Earlier quoted context omitted.
The question isn't how you and I can individually avoid being spear phished, but what policies can be implemented across an organization to prevent it. Even the most trusted security teams aren't going to be allowed to summarily fire everyone who fails the test. I also think this is a much stricter standard than you're recognizing. In my company's last spearphishing test, they sent out a link purporting to be a compa…
Just wondering if employees failed the test just by clicking on the link or if they had to actually enter some passwords or confidential information on the fake survey site. I wouldn't think clicking a link then looking at the address bar and seeing the domain name is wrong, then closing the page would be a problem, would it?
More than 1k people at Twitter had ability to aid hack of accounts
201–210 of 238 posts
Re: More than 1k people at Twitter had ability to aid hack of accounts
#202Worth mentioning only 5,000 people work at Twitter.
There are ~330 million active twitter users, which means 330,000 users per employee with access to admin accounts. That ratio is massively high compared to a large corporate (i.e, a global bank). In a typical global bank lets says there are 100,000 employees, with about 25-50 IT people with the rights to admin accounts (from first line support to third line engineers) that's only 2,000-4,000 users per IT admin person…
Re: More than 1k people at Twitter had ability to aid hack of accounts
#203Earlier quoted context omitted.
PGP solved this issue 30 years ago. I can not believe we have this discussion in 2020
I don't tweet much, but when I do I'd love to be able to sign them like I sign my git commits.
https://github.com/shabda/tweet-signer
At it's core it's just a spec, so feel free to write your own tools! Suggestions for improving the spec welcome. Please use Github issues
Re: More than 1k people at Twitter had ability to aid hack of accounts
#204For comparison, at Google in 2011, I was one of ~10 or so engineers that had the ability to view private Gmail or Gplus data (access that was heavily documented and audited). That being said, Google did have to go through it's own public humiliation [1] to put a system like that in place. https://gawker.com/5637234/gcreep-google-engineer-stalked-te...
I almost wonder if government officials should be outright banned from using any private messaging platform that isn't hosted by the government itself. There is just too much power in information.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#205Earlier quoted context omitted.
It's very easy to avoid being spear phished: do not trust any unsolicited message over any medium. Email/text/phone message/popup window purporting to be from your registrar with an urgent call to action? Ignore said call and contact them directly via known good number, email address, URL, etc. EDIT: Voice mimicry scam? Verify via known channel before taking action.
The question isn't how you and I can individually avoid being spear phished, but what policies can be implemented across an organization to prevent it. Even the most trusted security teams aren't going to be allowed to summarily fire everyone who fails the test. I also think this is a much stricter standard than you're recognizing. In my company's last spearphishing test, they sent out a link purporting to be a compa…
Re: More than 1k people at Twitter had ability to aid hack of accounts
#206Earlier quoted context omitted.
Disable links in emails by default goes a long way.
How would this work? I get emails like "you have been added to gerrit review" and " Redmine issue was updated" several time a day and I need to open these links.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#207For comparison, at Google in 2011, I was one of ~10 or so engineers that had the ability to view private Gmail or Gplus data (access that was heavily documented and audited). That being said, Google did have to go through it's own public humiliation [1] to put a system like that in place. https://gawker.com/5637234/gcreep-google-engineer-stalked-te...
Don't all engineers working on Gmail theoretically have the same access by conspiring with a code reviewer or two? It ultimately comes down to the person involved and I do not believe anyone can control the human factor.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#208Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .
> There's thousands of people that have the ability to drain your bank account right now. That's false equivalence. If a bank employee drains my account without authorization, it won't be difficult to prove and get back. But once your data leaks, it's out there.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#209Earlier quoted context omitted.
The question isn't how you and I can individually avoid being spear phished, but what policies can be implemented across an organization to prevent it. Even the most trusted security teams aren't going to be allowed to summarily fire everyone who fails the test. I also think this is a much stricter standard than you're recognizing. In my company's last spearphishing test, they sent out a link purporting to be a compa…
Just wondering if employees failed the test just by clicking on the link or if they had to actually enter some passwords or confidential information on the fake survey site. I wouldn't think clicking a link then looking at the address bar and seeing the domain name is wrong, then closing the page would be a problem, would it?
Re: More than 1k people at Twitter had ability to aid hack of accounts
#210Earlier quoted context omitted.
> If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. Not really, a blue checkmark is just a status symbol.
This is exactly the problem with the blue tick. It's basically meaningless other than as a budge of honour. It's also restricted to large companies and 'public' figures. What I'd like to see is, the Blue Tick being restored to be an actual mark of Verification, and be something that anyone can apply for with the appropriate identification documentation. Additionally, there should then be a toggle switch, where only V…
But at the same time, in aggregate, blue check marks do provide some degree of legitimacy to accounts - yes, this account is that person you know from outside twitter.
But twitter don’t do a great job of explaining how they verified an account, or even who they verified it to be. As has recently gone viral, twitter gave @sistersofmercy a blue check mark, because they really are the catholic institute of that name - not the band (@tsomofficial doesn’t have a blue check mark ...)
I think there’s the basis of something interesting in ‘verified accounts’ - and for sure they’re flawed - but I don’t think ‘meaningless’ is correct.