Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

151–160 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#152

Earlier quoted context omitted.

This is exactly the problem with the blue tick. It's basically meaningless other than as a budge of honour. It's also restricted to large companies and 'public' figures. What I'd like to see is, the Blue Tick being restored to be an actual mark of Verification, and be something that anyone can apply for with the appropriate identification documentation. Additionally, there should then be a toggle switch, where only V…

Sounds just like the 'real names' policy that Google and Facebook have tried before. That never made any difference to hate speech, racism and intolerance, so why do you think it will magically make Twitter better?

I can imagine at minimum this would help with bots. Considering the problems you state are actual systematic issues we have in our society I would expect that the verification process should not be perceived as working towards solving those.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#153

On a different note, online presence is becoming very important and with remote work culture gaining traction, having a good online presence has become a must have asset. I bought a course on building Twitter audience and been able to improve my following significantly from past 2 months. Twitter link: https://twitter.com/sunilc_ If you're looking to increase your social presence too, here's the course that I found v…

Spam motivational quotes and hope people retweet and like?

Re: More than 1k people at Twitter had ability to aid hack of accounts

#154

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…

As twitter only has about 5k Employees having more than 1k ie over 20% with access like this is shocking and the fact that "j random "contractor" has access even more so.

Twitter needs to get serious period and not just blue checks.

Also a lot of the other FANG type companies are effectively CNI - I think they need to start properly vetting people and I mean real security clearance possibly including TS

Re: More than 1k people at Twitter had ability to aid hack of accounts

#155

Earlier quoted context omitted.

Sounds just like the 'real names' policy that Google and Facebook have tried before. That never made any difference to hate speech, racism and intolerance, so why do you think it will magically make Twitter better?

I can imagine at minimum this would help with bots. Considering the problems you state are actual systematic issues we have in our society I would expect that the verification process should not be perceived as working towards solving those.

It would also exclude venerable people which is the problem with the real name idea

Re: More than 1k people at Twitter had ability to aid hack of accounts

#157

Earlier quoted context omitted.

There are already organisations that have to control employee access to ‘customer’ data very tightly. Law enforcement. Law enforcement agencies have access to large databases full of people along with a huge amount of very sensitive data (both confidential personal data, and stuff like information about ongoing and typically covert investigations). I’ve worked with several of these types of organisations and the ones…

> There are already organisations that have to control employee access to ‘customer’ data very tightly. How about... anybody who has customers in the EU?

GDPR really doesn't cover this

I know that people with access to some telecom systems in the UK have to have been vetted some even to DV level - ie the same as if you where working for a TLA.

So having to pass a TS clearance and the whole SF86 form for FANG employees is a possibility "so Elon about your pot smoking habits"

Re: More than 1k people at Twitter had ability to aid hack of accounts

#158

Earlier quoted context omitted.

The EU doesn’t provide any standards at all relating to information security. It only specifies that security controls must be ‘appropriate’, but no definition or precedent for what that means. Customer service and community moderation staff accessing customer data, or having administrative control over their accounts would certainly not be a violation of EU law.

Parent was probably referring to GDPR, which (IIRC) mandates that employees only have access to the information strictly necessary for their position. You doctor's secretary should only have access to your appointment schedule and phone number, not your medical condition.

Actually not in the UK receptionists triage patients as a extreme covid risk (trasnpaltee) I get priority

Re: More than 1k people at Twitter had ability to aid hack of accounts

#159

Earlier quoted context omitted.

‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…

PGP solved this issue 30 years ago. I can not believe we have this discussion in 2020

Except that the problem isn't the signature itself, it's the required infrastructure. Grandma doesn't know how to check The Donald's signature. And, of course, the infrastructure is hard (just check the unfixable problems with the PGP persistent DOS attacks that were discussed a year or 2 ago).

Re: More than 1k people at Twitter had ability to aid hack of accounts

#160
> implication that a hostile government might be able to cause even greater havoc.

it is stuff like this that make me question the whole article. like yes, obviously this was no "hostile" government since they were just scamming for some pocket change. but also how exactly would this hostile government create havoc with twitter?

Post reply on HN