Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

101–110 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#101
post #82
post #66

Earlier quoted context omitted.

The problem is with POTS, you dont have that kind of capability in the protocol, even Caller ID cannot be verified. Most network will trust whatever is being sent. It is like SMTP it was designed in era where security was simply not there.

pgp solved many use-cases.

[citation required]

(It's true there are a bunch of important things that PGP has helped solve. Ubiquitous person-to-person secure communication and person-to-service cryptographic authentication are not amongst them. PGP is certainly usefully employed in some niche use cases, but it has failed at pretty much all it's original goals. I can't remember that last time I used it for anything except verifying a software download, and even _that_ use case only applies to a tiny fraction of places that hoist software downloads. My Arch linux installs running pacman and silently checking php signatures for me may be the only time I've had PGP code run in maybe a decade...)

Re: More than 1k people at Twitter had ability to aid hack of accounts

#103

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…

> held pending verification that the blue check mark still applies to the person now in control of that account

That sounds to me like it's simply having a 2nd person verify the email change is correct. So your suggestion and the article's suggestion ("should at least need two people to change key settings") seem to be very similar if not the same as each other.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#104
post #48

Earlier quoted context omitted.

That just won’t work. Just target the attack in the middle of the night or lunch hour. Furthermore, the next attack will probably be automated and be against far, far more accounts.

Yeah, response time might be slower in the middle of the night, but a falsified tweet on a celebrity account in the middle of the night is also likely proportionally less damaging. Response time during lunch hour might be slower initially, but after responding to the first compromised account I don't think they'd be any slower. If an admin account is only supposed to be for use by a human employee, it should have a r…

> ... a falsified tweet on a celebrity account ...

A Hollywood celebrity? A bay area techbro "celebrity"? Or a Bollywood celebrity? Or a British Royal family celebrity? Or a KPop celebrity? Or a Russian oligarch celebrity?

The middle of who's night??? Twitter does exist on the other side of the Bay Bridge you know...

Re: More than 1k people at Twitter had ability to aid hack of accounts

#105

Earlier quoted context omitted.

No, according to The Block, @elonmusk repeatedly tweeted the scam at 4:17pm, 5:19pm, and 5:32pm, a span of 90 minutes, and the final scam tweet was at 6:05pm from @KimKardashian. An hour after @elonmusk's first scam tweet, 7 celebrity or corporate accounts had tweeted the scam, all with the same Bitcoin address. With the two-click system I described, how many compromised admin accounts would you expect the security t…

If your database system doesn't have a complete audit log of all fields (most databases have this capability, but more often than not it's disabled), it's possible that the mere act of reverting account ownership might remove data needed for tracing down what happened. Sure, it's a sucky position to be in, but I can see why they might have been hesitant to dive right in and start trying to undo damage before understa…

> I can see why they might have been hesitant to dive right in and start trying

I mean, after all - it was only the cattle.

It's not as if the attackers got into the accounts of customers, the paying advertisers.

(Besides, the Part Time CEO was probably in Africa and unavailable to provide decisive direction, right?)

Re: More than 1k people at Twitter had ability to aid hack of accounts

#106
post #60

Earlier quoted context omitted.

How about we don’t start wars based off a twitter feed?

In an ideal world, world leaders would all have restrained enough Twitter habits such that anything that inflammatory would be seen as an obvious signal that their account was compromised.

Where is this "ideal world" and how do I get there?

Re: More than 1k people at Twitter had ability to aid hack of accounts

#107
post #85

Earlier quoted context omitted.

The question isn't how you and I can individually avoid being spear phished, but what policies can be implemented across an organization to prevent it. Even the most trusted security teams aren't going to be allowed to summarily fire everyone who fails the test. I also think this is a much stricter standard than you're recognizing. In my company's last spearphishing test, they sent out a link purporting to be a compa…

Disable links in emails by default goes a long way.

How would this work? I get emails like "you have been added to gerrit review" and " Redmine issue was updated" several time a day and I need to open these links.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#108
This should be a wake up call. Thank god the malicious messaging was only limited to a tiny Bitcoin scam. Imagine if they had pulled this off on the accounts of national leaders to stir hostilities or violence.

What is the recourse for this kind of failure? I suspect there is none. Twitter is shielded from lawsuits for its content. If this is provably negligent behavior and resulted in actual physical harm it are we supposed to do nothing and simply hope it never happens again?

I cannot fathom what I would do if I were in the position of Timothy Klausutis: https://www.washingtonpost.com/politics/widower-of-late-joe-...

Re: More than 1k people at Twitter had ability to aid hack of accounts

#109
post #15

Earlier quoted context omitted.

It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it: > Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees." https://www.npr.org/2019/11/06/777098293/2-former-twitter-em... 1,000 people, in…

I don't think that's a contradiction, I think you and Twitter have different understandings of what the size of a "limited group of employees" is. The usual advice of dismissing nebulous corporate statements like that applies. Anyway, even if they had provided a figure, I think you're taking it out of context - the quote says access to "sensitive account information" is limited, not access to account recovery options…

I think the misunderstanding is over the phrase "sensitive account information".

I notice it wasn't Nestle or Verizon or Disney or Heinz or Unilever accounts that got hacked.

You know, the information about "accounts". The records of monetary transactions.

https://www.statista.com/statistics/1094351/us-twitter-adver...

Re: More than 1k people at Twitter had ability to aid hack of accounts

#110

Earlier quoted context omitted.

> 1,000 people, including contractors outside the company, is not a "limited group of trained and vetted employees." That's not necessarily true. 20% of the company could fairly reasonably be deemed "limited", and there being a thousand of them doesn't mean they're not trained on their tasks.

Today I learned that Twitter has 4,600 employees. What are they all doing?

Ya cos Twitter is just a CRUD app /s

Once you want to add more people to any business, you need to add even more people to that business.

Lets say you have 10 engineers and want to add another. Suddenly HR's workload has tipped over the limit and you need more HR people. Now communication is fracturing for those 10 engineers and you need a Product Manager and an Engineering Manager to centralise the steering and cohesion of those 11 engineers. Now budgets, payroll and accounting has increased and you need another Finance person.

Suddenly your office is too small so you need a bigger office and an office manager.

This is obviously a contrived example, but having worked at very early stage startup, a mid sized startup and a global megacorp while seeing all of them go through various growth cycles you start to appreciate how headcount can creep in ways which feel indirect to the most pressing problem at hand (ship more features, deliver more customer value).

You see it software terms too - as your software project scales suddenly you need more infra, your CI environment gets more complex. Suddenly your workflows don't scale as too many engineers are working on the same code, so you rearchitect (components/microservices) then you need to start building dev tooling and metrics/observability....

I guess as some kind of system scales, the leverage you gain from adding a thing to it has some diminishing curve / inverse relationship to the size of the system.

Post reply on HN