Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

171–180 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#171
post #147

Earlier quoted context omitted.

Sure, how about we dial the hyperbole down a bit, to "accounts universally known to be a primary mechanisms for announcement of international policy by the leader of a country which has started 12 'armed conflicts' in the last 20 years (or 14 if you count them doing it twice in Iraq and Lybia)"? I find it quite horrifying that elected officials are legally allowed to use totally unaccountable social media platforms t…

What are our options here? Some *.gov website that public isn't going to read?

Yes. It might still be mirrored on Twitter, but at least that would not put it as authoritative source and the people at the trigger would've a page too look beforehand.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#172

Earlier quoted context omitted.

Actually not in the UK receptionists triage patients as a extreme covid risk (trasnpaltee) I get priority

Well yes, being able to give priority to at-risk patients would fall under necessary use. I doubt the receptionist has your actual medical history, but they would certainly see an indicator of your risk category.

There is no such thing as “necessary use” and the GDPR does not specify that an organisation must restrict employee access to personal data to only those whose access is “strictly necessary” (the cookie law contains that phrase, but in a completely different context).

The only thing the GDPR says that would apply in this circumstance is this:

> processed in a manner that ensures appropriate security of the personal data

As I stated above, the EU provides exactly 0 guidance on what “appropriate security” is, and no form of standard at all that it expects you to comply with. To make matters more confusing, an organisation is allowed to take their own budget into account, against the cost of security controls, when deciding what is “appropriate”.

You could ask the question, was twitter appropriately secure? You might come to the conclusion that they weren’t, because they were breached and any system that is breached must not be appropriately secure. That wouldn’t be an unreasonable conclusion, and as far as anybody knows that could very well be the standard that any data protection authority may decide to uphold at any time of their choosing. But then that would lead you to consider that there is no such thing as a system that can not be breached, so in that case there would be no such thing as a GDPR compliant service.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#173
post #115

I remember during my time with a large mobile carrier in UK I was told of a person in the company who could in theory read any SMS on the network. Mind you this was literally one person for over 30 million customers. He had a high security clearance, extensive security training and the powers vested in him were used mainly to identify scammers and other criminals. Pretty sure this was a requirement set by law - we ne…

Social networks were never supposed to be important or serious in the same way as phone networks. I would argue they still aren't. At the bottom, they are just time waster websites. You wouldn't demand that level of security of a php forum would you?

> Social networks were never supposed to be important or serious in the same way as phone networks.

I would think Zuckerberg intended Facebook to be important and serious. You don’t make a billion dollars off of something that’s trivial and unimportant.... The users might view it that way, but that lack of appreciation is just what enables you to make billions off of them.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#174
post #165

I created a Twitter account close to a month ago and it was immediately suspended because it "appears to have exhibited automated behavior that violates the Twitter Rules". Well it did not really do anything yet, even less so anything against their rules. The account is still suspended despite multiple appeals and messages. At the same time, dozens (hundreds?) of verified accounts get taken over. I think their fraud…

They do this for all new accounts. It's a way to harvest phone numbers from unsuspecting victims of this surveillance. It doesn't matter from what ip, machine or whatever you register. It will automatically get suspended because I think they've realized it's easier to force people to enter their phone numbers in "protection" after they just created an account rather than to just ask for it during signup. Less questio…

I was assuming something like that. Very shady.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#175

Earlier quoted context omitted.

It would also exclude venerable people which is the problem with the real name idea

We can imagine a system where twitter checks that person is a real unique human but does not use their personal data for anything else.

Until the next hack links their real name with their handle? No thanks.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#176

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

How would a Twitter account start a war?

Re: More than 1k people at Twitter had ability to aid hack of accounts

#177
post #144

Earlier quoted context omitted.

If your database system doesn't have a complete audit log of all fields (most databases have this capability, but more often than not it's disabled), it's possible that the mere act of reverting account ownership might remove data needed for tracing down what happened. Sure, it's a sucky position to be in, but I can see why they might have been hesitant to dive right in and start trying to undo damage before understa…

Which databases? It's definitely not standard in PostgreSQL or MySQL/MariaDB

Replication logs (WAL logs in postgres) contain a complete list of changes to every field. Most big companies keep them as part of a backup strategy. But most wouldn't have the tooling to inspect the logs and see exactly which change was made when during an incident.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#178

Earlier quoted context omitted.

I can imagine at minimum this would help with bots. Considering the problems you state are actual systematic issues we have in our society I would expect that the verification process should not be perceived as working towards solving those.

I have no idea how comment bots run today, but for anyone only slightly invested, it would mean one additional hurdle (get accounts for actual people who are not using the service), but not a blocker (like captchas: they mostly serve to annoy regular users).

That seems like a pretty large hurdle, compared to today where it seems they're just creating as many accounts as they want. There isn't a single political tweet without a bunch of bot garbage as replies. I assume any name with 8 digits at the end is a bot and an auto-block (and these are all over political tweets), but there are so many more tweets that are highly suspicious once you go in and look at their feed.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#179

Earlier quoted context omitted.

There may be a bit of an hyperbole in the expression "accounts that could start a war": there are indeed accounts of people who could start a war, yet I fail to imagine how a single tweet, or a few tweets, by some hacker could actually start a war. Escalate tensions, sure. But I assume world leaders and their advisors don't rely (solely) on tweets before calling the cavalry.

Sure, how about we dial the hyperbole down a bit, to "accounts universally known to be a primary mechanisms for announcement of international policy by the leader of a country which has started 12 'armed conflicts' in the last 20 years (or 14 if you count them doing it twice in Iraq and Lybia)"? I find it quite horrifying that elected officials are legally allowed to use totally unaccountable social media platforms t…

>I find it quite horrifying that elected officials are legally allowed to use totally unaccountable social media platforms to communicate policy to the public.

It also creates a number of issues. If twitter decides to ban me, doesn't that impact my right to contact my representatives via twitter (especially since a judge has already ruled that a government official blocking a person on twitter does violate their right). Seems that the government should only be allowed to use a platform for communication if that platform is treated as a public square that all can access regardless of past history, same as public squares of the past. This isn't putting a limit on Twitter, they are a private company and can do what they want. This is putting a limit on the government. Now, if Twitter helps the government establish such an account, then they would be a private company choosing to open itself up as a public square and, specifically with regards to the parts that are a public square, losing some of the rights of a private company (they can't ban you from the public square, but they can ban you from anywhere else as the rest of the site isn't part of the public square).

Re: More than 1k people at Twitter had ability to aid hack of accounts

#180

Earlier quoted context omitted.

‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…

> held pending verification that the blue check mark still applies to the person now in control of that account That sounds to me like it's simply having a 2nd person verify the email change is correct. So your suggestion and the article's suggestion ("should at least need two people to change key settings") seem to be very similar if not the same as each other.

Process can be automated depending on how the account needs to be verified. Might be that say for a brand account it is connected to a domain ownership/verification model, where 1) email address must be in a particular domain, and 2) email must be able to complete a challenge/response process that demonstrates they control the company website - eg some random value is sent to the email address and they have to make it available via an https resource on the company domain.

For personal celebrity accounts maybe verification is just that the email address must send in a scan of a government photo Id, and sure maybe that triggers a manual check, but it’s not just a ‘two keys’ solution - it’s a verification process.

Sure, the same admin console might be able to go in and change the verification mode and rules on a verified account - but that’s something that would happen rarely, and a flurry of activity changing the verification process for a bunch of accounts would definitely merit a red flag.

Post reply on HN