Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

141–150 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#141

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…

PGP solved this issue 30 years ago. I can not believe we have this discussion in 2020

Re: More than 1k people at Twitter had ability to aid hack of accounts

#142
post #33

Earlier quoted context omitted.

> The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools. Spear-phishing by its very definition is a highly targeted attack. I wouldn't count on any level of training to prevent someone from getting phished. Given some of the spear phishing campaigns I've seen, I wouldn't trust even myself not to fall for them. It's a problem that n…

It's very easy to avoid being spear phished: do not trust any unsolicited message over any medium. Email/text/phone message/popup window purporting to be from your registrar with an urgent call to action? Ignore said call and contact them directly via known good number, email address, URL, etc. EDIT: Voice mimicry scam? Verify via known channel before taking action.

Maybe on individual level but on organisation level it's one of the biggest current attack vectors.

And there is no magic bullet. Trying to educate people gives some results, but mostly just prevents low effort phishing attack.

I have never seen pentest that include social engineering fail. (This might be just our customers. I would expect govt or infrastructure organization to be better)

Re: More than 1k people at Twitter had ability to aid hack of accounts

#143
post #113

Earlier quoted context omitted.

> If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. Not really, a blue checkmark is just a status symbol.

This is exactly the problem with the blue tick. It's basically meaningless other than as a budge of honour. It's also restricted to large companies and 'public' figures. What I'd like to see is, the Blue Tick being restored to be an actual mark of Verification, and be something that anyone can apply for with the appropriate identification documentation. Additionally, there should then be a toggle switch, where only V…

Sounds just like the 'real names' policy that Google and Facebook have tried before. That never made any difference to hate speech, racism and intolerance, so why do you think it will magically make Twitter better?

Re: More than 1k people at Twitter had ability to aid hack of accounts

#144

Earlier quoted context omitted.

No, according to The Block, @elonmusk repeatedly tweeted the scam at 4:17pm, 5:19pm, and 5:32pm, a span of 90 minutes, and the final scam tweet was at 6:05pm from @KimKardashian. An hour after @elonmusk's first scam tweet, 7 celebrity or corporate accounts had tweeted the scam, all with the same Bitcoin address. With the two-click system I described, how many compromised admin accounts would you expect the security t…

If your database system doesn't have a complete audit log of all fields (most databases have this capability, but more often than not it's disabled), it's possible that the mere act of reverting account ownership might remove data needed for tracing down what happened. Sure, it's a sucky position to be in, but I can see why they might have been hesitant to dive right in and start trying to undo damage before understa…

Which databases? It's definitely not standard in PostgreSQL or MySQL/MariaDB

Re: More than 1k people at Twitter had ability to aid hack of accounts

#145

Earlier quoted context omitted.

This is exactly the problem with the blue tick. It's basically meaningless other than as a budge of honour. It's also restricted to large companies and 'public' figures. What I'd like to see is, the Blue Tick being restored to be an actual mark of Verification, and be something that anyone can apply for with the appropriate identification documentation. Additionally, there should then be a toggle switch, where only V…

Sounds just like the 'real names' policy that Google and Facebook have tried before. That never made any difference to hate speech, racism and intolerance, so why do you think it will magically make Twitter better?

Because the world is in a different place now. As long as twitter doesn't make it mandatory, it should work. Those that want a bit of decency on Twitter can get verified and have the knowledge that the people they converse with are who they say they are, and those that do not can carry on using Twitter in the same way they always have.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#146
post #48

Earlier quoted context omitted.

That just won’t work. Just target the attack in the middle of the night or lunch hour. Furthermore, the next attack will probably be automated and be against far, far more accounts.

Yeah, response time might be slower in the middle of the night, but a falsified tweet on a celebrity account in the middle of the night is also likely proportionally less damaging. Response time during lunch hour might be slower initially, but after responding to the first compromised account I don't think they'd be any slower. If an admin account is only supposed to be for use by a human employee, it should have a r…

[deleted]

Re: More than 1k people at Twitter had ability to aid hack of accounts

#147

Earlier quoted context omitted.

There may be a bit of an hyperbole in the expression "accounts that could start a war": there are indeed accounts of people who could start a war, yet I fail to imagine how a single tweet, or a few tweets, by some hacker could actually start a war. Escalate tensions, sure. But I assume world leaders and their advisors don't rely (solely) on tweets before calling the cavalry.

Sure, how about we dial the hyperbole down a bit, to "accounts universally known to be a primary mechanisms for announcement of international policy by the leader of a country which has started 12 'armed conflicts' in the last 20 years (or 14 if you count them doing it twice in Iraq and Lybia)"? I find it quite horrifying that elected officials are legally allowed to use totally unaccountable social media platforms t…

What are our options here? Some *.gov website that public isn't going to read?

Re: More than 1k people at Twitter had ability to aid hack of accounts

#148
well, I worked on a software house that makes software for industry automation. each user of the software has all their actions logged and time-stamped. if you edit something, give a big discount, granted permission, deleted something... it all goes into a different DB filled with just the logs. why doesn't Twitter have something like this? am I missing something?

Re: More than 1k people at Twitter had ability to aid hack of accounts

#149

Earlier quoted context omitted.

‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…

PGP solved this issue 30 years ago. I can not believe we have this discussion in 2020

I don't tweet much, but when I do I'd love to be able to sign them like I sign my git commits.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#150
post #48

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

That just won’t work. Just target the attack in the middle of the night or lunch hour. Furthermore, the next attack will probably be automated and be against far, far more accounts.

> Just target the attack in the middle of the night

Define 'middle of the night'. Is that Eastern US, Western US, GMT, or CET?

If I assume it's 2 AM pacific (since Twitter HQ is in SF), that's 11 AM in most of Europe, which makes it middle of the day for about 700 million Europeans, many of whom speak English and are interested in US celebrities. And that's still ignoring the majority of the World.

Anything on the internet is 24/7. Musk regularly tweets in the 'middle of the night' and I see those tweets come in while drinking a cup of coffee.

Also, Twitter has offices around the world and people don't collectively log out for lunch at a specific time, so there should always be people available to handle this type of incident. Provided they get the training and tools to do so.

Post reply on HN