestimate), that's 2,500 people right there. [1]: https://www.google.com/search?q=chase+employees

And they all have access to all accounts? I would imagine only a bank teller from the appropriate branch would have access to this branch's accounts.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#95

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

> this sounds expensive and unnecessary to me

Should we be OK with what has become a significant communication platform being run with sub-par security because it's "expensive" to do it properly?

Re: More than 1k people at Twitter had ability to aid hack of accounts

#96

Earlier quoted context omitted.

Bingo. Corrupting two is much less likely.

The key trick isn't so much the two as that they're randomly selected. I moved a large amount of money a few years back to buy my home (I do not like debt, so I saved up until I could afford somewhere to live, then I bought it) The bank's web site lets you type in any amount of money but then it says politely that you can't do this from the web site, please call the bank. I called the bank (they always pick up in 2-3…

In your story the bank trusted a phone call more than you being logged in the website? How did they authenticate you over the phone?

Re: More than 1k people at Twitter had ability to aid hack of accounts

#97

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

I once had to restore my Authy 2FAs from a backup, and didn't have access to the original device. Restoring it took 24 hours, during which I got bombarded with text messages and emails warning me that someone was restoring my backup, and that if it wasn't me, I should immediately click or reply to prevent it from happening. Seems like that might help - a 24 hour waiting period on any significant account changes for v…

This method is actually used by many countries, most of them in Africa, where thanks to MPESA and such the need of protection against SIM swapping is even higher, since your SIM is literally your bank account.

https://www.wired.com/story/sim-swap-fix-carriers-banks/

"The SIM Swap Fix That the US Isn't Using While foreign phone carriers are sharing data to stop SIM swap fraud, US carriers are dragging feet."

Re: More than 1k people at Twitter had ability to aid hack of accounts

#98

Earlier quoted context omitted.

The key trick isn't so much the two as that they're randomly selected. I moved a large amount of money a few years back to buy my home (I do not like debt, so I saved up until I could afford somewhere to live, then I bought it) The bank's web site lets you type in any amount of money but then it says politely that you can't do this from the web site, please call the bank. I called the bank (they always pick up in 2-3…

In your story the bank trusted a phone call more than you being logged in the website? How did they authenticate you over the phone?

The first call is authenticated as being the bank by calling the correct phone number the bank has on the website.

The second call is authorized via a password given on the first phone call:

> (with the agreed password for when the bank calls me)

Now the stringency of the verification of the caller being OP is unknown.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#99
post #33

Earlier quoted context omitted.

> The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools. Spear-phishing by its very definition is a highly targeted attack. I wouldn't count on any level of training to prevent someone from getting phished. Given some of the spear phishing campaigns I've seen, I wouldn't trust even myself not to fall for them. It's a problem that n…

It's very easy to avoid being spear phished: do not trust any unsolicited message over any medium. Email/text/phone message/popup window purporting to be from your registrar with an urgent call to action? Ignore said call and contact them directly via known good number, email address, URL, etc. EDIT: Voice mimicry scam? Verify via known channel before taking action.

That's exactly it. If it is inbound you can't trust it.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#100
post #95

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

> this sounds expensive and unnecessary to me Should we be OK with what has become a significant communication platform being run with sub-par security because it's "expensive" to do it properly?

Personally I think we need to step back and work out why the fuck anyone is OK with Twitter "accounts that could start a war"? And yet here we are.
Post reply on HN