accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…
‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…
More than 1k people at Twitter had ability to aid hack of accounts
141–150 of 238 posts
Re: More than 1k people at Twitter had ability to aid hack of accounts
#142Earlier quoted context omitted.
> The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools. Spear-phishing by its very definition is a highly targeted attack. I wouldn't count on any level of training to prevent someone from getting phished. Given some of the spear phishing campaigns I've seen, I wouldn't trust even myself not to fall for them. It's a problem that n…
It's very easy to avoid being spear phished: do not trust any unsolicited message over any medium. Email/text/phone message/popup window purporting to be from your registrar with an urgent call to action? Ignore said call and contact them directly via known good number, email address, URL, etc. EDIT: Voice mimicry scam? Verify via known channel before taking action.
And there is no magic bullet. Trying to educate people gives some results, but mostly just prevents low effort phishing attack.
I have never seen pentest that include social engineering fail. (This might be just our customers. I would expect govt or infrastructure organization to be better)
Re: More than 1k people at Twitter had ability to aid hack of accounts
#143Earlier quoted context omitted.
> If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. Not really, a blue checkmark is just a status symbol.
This is exactly the problem with the blue tick. It's basically meaningless other than as a budge of honour. It's also restricted to large companies and 'public' figures. What I'd like to see is, the Blue Tick being restored to be an actual mark of Verification, and be something that anyone can apply for with the appropriate identification documentation. Additionally, there should then be a toggle switch, where only V…
Re: More than 1k people at Twitter had ability to aid hack of accounts
#144Earlier quoted context omitted.
No, according to The Block, @elonmusk repeatedly tweeted the scam at 4:17pm, 5:19pm, and 5:32pm, a span of 90 minutes, and the final scam tweet was at 6:05pm from @KimKardashian. An hour after @elonmusk's first scam tweet, 7 celebrity or corporate accounts had tweeted the scam, all with the same Bitcoin address. With the two-click system I described, how many compromised admin accounts would you expect the security t…
If your database system doesn't have a complete audit log of all fields (most databases have this capability, but more often than not it's disabled), it's possible that the mere act of reverting account ownership might remove data needed for tracing down what happened. Sure, it's a sucky position to be in, but I can see why they might have been hesitant to dive right in and start trying to undo damage before understa…
Re: More than 1k people at Twitter had ability to aid hack of accounts
#145Earlier quoted context omitted.
This is exactly the problem with the blue tick. It's basically meaningless other than as a budge of honour. It's also restricted to large companies and 'public' figures. What I'd like to see is, the Blue Tick being restored to be an actual mark of Verification, and be something that anyone can apply for with the appropriate identification documentation. Additionally, there should then be a toggle switch, where only V…
Sounds just like the 'real names' policy that Google and Facebook have tried before. That never made any difference to hate speech, racism and intolerance, so why do you think it will magically make Twitter better?
Re: More than 1k people at Twitter had ability to aid hack of accounts
#146Earlier quoted context omitted.
That just won’t work. Just target the attack in the middle of the night or lunch hour. Furthermore, the next attack will probably be automated and be against far, far more accounts.
Yeah, response time might be slower in the middle of the night, but a falsified tweet on a celebrity account in the middle of the night is also likely proportionally less damaging. Response time during lunch hour might be slower initially, but after responding to the first compromised account I don't think they'd be any slower. If an admin account is only supposed to be for use by a human employee, it should have a r…
Re: More than 1k people at Twitter had ability to aid hack of accounts
#147Earlier quoted context omitted.
There may be a bit of an hyperbole in the expression "accounts that could start a war": there are indeed accounts of people who could start a war, yet I fail to imagine how a single tweet, or a few tweets, by some hacker could actually start a war. Escalate tensions, sure. But I assume world leaders and their advisors don't rely (solely) on tweets before calling the cavalry.
Sure, how about we dial the hyperbole down a bit, to "accounts universally known to be a primary mechanisms for announcement of international policy by the leader of a country which has started 12 'armed conflicts' in the last 20 years (or 14 if you count them doing it twice in Iraq and Lybia)"? I find it quite horrifying that elected officials are legally allowed to use totally unaccountable social media platforms t…
Re: More than 1k people at Twitter had ability to aid hack of accounts
#148Re: More than 1k people at Twitter had ability to aid hack of accounts
#149Earlier quoted context omitted.
‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…
PGP solved this issue 30 years ago. I can not believe we have this discussion in 2020
Re: More than 1k people at Twitter had ability to aid hack of accounts
#150accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…
That just won’t work. Just target the attack in the middle of the night or lunch hour. Furthermore, the next attack will probably be automated and be against far, far more accounts.
Define 'middle of the night'. Is that Eastern US, Western US, GMT, or CET?
If I assume it's 2 AM pacific (since Twitter HQ is in SF), that's 11 AM in most of Europe, which makes it middle of the day for about 700 million Europeans, many of whom speak English and are interested in US celebrities. And that's still ignoring the majority of the World.
Anything on the internet is 24/7. Musk regularly tweets in the 'middle of the night' and I see those tweets come in while drinking a cup of coffee.
Also, Twitter has offices around the world and people don't collectively log out for lunch at a specific time, so there should always be people available to handle this type of incident. Provided they get the training and tools to do so.