Earlier quoted context omitted.
It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it: > Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees." https://www.npr.org/2019/11/06/777098293/2-former-twitter-em... 1,000 people, in…
It's funny how most people think that 1000 out of 4600 employees having admin access is "not misleading" and counts as a "limited" group. It shows how in the public mind, technology groups should not be held accountable for their actions.
More than 1k people at Twitter had ability to aid hack of accounts
131–140 of 238 posts
Re: More than 1k people at Twitter had ability to aid hack of accounts
#132Earlier quoted context omitted.
‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…
> If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. Not really, a blue checkmark is just a status symbol.
What I'd like to see is, the Blue Tick being restored to be an actual mark of Verification, and be something that anyone can apply for with the appropriate identification documentation.
Additionally, there should then be a toggle switch, where only Verified accounts see tweets and replies from other Verified accounts[1]. This would effectively create two Twitters; one where every account is identifiable and accountable for what they tweet, and another that continues with the anarchic system they have now, where hate speech, racism and intolerance run rife[2].
---
[1] I've heard rumours that this toggle switch already exists on Verified accounts - can anyone confirm ?
[2] Yes, free speech may be trapped here too, unless some sort of middle ground can be worked out.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#133Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .
"There's thousands of people that have the ability to drain your bank account right now" Do you have some data to back that up? Sounds implausible
Re: More than 1k people at Twitter had ability to aid hack of accounts
#134Re: More than 1k people at Twitter had ability to aid hack of accounts
#135Earlier quoted context omitted.
> If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. Not really, a blue checkmark is just a status symbol.
This is exactly the problem with the blue tick. It's basically meaningless other than as a budge of honour. It's also restricted to large companies and 'public' figures. What I'd like to see is, the Blue Tick being restored to be an actual mark of Verification, and be something that anyone can apply for with the appropriate identification documentation. Additionally, there should then be a toggle switch, where only V…
Re: More than 1k people at Twitter had ability to aid hack of accounts
#136Worth mentioning only 5,000 people work at Twitter.
That ratio is massively high compared to a large corporate (i.e, a global bank). In a typical global bank lets says there are 100,000 employees, with about 25-50 IT people with the rights to admin accounts (from first line support to third line engineers) that's only 2,000-4,000 users per IT admin person.
Based on that, I'm surprised that it's only 1,000 staff members in Twitter with admin access, and not the whole company.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#137Earlier quoted context omitted.
This is exactly the problem with the blue tick. It's basically meaningless other than as a budge of honour. It's also restricted to large companies and 'public' figures. What I'd like to see is, the Blue Tick being restored to be an actual mark of Verification, and be something that anyone can apply for with the appropriate identification documentation. Additionally, there should then be a toggle switch, where only V…
[1] Sort of. It's a tab on the Notifications screen that only shows replies/likes/mentions from other Verified accounts.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#138Earlier quoted context omitted.
It's funny how most people think that 1000 out of 4600 employees having admin access is "not misleading" and counts as a "limited" group. It shows how in the public mind, technology groups should not be held accountable for their actions.
I take it that 1000 out of 4600 employees shows that, not unsurprisingly, a lot of the staff at this technology company may be involved in hands-on activities against live services. Maybe DevOps style.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#139Earlier quoted context omitted.
Hmm I think it’s just our group, we have a Production support team that holds the keys, and there’s only 3 of them that can access my app. For example, if I want to change an environment variable, I can’t just log into the cloud console or run a cli command. God no. That would be too easy. I have to write a script for this team to run. This script is entered into an authorization app where a few parties “sign off”, a…
Reading this makes me happy! Always good to see people taking security seriously.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#140Earlier quoted context omitted.
> this sounds expensive and unnecessary to me Should we be OK with what has become a significant communication platform being run with sub-par security because it's "expensive" to do it properly?
Personally I think we need to step back and work out why the fuck anyone is OK with Twitter "accounts that could start a war"? And yet here we are.