Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

131–140 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#131
post #15

Earlier quoted context omitted.

It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it: > Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees." https://www.npr.org/2019/11/06/777098293/2-former-twitter-em... 1,000 people, in…

It's funny how most people think that 1000 out of 4600 employees having admin access is "not misleading" and counts as a "limited" group. It shows how in the public mind, technology groups should not be held accountable for their actions.

I take it that 1000 out of 4600 employees shows that, not unsurprisingly, a lot of the staff at this technology company may be involved in hands-on activities against live services. Maybe DevOps style.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#132
post #113

Earlier quoted context omitted.

‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…

> If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. Not really, a blue checkmark is just a status symbol.

This is exactly the problem with the blue tick. It's basically meaningless other than as a budge of honour. It's also restricted to large companies and 'public' figures.

What I'd like to see is, the Blue Tick being restored to be an actual mark of Verification, and be something that anyone can apply for with the appropriate identification documentation.

Additionally, there should then be a toggle switch, where only Verified accounts see tweets and replies from other Verified accounts[1]. This would effectively create two Twitters; one where every account is identifiable and accountable for what they tweet, and another that continues with the anarchic system they have now, where hate speech, racism and intolerance run rife[2].

---

[1] I've heard rumours that this toggle switch already exists on Verified accounts - can anyone confirm ?

[2] Yes, free speech may be trapped here too, unless some sort of middle ground can be worked out.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#133
post #29

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

"There's thousands of people that have the ability to drain your bank account right now" Do you have some data to back that up? Sounds implausible

Does it matter? There are also millions of people who could murder you or burn down your house or kidnap you and force you to withdraw your money from the bank. But just like a bank worker stealing money, these are all serious crimes and easy to get caught so we're pretty safe.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#135
post #113

Earlier quoted context omitted.

> If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. Not really, a blue checkmark is just a status symbol.

This is exactly the problem with the blue tick. It's basically meaningless other than as a budge of honour. It's also restricted to large companies and 'public' figures. What I'd like to see is, the Blue Tick being restored to be an actual mark of Verification, and be something that anyone can apply for with the appropriate identification documentation. Additionally, there should then be a toggle switch, where only V…

[1] Sort of. It's a tab on the Notifications screen that only shows replies/likes/mentions from other Verified accounts.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#136
post #93

Worth mentioning only 5,000 people work at Twitter.

There are ~330 million active twitter users, which means 330,000 users per employee with access to admin accounts.

That ratio is massively high compared to a large corporate (i.e, a global bank). In a typical global bank lets says there are 100,000 employees, with about 25-50 IT people with the rights to admin accounts (from first line support to third line engineers) that's only 2,000-4,000 users per IT admin person.

Based on that, I'm surprised that it's only 1,000 staff members in Twitter with admin access, and not the whole company.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#137

Earlier quoted context omitted.

This is exactly the problem with the blue tick. It's basically meaningless other than as a budge of honour. It's also restricted to large companies and 'public' figures. What I'd like to see is, the Blue Tick being restored to be an actual mark of Verification, and be something that anyone can apply for with the appropriate identification documentation. Additionally, there should then be a toggle switch, where only V…

[1] Sort of. It's a tab on the Notifications screen that only shows replies/likes/mentions from other Verified accounts.

Thought so. Thanks!

Re: More than 1k people at Twitter had ability to aid hack of accounts

#138

Earlier quoted context omitted.

It's funny how most people think that 1000 out of 4600 employees having admin access is "not misleading" and counts as a "limited" group. It shows how in the public mind, technology groups should not be held accountable for their actions.

I take it that 1000 out of 4600 employees shows that, not unsurprisingly, a lot of the staff at this technology company may be involved in hands-on activities against live services. Maybe DevOps style.

Why is that not surprising? Maybe we are used to different types of technology companies though.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#139
post #83

Earlier quoted context omitted.

Hmm I think it’s just our group, we have a Production support team that holds the keys, and there’s only 3 of them that can access my app. For example, if I want to change an environment variable, I can’t just log into the cloud console or run a cli command. God no. That would be too easy. I have to write a script for this team to run. This script is entered into an authorization app where a few parties “sign off”, a…

Reading this makes me happy! Always good to see people taking security seriously.

Yep, this is how strict change control needs to work - if it can be streamlined, all well and good, but not by removing the checks and balances that can help prevent operational issues (not just fraud issues)

Re: More than 1k people at Twitter had ability to aid hack of accounts

#140
post #95

Earlier quoted context omitted.

> this sounds expensive and unnecessary to me Should we be OK with what has become a significant communication platform being run with sub-par security because it's "expensive" to do it properly?

Personally I think we need to step back and work out why the fuck anyone is OK with Twitter "accounts that could start a war"? And yet here we are.

Luckily, after this incident, I believe it has gotten way less likely, that a tweet can start a war.
Post reply on HN