Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

121–130 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#121

Earlier quoted context omitted.

> There are already organisations that have to control employee access to ‘customer’ data very tightly. How about... anybody who has customers in the EU?

The EU doesn’t provide any standards at all relating to information security. It only specifies that security controls must be ‘appropriate’, but no definition or precedent for what that means. Customer service and community moderation staff accessing customer data, or having administrative control over their accounts would certainly not be a violation of EU law.

Parent was probably referring to GDPR, which (IIRC) mandates that employees only have access to the information strictly necessary for their position. You doctor's secretary should only have access to your appointment schedule and phone number, not your medical condition.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#122
post #115

I remember during my time with a large mobile carrier in UK I was told of a person in the company who could in theory read any SMS on the network. Mind you this was literally one person for over 30 million customers. He had a high security clearance, extensive security training and the powers vested in him were used mainly to identify scammers and other criminals. Pretty sure this was a requirement set by law - we ne…

Social networks were never supposed to be important or serious in the same way as phone networks. I would argue they still aren't. At the bottom, they are just time waster websites. You wouldn't demand that level of security of a php forum would you?

Social networs including Twitter host tax-payer supported institutions such as USGS and NASA where they post updates.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#123
post #115

I remember during my time with a large mobile carrier in UK I was told of a person in the company who could in theory read any SMS on the network. Mind you this was literally one person for over 30 million customers. He had a high security clearance, extensive security training and the powers vested in him were used mainly to identify scammers and other criminals. Pretty sure this was a requirement set by law - we ne…

Social networks were never supposed to be important or serious in the same way as phone networks. I would argue they still aren't. At the bottom, they are just time waster websites. You wouldn't demand that level of security of a php forum would you?

At a certain threshold yes I would, if it served millions of people. A small ISP can get away with terrible security but once they start having millions of customers someone is going to sound an alarm. A forum, written in any language, should be no different. I realise there are challenges in making this happen but they are not unrealistic.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#124
post #115

I remember during my time with a large mobile carrier in UK I was told of a person in the company who could in theory read any SMS on the network. Mind you this was literally one person for over 30 million customers. He had a high security clearance, extensive security training and the powers vested in him were used mainly to identify scammers and other criminals. Pretty sure this was a requirement set by law - we ne…

Social networks were never supposed to be important or serious in the same way as phone networks. I would argue they still aren't. At the bottom, they are just time waster websites. You wouldn't demand that level of security of a php forum would you?

Except that huge public figures tweeting can actually affect real life a lot more than a bunch of SMS messages to yer nan....

Re: More than 1k people at Twitter had ability to aid hack of accounts

#125
post #113

Earlier quoted context omitted.

‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…

> If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. Not really, a blue checkmark is just a status symbol.

It gives validity and implies trust.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#126
post #115

I remember during my time with a large mobile carrier in UK I was told of a person in the company who could in theory read any SMS on the network. Mind you this was literally one person for over 30 million customers. He had a high security clearance, extensive security training and the powers vested in him were used mainly to identify scammers and other criminals. Pretty sure this was a requirement set by law - we ne…

Social networks were never supposed to be important or serious in the same way as phone networks. I would argue they still aren't. At the bottom, they are just time waster websites. You wouldn't demand that level of security of a php forum would you?

You’re right about the first part, but large global social networks are quite close to phone networks in importance now.

Though cases like the recent bipolar tweets from Kanye West on Twitter does seem to support your point.

You could have said Wordpress forums, why take it out on PHP, though I get the message ;)

Re: More than 1k people at Twitter had ability to aid hack of accounts

#127

Earlier quoted context omitted.

I once had to restore my Authy 2FAs from a backup, and didn't have access to the original device. Restoring it took 24 hours, during which I got bombarded with text messages and emails warning me that someone was restoring my backup, and that if it wasn't me, I should immediately click or reply to prevent it from happening. Seems like that might help - a 24 hour waiting period on any significant account changes for v…

I actually had a similar idea for fighting SIM swaps—we should be able to ask telecoms "hey, when's the last time this phone number was moved to another device/changed IMEI numbers?" and distrust the number if it's been changed less than 48 hours ago. I've looked but as far as I can tell, such an API does not exist, alas.

That is part of a service that we use, provided for some banks, but requires a lot of integration with the mobile networks and a lot of additional business logic around new sims, old sims used on new accounts, old sims used on old accounts when first set up, etc. Banks use it for determining whether it is deemed safe to send OTP or other sensitive messages to a mobile. If sim has been swapped recently, they may then choose not to use text message delivery to prevent potential sim-swap fraud.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#128
post #65
post #55

Earlier quoted context omitted.

Something like Require-Recipient-Valid-Since from SMTP? That would be neat. Does SMS have the necessary protocol flexibility to allow that to be added?

The User Data Header of SMS [0] isn't very flexible, and quite constrained - both it and the message needs to fit inside a 140 byte payload. There are a handful of bytes reserved for a future purpose, which could be used for something like this, but you're limiting how large the message can be, likely significantly. [0] https://en.wikipedia.org/wiki/User_Data_Header

For SMPP, there is the option to add further data using 'TLV' (Tag/Length/Value) parameters, not only UDH properties.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#129

Earlier quoted context omitted.

Personally I think we need to step back and work out why the fuck anyone is OK with Twitter "accounts that could start a war"? And yet here we are.

There may be a bit of an hyperbole in the expression "accounts that could start a war": there are indeed accounts of people who could start a war, yet I fail to imagine how a single tweet, or a few tweets, by some hacker could actually start a war. Escalate tensions, sure. But I assume world leaders and their advisors don't rely (solely) on tweets before calling the cavalry.

Sure, how about we dial the hyperbole down a bit, to "accounts universally known to be a primary mechanisms for announcement of international policy by the leader of a country which has started 12 'armed conflicts' in the last 20 years (or 14 if you count them doing it twice in Iraq and Lybia)"?

I find it quite horrifying that elected officials are legally allowed to use totally unaccountable social media platforms to communicate policy to the public.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#130
post #33

Earlier quoted context omitted.

It's very easy to avoid being spear phished: do not trust any unsolicited message over any medium. Email/text/phone message/popup window purporting to be from your registrar with an urgent call to action? Ignore said call and contact them directly via known good number, email address, URL, etc. EDIT: Voice mimicry scam? Verify via known channel before taking action.

The question isn't how you and I can individually avoid being spear phished, but what policies can be implemented across an organization to prevent it. Even the most trusted security teams aren't going to be allowed to summarily fire everyone who fails the test. I also think this is a much stricter standard than you're recognizing. In my company's last spearphishing test, they sent out a link purporting to be a compa…

Just wondering if employees failed the test just by clicking on the link or if they had to actually enter some passwords or confidential information on the fake survey site. I wouldn't think clicking a link then looking at the address bar and seeing the domain name is wrong, then closing the page would be a problem, would it?
Post reply on HN