They should require hardware security devices (dongles). Really Twitter should be ashamed of their poor internal security.
An update on our security incident
21–30 of 245 posts
Re: An update on our security incident
#22Re: An update on our security incident
#23Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update... > The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all o…
Re: An update on our security incident
#24It is inexcusable that Twitter is employing people who are susceptible to social engineering attacks like this. This is simple training and seriousness.
Training that is notorious for being ineffective in practise and usually more about box ticking. Assuming that none of your employees fall for phising, much less targeted phising, is woefully unrealistic. Especially at twitter's scale. Assuming humans won't do stupid things 100% of the time is never an effective security control.
It’s not a solution to the problem, but it certainly helps.
Re: An update on our security incident
#25It is inexcusable that Twitter is employing people who are susceptible to social engineering attacks like this. This is simple training and seriousness.
Admitting that to yourself is a huge step forward in being able to detect it. Believing yourself immune increases your chances of being spearfished.
Re: An update on our security incident
#26Earlier quoted context omitted.
It just takes one mistake to be spearfished.
I will freely admit that I fell for a phishing campaign. I’d just bought something on eBay (this was a while ago). I got an email about something in my account later that day that made it through my spam filters. I clicked on it, signed in, and then realized I’d done the deed. Nothing happened or was lost, but yes - it just takes one quick mistake.
Re: An update on our security incident
#27It is inexcusable that Twitter is employing people who are susceptible to social engineering attacks like this. This is simple training and seriousness.
You too could be social engineered. The worlds foremost security specialists are not immune, good chance that there is some social engineering vector that would work on you. Admitting that to yourself is a huge step forward in being able to detect it. Believing yourself immune increases your chances of being spearfished.
I bet there are some that are immune. But yes, 99% of employees can be phished.
Re: An update on our security incident
#28They should require hardware security devices (dongles). Really Twitter should be ashamed of their poor internal security.
Dongles are rare here in the US. But I know that bloomberg uses them. I was shocked when I learned that retail banks in Singapore give everyone dongles to log in. In the US that's tyranny Lol
Re: An update on our security incident
#29Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update... > The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all o…
Were the spear fishing attacked also used to get 2FA, or did these accounts not have 2FA? Would hardware based 2FA not have stopped this?
Re: An update on our security incident
#30Earlier quoted context omitted.
I will freely admit that I fell for a phishing campaign. I’d just bought something on eBay (this was a while ago). I got an email about something in my account later that day that made it through my spam filters. I clicked on it, signed in, and then realized I’d done the deed. Nothing happened or was lost, but yes - it just takes one quick mistake.
I don’t get it. You know your ebay password?
In short, I do not know my ebay password, but I could have fallen for this phishing attack.