Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

181–190 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#181

Earlier quoted context omitted.

PGP solved this issue 30 years ago. I can not believe we have this discussion in 2020

Except that the problem isn't the signature itself, it's the required infrastructure. Grandma doesn't know how to check The Donald's signature. And, of course, the infrastructure is hard (just check the unfixable problems with the PGP persistent DOS attacks that were discussed a year or 2 ago).

Twitter knows how to check a signature though.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#182
post #176

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

How would a Twitter account start a war?

I don't know if it's possible.

But people who do think it's possible probably think it would happen something like this: https://twitter.com/realdonaldtrump/status/12139194805748121...

Re: More than 1k people at Twitter had ability to aid hack of accounts

#183

Earlier quoted context omitted.

There may be a bit of an hyperbole in the expression "accounts that could start a war": there are indeed accounts of people who could start a war, yet I fail to imagine how a single tweet, or a few tweets, by some hacker could actually start a war. Escalate tensions, sure. But I assume world leaders and their advisors don't rely (solely) on tweets before calling the cavalry.

Sure, how about we dial the hyperbole down a bit, to "accounts universally known to be a primary mechanisms for announcement of international policy by the leader of a country which has started 12 'armed conflicts' in the last 20 years (or 14 if you count them doing it twice in Iraq and Lybia)"? I find it quite horrifying that elected officials are legally allowed to use totally unaccountable social media platforms t…

Mostly, I find it horrifying that we would elect an official whose grasp of diplomacy is so poor as to continually use completely unfiltered channels, with little grasp of the effect of such communications.

The ultimate check on the behavior of elected officials is supposed to be the voters. You shouldn't have to have laws to prevent them from making bad choices. In this case, the voters like their speech to be "tell it like it is", which mostly means hating the same people they hate. They're getting what they asked for, and are likely to ask for it again.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#184
Should there be citizenship requirements for access to customer data at that scale? Background checks? Security clearances?[1] When you have so much private data and the ability to put words into people’s mouths, aren’t you a national security asset at that point? Today it’s some bitcoin scammers, tomorrow it’s Russian or Chinese intelligence. If I was in charge of Russian or Chinese intelligence, I’d make sure that my citizens working inside these companies are using that data to my advantage, or are at least positioned to should an opportunity arise.

There is already tons of evidence of Chinese nationals coming to the US to work at these companies with the express purpose of stealing trade secrets and sending them back to China. Why would the Chinese government stop there? How about your personal emails, your Twitter DMs, etc.?

Citizenship is loyalty. That is what it means legally and what it has meant in practice. Especially if your family is still in your country of citizenship.

Yes, this would mean the international segmenting of the internet, at least in terms of which websites you plug your personal data into vs. “just browse”. This strikes us nerds as awful. But perhaps anything else was just a naive fantasy. The last decade should have shattered our innocence. What happens online matters for great power politics, and great power politics matters a lot for ordinary people.

[1] The current security clearance process is at least partly a jobs programs for people with boring, unadventurous youths. I’m not advocating for that, just the principle of a security clearance.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#185

Should there be citizenship requirements for access to customer data at that scale? Background checks? Security clearances?[1] When you have so much private data and the ability to put words into people’s mouths, aren’t you a national security asset at that point? Today it’s some bitcoin scammers, tomorrow it’s Russian or Chinese intelligence. If I was in charge of Russian or Chinese intelligence, I’d make sure that…

You know, I used to think that locking down certain websites to citizens of the country the website resides in was a bad thing.

Now with the advent of all these apparent "bots", "state actors", etc. etc. I'm starting to think it might not be a bad idea.

There's a bunch of "what-ifs" however like "what if the government starts removing content it doesn't like", "should you be able to be banned from the platform?", etc.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#186

Should there be citizenship requirements for access to customer data at that scale? Background checks? Security clearances?[1] When you have so much private data and the ability to put words into people’s mouths, aren’t you a national security asset at that point? Today it’s some bitcoin scammers, tomorrow it’s Russian or Chinese intelligence. If I was in charge of Russian or Chinese intelligence, I’d make sure that…

That's a very US-centric view. Twitter has a lot of non-US users as well. In fact, a Dutch right-wing politician was apparently targeted in this attack.[1] How would such a requirement help in this case?

[1]: https://www.reuters.com/article/us-twitter-cyber-netherlands...

Re: More than 1k people at Twitter had ability to aid hack of accounts

#187

Should there be citizenship requirements for access to customer data at that scale? Background checks? Security clearances?[1] When you have so much private data and the ability to put words into people’s mouths, aren’t you a national security asset at that point? Today it’s some bitcoin scammers, tomorrow it’s Russian or Chinese intelligence. If I was in charge of Russian or Chinese intelligence, I’d make sure that…

That's a very US-centric view. Twitter has a lot of non-US users as well. In fact, a Dutch right-wing politician was apparently targeted in this attack.[1] How would such a requirement help in this case? [1]: https://www.reuters.com/article/us-twitter-cyber-netherlands...

Maybe the Dutch should do the same thing. Or throw their lot in with a country or group of countries they trust (EU, EU+x, NATO, etc.). The geopolitics of this would be complicated. But that has been life for small polities for thousands of years.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#188

Earlier quoted context omitted.

Well yes, being able to give priority to at-risk patients would fall under necessary use. I doubt the receptionist has your actual medical history, but they would certainly see an indicator of your risk category.

There is no such thing as “necessary use” and the GDPR does not specify that an organisation must restrict employee access to personal data to only those whose access is “strictly necessary” (the cookie law contains that phrase, but in a completely different context). The only thing the GDPR says that would apply in this circumstance is this: > processed in a manner that ensures appropriate security of the personal d…

GDPR Article 6 spends a lot of time defining ‘necessary’ use. It says that ‘processing data’ - which is defined very broadly and includes accessing it - is only legal if it is for a ‘necessary purpose’ - either necessary to accomplish contracted work for a customer, comply with the law, or some few other permitted categories.

Combined with, as you say, that GDPR also states as a matter of principle data must be “processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing” - I would take that as meaning you can’t just leave data openly accessible to people who don’t need to process it and rely on them not accessing data they don’t need, you are expected to protect the data against that risk. I.e. secure access to data so it can only be processed for necessary purposes.

It is possible for small organizations that ‘telling Janet she isn’t allowed to look in the customer accounts spreadsheet’ is an adequate control but as organizations get bigger obviously the expectation that technical controls should be in place expands.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#189
post #118

Earlier quoted context omitted.

‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…

Twitter's blue check is a growth hack, not a notary public.

De facto or de jure?

Re: More than 1k people at Twitter had ability to aid hack of accounts

#190

For comparison, at Google in 2011, I was one of ~10 or so engineers that had the ability to view private Gmail or Gplus data (access that was heavily documented and audited). That being said, Google did have to go through it's own public humiliation [1] to put a system like that in place. https://gawker.com/5637234/gcreep-google-engineer-stalked-te...

Don't all engineers working on Gmail theoretically have the same access by conspiring with a code reviewer or two?

It ultimately comes down to the person involved and I do not believe anyone can control the human factor.

Post reply on HN