Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

211–220 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#211

Earlier quoted context omitted.

I can imagine at minimum this would help with bots. Considering the problems you state are actual systematic issues we have in our society I would expect that the verification process should not be perceived as working towards solving those.

It would also exclude venerable people which is the problem with the real name idea

*vulnerable, presumably

Re: More than 1k people at Twitter had ability to aid hack of accounts

#212

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

> There's thousands of people that have the ability to drain your bank account right now.

Let them do it... the bank will always be responsible and it will always be solved without much issue.

Twitter accounts though... good luck taking back theses bitcoins from all the one that got scammed. Good luck even getting back your account if you aren't named Bill Gates.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#213

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…

pending verification that the blue check mark still applies to the person now in control of that account

Why would you want to ever allow an admin to transfer control of a verified account to an unverified person?

If you're saying that the account recovery process needs to be at least as secure as the credential that was verified (e.g. email address), then I agree. But I don't think reversion to a "pending" state would ever be desirable, though.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#214
post #113

Earlier quoted context omitted.

> If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. Not really, a blue checkmark is just a status symbol.

This is exactly the problem with the blue tick. It's basically meaningless other than as a budge of honour. It's also restricted to large companies and 'public' figures. What I'd like to see is, the Blue Tick being restored to be an actual mark of Verification, and be something that anyone can apply for with the appropriate identification documentation. Additionally, there should then be a toggle switch, where only V…

I think the Yonatan Zunger had the right solution to this: Verify Facts Not People.

Replace the checkmark with a Verified Badge that says their position if they're an elected official or major organization leader, or just Real Name if they've verified their ID.

He wrote this in response to the Jason Kessler kerfuffle, well before the "factcheckUK" stunt, but it would have actually solved that too! Imagine seeing the username "factcheckUK" with the Verified Badge "Conservative and Unionist Party, UK 🇬🇧".

https://medium.com/@yonatanzunger/the-hard-lessons-of-blue-c...

Re: More than 1k people at Twitter had ability to aid hack of accounts

#215

Earlier quoted context omitted.

It would also exclude venerable people which is the problem with the real name idea

We can imagine a system where twitter checks that person is a real unique human but does not use their personal data for anything else.

How to verify uniqueness?

Re: More than 1k people at Twitter had ability to aid hack of accounts

#217

Earlier quoted context omitted.

This is exactly the problem with the blue tick. It's basically meaningless other than as a budge of honour. It's also restricted to large companies and 'public' figures. What I'd like to see is, the Blue Tick being restored to be an actual mark of Verification, and be something that anyone can apply for with the appropriate identification documentation. Additionally, there should then be a toggle switch, where only V…

Do you really think blue check marks are ‘meaningless’? Are you thinking of them in the context of, among your peers who has blue checks and who doesn’t being somewhat arbitrary? Because for sure if you’re part of a professional community that is common - you’ll find academics and journalists and medical professionals and so on all have very random experiences with blue check marks, much like tech does. But at the sa…

What do you think of Yonatan Zunger's proposed fix, to verify facts and not people?

So @sistersofmercy might get a Verified Badge saying "Religious Institute, Ireland", and @tsomofficial might get a Verified Badge saying "Musical Group, UK".

He wrote this in response to the Jason Kessler kerfuffle, well before the "factcheckUK" stunt, but it would have actually solved that too! Imagine seeing the username "factcheckUK" with the Verified Badge "Conservative and Unionist Party, UK 🇬🇧".

https://medium.com/@yonatanzunger/the-hard-lessons-of-blue-c...

Re: More than 1k people at Twitter had ability to aid hack of accounts

#218
post #25

twitter, seems to have a cowboy engineering culture. that's why one of their exec's blamed rails for their failure to combat harassment[0]. n I bet now, if they still ran rails, it would've been blamed lol. [0]: https://char.gd/recharged/daily/twitter-blames-ruby-on-rails...

"...a rudimentary web-application framework that made it nearly impossible to find a technical solution to the harassment problem" To me, this is analogous to the perhaps undeserved "the internet is a series of tubes" lampooning, but I'm still chuckling how they managed to word that so poorly.

It sounds like a perfect answer to those claiming "harassement" is a technology problem.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#220

Earlier quoted context omitted.

Do you really think blue check marks are ‘meaningless’? Are you thinking of them in the context of, among your peers who has blue checks and who doesn’t being somewhat arbitrary? Because for sure if you’re part of a professional community that is common - you’ll find academics and journalists and medical professionals and so on all have very random experiences with blue check marks, much like tech does. But at the sa…

What do you think of Yonatan Zunger's proposed fix, to verify facts and not people? So @sistersofmercy might get a Verified Badge saying "Religious Institute, Ireland", and @tsomofficial might get a Verified Badge saying "Musical Group, UK". He wrote this in response to the Jason Kessler kerfuffle, well before the "factcheckUK" stunt, but it would have actually solved that too! Imagine seeing the username "factcheckU…

100% this is how to make it meaningful.
Post reply on HN