Earlier quoted context omitted.
PGP solved this issue 30 years ago. I can not believe we have this discussion in 2020
Except that the problem isn't the signature itself, it's the required infrastructure. Grandma doesn't know how to check The Donald's signature. And, of course, the infrastructure is hard (just check the unfixable problems with the PGP persistent DOS attacks that were discussed a year or 2 ago).
More than 1k people at Twitter had ability to aid hack of accounts
181–190 of 238 posts
Re: More than 1k people at Twitter had ability to aid hack of accounts
#182accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…
How would a Twitter account start a war?
But people who do think it's possible probably think it would happen something like this: https://twitter.com/realdonaldtrump/status/12139194805748121...
Re: More than 1k people at Twitter had ability to aid hack of accounts
#183Earlier quoted context omitted.
There may be a bit of an hyperbole in the expression "accounts that could start a war": there are indeed accounts of people who could start a war, yet I fail to imagine how a single tweet, or a few tweets, by some hacker could actually start a war. Escalate tensions, sure. But I assume world leaders and their advisors don't rely (solely) on tweets before calling the cavalry.
Sure, how about we dial the hyperbole down a bit, to "accounts universally known to be a primary mechanisms for announcement of international policy by the leader of a country which has started 12 'armed conflicts' in the last 20 years (or 14 if you count them doing it twice in Iraq and Lybia)"? I find it quite horrifying that elected officials are legally allowed to use totally unaccountable social media platforms t…
The ultimate check on the behavior of elected officials is supposed to be the voters. You shouldn't have to have laws to prevent them from making bad choices. In this case, the voters like their speech to be "tell it like it is", which mostly means hating the same people they hate. They're getting what they asked for, and are likely to ask for it again.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#184There is already tons of evidence of Chinese nationals coming to the US to work at these companies with the express purpose of stealing trade secrets and sending them back to China. Why would the Chinese government stop there? How about your personal emails, your Twitter DMs, etc.?
Citizenship is loyalty. That is what it means legally and what it has meant in practice. Especially if your family is still in your country of citizenship.
Yes, this would mean the international segmenting of the internet, at least in terms of which websites you plug your personal data into vs. “just browse”. This strikes us nerds as awful. But perhaps anything else was just a naive fantasy. The last decade should have shattered our innocence. What happens online matters for great power politics, and great power politics matters a lot for ordinary people.
[1] The current security clearance process is at least partly a jobs programs for people with boring, unadventurous youths. I’m not advocating for that, just the principle of a security clearance.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#185Should there be citizenship requirements for access to customer data at that scale? Background checks? Security clearances?[1] When you have so much private data and the ability to put words into people’s mouths, aren’t you a national security asset at that point? Today it’s some bitcoin scammers, tomorrow it’s Russian or Chinese intelligence. If I was in charge of Russian or Chinese intelligence, I’d make sure that…
Now with the advent of all these apparent "bots", "state actors", etc. etc. I'm starting to think it might not be a bad idea.
There's a bunch of "what-ifs" however like "what if the government starts removing content it doesn't like", "should you be able to be banned from the platform?", etc.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#186Should there be citizenship requirements for access to customer data at that scale? Background checks? Security clearances?[1] When you have so much private data and the ability to put words into people’s mouths, aren’t you a national security asset at that point? Today it’s some bitcoin scammers, tomorrow it’s Russian or Chinese intelligence. If I was in charge of Russian or Chinese intelligence, I’d make sure that…
[1]: https://www.reuters.com/article/us-twitter-cyber-netherlands...
Re: More than 1k people at Twitter had ability to aid hack of accounts
#187Should there be citizenship requirements for access to customer data at that scale? Background checks? Security clearances?[1] When you have so much private data and the ability to put words into people’s mouths, aren’t you a national security asset at that point? Today it’s some bitcoin scammers, tomorrow it’s Russian or Chinese intelligence. If I was in charge of Russian or Chinese intelligence, I’d make sure that…
That's a very US-centric view. Twitter has a lot of non-US users as well. In fact, a Dutch right-wing politician was apparently targeted in this attack.[1] How would such a requirement help in this case? [1]: https://www.reuters.com/article/us-twitter-cyber-netherlands...
Re: More than 1k people at Twitter had ability to aid hack of accounts
#188Earlier quoted context omitted.
Well yes, being able to give priority to at-risk patients would fall under necessary use. I doubt the receptionist has your actual medical history, but they would certainly see an indicator of your risk category.
There is no such thing as “necessary use” and the GDPR does not specify that an organisation must restrict employee access to personal data to only those whose access is “strictly necessary” (the cookie law contains that phrase, but in a completely different context). The only thing the GDPR says that would apply in this circumstance is this: > processed in a manner that ensures appropriate security of the personal d…
Combined with, as you say, that GDPR also states as a matter of principle data must be “processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing” - I would take that as meaning you can’t just leave data openly accessible to people who don’t need to process it and rely on them not accessing data they don’t need, you are expected to protect the data against that risk. I.e. secure access to data so it can only be processed for necessary purposes.
It is possible for small organizations that ‘telling Janet she isn’t allowed to look in the customer accounts spreadsheet’ is an adequate control but as organizations get bigger obviously the expectation that technical controls should be in place expands.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#189Earlier quoted context omitted.
‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…
Twitter's blue check is a growth hack, not a notary public.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#190For comparison, at Google in 2011, I was one of ~10 or so engineers that had the ability to view private Gmail or Gplus data (access that was heavily documented and audited). That being said, Google did have to go through it's own public humiliation [1] to put a system like that in place. https://gawker.com/5637234/gcreep-google-engineer-stalked-te...
It ultimately comes down to the person involved and I do not believe anyone can control the human factor.