Live data from Hacker News

An update on our security incident

blog.twitter.com

21–30 of 245 posts

Re: An update on our security incident

#21

They should require hardware security devices (dongles). Really Twitter should be ashamed of their poor internal security.

Note that not all hardware security devices are safe. U2F security devices are safe against phishing; OTP security devices are not safe against phishing.

Re: An update on our security incident

#23
post #5

Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update... > The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all o…

Were the spear fishing attacked also used to get 2FA, or did these accounts not have 2FA? Would hardware based 2FA not have stopped this?

Re: An update on our security incident

#24
post #18
post #8

It is inexcusable that Twitter is employing people who are susceptible to social engineering attacks like this. This is simple training and seriousness.

Training that is notorious for being ineffective in practise and usually more about box ticking. Assuming that none of your employees fall for phising, much less targeted phising, is woefully unrealistic. Especially at twitter's scale. Assuming humans won't do stupid things 100% of the time is never an effective security control.

This is an excessively pessimistic take on security training. How many spear phishing attempts have been thwarted because the employee knew better?

It’s not a solution to the problem, but it certainly helps.

Re: An update on our security incident

#25
post #8

It is inexcusable that Twitter is employing people who are susceptible to social engineering attacks like this. This is simple training and seriousness.

You too could be social engineered. The worlds foremost security specialists are not immune, good chance that there is some social engineering vector that would work on you.

Admitting that to yourself is a huge step forward in being able to detect it. Believing yourself immune increases your chances of being spearfished.

Re: An update on our security incident

#26

Earlier quoted context omitted.

It just takes one mistake to be spearfished.

I will freely admit that I fell for a phishing campaign. I’d just bought something on eBay (this was a while ago). I got an email about something in my account later that day that made it through my spam filters. I clicked on it, signed in, and then realized I’d done the deed. Nothing happened or was lost, but yes - it just takes one quick mistake.

I don’t get it. You know your ebay password?

Re: An update on our security incident

#27
post #8

It is inexcusable that Twitter is employing people who are susceptible to social engineering attacks like this. This is simple training and seriousness.

You too could be social engineered. The worlds foremost security specialists are not immune, good chance that there is some social engineering vector that would work on you. Admitting that to yourself is a huge step forward in being able to detect it. Believing yourself immune increases your chances of being spearfished.

> The worlds foremost security specialists are not immune

I bet there are some that are immune. But yes, 99% of employees can be phished.

Re: An update on our security incident

#28

They should require hardware security devices (dongles). Really Twitter should be ashamed of their poor internal security.

Dongles are rare here in the US. But I know that bloomberg uses them. I was shocked when I learned that retail banks in Singapore give everyone dongles to log in. In the US that's tyranny Lol

Rare for employees or rare for consumers? Companies can push much higher security onto employees than onto consumers.

Re: An update on our security incident

#29
post #5

Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update... > The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all o…

Were the spear fishing attacked also used to get 2FA, or did these accounts not have 2FA? Would hardware based 2FA not have stopped this?

I haven't seen a form of phishing that hardware 2FA doesn't stop. Yes, it would have.

Re: An update on our security incident

#30

Earlier quoted context omitted.

I will freely admit that I fell for a phishing campaign. I’d just bought something on eBay (this was a while ago). I got an email about something in my account later that day that made it through my spam filters. I clicked on it, signed in, and then realized I’d done the deed. Nothing happened or was lost, but yes - it just takes one quick mistake.

I don’t get it. You know your ebay password?

Some password databases involve copy and pasting or autotyping. If you want automatic hostname verification you need a password database integrated with your browser. On mobile many browsers don't support extensions so integrating my password database into the browser would be hard.

In short, I do not know my ebay password, but I could have fallen for this phishing attack.

Post reply on HN