Earlier quoted context omitted.
You know, I used to think that locking down certain websites to citizens of the country the website resides in was a bad thing. Now with the advent of all these apparent "bots", "state actors", etc. etc. I'm starting to think it might not be a bad idea. There's a bunch of "what-ifs" however like "what if the government starts removing content it doesn't like", "should you be able to be banned from the platform?", etc…
At least within the US, I think sufficiently large platforms should not be allowed to censor on the basis of viewpoint. But that is exactly the kind of political question that nation states, not international forces, should be answering.
More than 1k people at Twitter had ability to aid hack of accounts
231–238 of 238 posts
Re: More than 1k people at Twitter had ability to aid hack of accounts
#232Should there be citizenship requirements for access to customer data at that scale? Background checks? Security clearances?[1] When you have so much private data and the ability to put words into people’s mouths, aren’t you a national security asset at that point? Today it’s some bitcoin scammers, tomorrow it’s Russian or Chinese intelligence. If I was in charge of Russian or Chinese intelligence, I’d make sure that…
Re: More than 1k people at Twitter had ability to aid hack of accounts
#233I created a Twitter account close to a month ago and it was immediately suspended because it "appears to have exhibited automated behavior that violates the Twitter Rules". Well it did not really do anything yet, even less so anything against their rules. The account is still suspended despite multiple appeals and messages. At the same time, dozens (hundreds?) of verified accounts get taken over. I think their fraud…
They do this for all new accounts. It's a way to harvest phone numbers from unsuspecting victims of this surveillance. It doesn't matter from what ip, machine or whatever you register. It will automatically get suspended because I think they've realized it's easier to force people to enter their phone numbers in "protection" after they just created an account rather than to just ask for it during signup. Less questio…
Re: More than 1k people at Twitter had ability to aid hack of accounts
#234twitter, seems to have a cowboy engineering culture. that's why one of their exec's blamed rails for their failure to combat harassment[0]. n I bet now, if they still ran rails, it would've been blamed lol. [0]: https://char.gd/recharged/daily/twitter-blames-ruby-on-rails...
Re: More than 1k people at Twitter had ability to aid hack of accounts
#235Earlier quoted context omitted.
> probably wouldn't have stopped this. Uh yes, that is how audit trails work
Auditing tells you what happened, it doesn't prevent it from happening. If they have logs then they can use it in the future (and it seems they do) to design better protections but only active alarms and security controls can prevent something happening in real-time. However that does raise the question of why Twitter ever needs such access to someone's account in the first place, especially without a combination of…
Re: More than 1k people at Twitter had ability to aid hack of accounts
#236I remember during my time with a large mobile carrier in UK I was told of a person in the company who could in theory read any SMS on the network. Mind you this was literally one person for over 30 million customers. He had a high security clearance, extensive security training and the powers vested in him were used mainly to identify scammers and other criminals. Pretty sure this was a requirement set by law - we ne…
We should be limiting what people can do, and not giving them the keys to the kingdom.
Re: More than 1k people at Twitter had ability to aid hack of accounts
#237> implication that a hostile government might be able to cause even greater havoc. it is stuff like this that make me question the whole article. like yes, obviously this was no "hostile" government since they were just scamming for some pocket change. but also how exactly would this hostile government create havoc with twitter?
There are so many government officials on Twitter, and causing any number of them to tweet something plausible but untrue could be a big deal - from moving markets to moving troops. Just imagine if Donald Trump's account tweeted that Antifa should be shot on sight. I'm certain people would die because of that. Or, perhaps slightly less plausibly, that Boris Johnson tweeted that he's had enough and is abandoning negot…
Re: More than 1k people at Twitter had ability to aid hack of accounts
#238Earlier quoted context omitted.
Just wondering if employees failed the test just by clicking on the link or if they had to actually enter some passwords or confidential information on the fake survey site. I wouldn't think clicking a link then looking at the address bar and seeing the domain name is wrong, then closing the page would be a problem, would it?
We got judged on both. Most security teams in my experience feel that even clicking on the link is a big risk, although I've never read a more detailed explanation of why than "oh there might be a 0-day".
The corporate security team sent out the email. It had a link with no actual content, giving an error, but that got you on the list of people with bad security behavior.
The trouble at my office was that most employees were highly capable security researchers. These are people who reverse engineer malware for pay and for fun. Of course they eagerly attempted to download from the link! They wanted fresh new malware. People would typically download via wget in a virtual machine on a PC without important data.