Live data from Hacker News

An update on our security incident

blog.twitter.com

41–50 of 245 posts

Re: An update on our security incident

#41
post #37
post #18

Earlier quoted context omitted.

Training that is notorious for being ineffective in practise and usually more about box ticking. Assuming that none of your employees fall for phising, much less targeted phising, is woefully unrealistic. Especially at twitter's scale. Assuming humans won't do stupid things 100% of the time is never an effective security control.

Where I work there is training software that is somewhat effective at preventing phising - it actually sends out phising emails itself. Then employees who fall for it are given extra training (in a no fault sort of way).

Perhaps, but im also wary of these types of things, because i worry that people will feel embarassed at being tricked, and will (maybe subconciously) see the internal security team as the enemy, which is also a bad outcome.

I also worry that the emails might not represent real attack emails, and we end up training users to identify the test emails but not real attack emails.

(Not that i got any better solution)

Re: An update on our security incident

#42
post #5

Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update... > The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all o…

Were the spear fishing attacked also used to get 2FA, or did these accounts not have 2FA? Would hardware based 2FA not have stopped this?

Without details it's hard to say. They talk about "phone spear phishing". It's within the realm of that description to say they were hit the same way someone I know recently was - someone called and said "Can you just install Teamviewer on your desktop for me and give access to a logged on session".

Re: An update on our security incident

#43

They should require hardware security devices (dongles). Really Twitter should be ashamed of their poor internal security.

Dongles are rare here in the US. But I know that bloomberg uses them. I was shocked when I learned that retail banks in Singapore give everyone dongles to log in. In the US that's tyranny Lol

We're talking about companies, not users. Competent companies can and absolutely do require dongles (or equivalently trustable corporate hardware) to log in to their systems.

Re: An update on our security incident

#44
post #29

Earlier quoted context omitted.

Were the spear fishing attacked also used to get 2FA, or did these accounts not have 2FA? Would hardware based 2FA not have stopped this?

I haven't seen a form of phishing that hardware 2FA doesn't stop. Yes, it would have.

The way it is worded can also mean that there were XSS vulnerabilities in the internal tool since they are saying "gained information about how our processes work". I feel like that's a strange and vague thing to say. The right kind of xss vulnerability would enable them to bypass 2fa too, maybe steal backup codes even.

Re: An update on our security incident

#45
post #5

Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update... > The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all o…

Were the spear fishing attacked also used to get 2FA, or did these accounts not have 2FA? Would hardware based 2FA not have stopped this?

Maybe? I imagine a spear fishing attack could entail the target is sent to a false panel to login where it sends a true 2FA request. The target then freely gives this 2FA code to the attacker.

Re: An update on our security incident

#46
post #5

Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update... > The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all o…

Ok, we'll change to that from https://www.reuters.com/article/us-twitter-cyber/twitter-say.... Thanks!

Re: An update on our security incident

#47
Frankly, I love Twitter. They've always seemed like the "scrappy" big player in the tech space that's played just the right side of the norm in many cases. An appropriately filtered experience on Twitter as a user is actually quite fun.

That said, much of this is atrocious news. For all of their engineering prowess, seeing poor opsec failures combined with the lack of basic security principles like "containment of blast radius" and "fast response to critical failures" is not something you can easily forgive at this scale.

But who am I kidding... it would be especially rich if some of these takeovers were enabled by simjacking-like attacks. Not that long ago, the only two-factor auth mechanism that worked for me was SMS.

Re: An update on our security incident

#48
>

For a split second I thought they tweeted from Trump's account. But then 36 gave it away.

Imagine if they did and decided to declare global thermonuclear war.

POTUS should NOT have an account on Twitter.

Speaking of POTUS, what about Deep Fakes? There should be an international agreement on how nations should handle such emerging threats to global stability.

Re: An update on our security incident

#49
post #5

Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update... > The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all o…

> ultimately Tweeting from 45

for a moment I thought it read `tweeting from 45's`

Re: An update on our security incident

#50

They should require hardware security devices (dongles). Really Twitter should be ashamed of their poor internal security.

Dongles are rare here in the US. But I know that bloomberg uses them. I was shocked when I learned that retail banks in Singapore give everyone dongles to log in. In the US that's tyranny Lol

I work for a crypto currency company and it was the first time in my career that I was issued a YubiKey (I once had an RSA 2fa token for vpn access). It took some getting used to but now I just keep in on my keychain and I always have it with me. I need it for SSO, git, VPN, and basically all internal services.

They aren't sufficient by themselves however, they don't protect from is malicious internal employees.

Post reply on HN