Live data from Hacker News

An update on our security incident

blog.twitter.com

51–60 of 245 posts

Re: An update on our security incident

#51
post #2

No employee should have the power to subvert 130 high value accounts in a short time period.

Why do we even have 'high value' accounts on a centralized platform?

Why isn't there a whitehouse.gov ActivityPub instance that no single admin can censor or subvert?

Re: An update on our security incident

#52
post #28

Earlier quoted context omitted.

Dongles are rare here in the US. But I know that bloomberg uses them. I was shocked when I learned that retail banks in Singapore give everyone dongles to log in. In the US that's tyranny Lol

Rare for employees or rare for consumers? Companies can push much higher security onto employees than onto consumers.

How do they deal with lost dongles?

Re: An update on our security incident

#53
post #5

Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update... > The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all o…

Why are internal employee tools publically accessible? Minimum they should require VPN access, but really go further with Zero Trust.

Another instance where zero-trust networking has utterly failed.

Security comes in layers. That first layer of requiring a VPN can stop many types of attacks from happening.

Next layer is requiring MFA for VPN access. Then for admin access, require MFA only from approved devices on the domain.

Large banks and the DoD have been doing this for years.

The "fail often and fail fast" crew are always reinventing the wheel after bad experiences. I honestly feel sorry for them.

Re: An update on our security incident

#54
post #30

Earlier quoted context omitted.

I don’t get it. You know your ebay password?

Some password databases involve copy and pasting or autotyping. If you want automatic hostname verification you need a password database integrated with your browser. On mobile many browsers don't support extensions so integrating my password database into the browser would be hard. In short, I do not know my ebay password, but I could have fallen for this phishing attack.

On mobile this is possible even without browser extensions - enpass, lastpass etc work just fine in Chrome or any other app, if it detects a password field.

Re: An update on our security incident

#55
post #2

No employee should have the power to subvert 130 high value accounts in a short time period.

Why do we even have 'high value' accounts on a centralized platform? Why isn't there a whitehouse.gov ActivityPub instance that no single admin can censor or subvert?

We will do that now. We will start the competitive bidding process, and we expect the RFP paperwork to be returned by October, 2021. After that, if there are no injunctions filed because of the bidding process, preliminary design documents will start being created. Preliminary design review will occur August 2022. ...

Re: An update on our security incident

#56

They should require hardware security devices (dongles). Really Twitter should be ashamed of their poor internal security.

It depends on the attack.

For example if a Twitter user was logged in with a dongle but the attacker had access via social engeneered remote desktop access a dongle still could mean access to private data.

But yes. As far as I know Google and Facebook require them. Also Google sometimes require permission of an other co-worker to access data.

Re: An update on our security incident

#57
post #49
post #5

Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update... > The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all o…

> ultimately Tweeting from 45 for a moment I thought it read `tweeting from 45's`

Nah, you're thinking of putting a 33 RPM disc on the phonograph, then setting the playback speed to 45 RPM.

Hands down the easiest way to make Shaun Cassidy sound like one of the Chipmunks.

Re: An update on our security incident

#58
post #50

Earlier quoted context omitted.

Dongles are rare here in the US. But I know that bloomberg uses them. I was shocked when I learned that retail banks in Singapore give everyone dongles to log in. In the US that's tyranny Lol

I work for a crypto currency company and it was the first time in my career that I was issued a YubiKey (I once had an RSA 2fa token for vpn access). It took some getting used to but now I just keep in on my keychain and I always have it with me. I need it for SSO, git, VPN, and basically all internal services. They aren't sufficient by themselves however, they don't protect from is malicious internal employees.

Preparing for malicious internal employees seems to me like preparing for "the big one," in the northwest.

Do a cursory amount of preparation. Outside of basic measures, you're probably doing more harm to the business than good. The likelihood of internal malicious attackers is very low in the grand scheme of things, and the attack surface is huge.

Most companies are going to be compromised by outside attackers—its there that you should focus your energy. If internal attackers are your biggest threat, you've done a fantastic job.

Re: An update on our security incident

#59

Earlier quoted context omitted.

Why are internal employee tools publically accessible? Minimum they should require VPN access, but really go further with Zero Trust.

AFIK, in a Zero Trust Architecture a VPN is considered a perimeter and therefore it becomes a vector of attack to access systems of authoritative decision. Many security researchers have already established that the benefits of a VPN especially in the modern distributed world are marginal at best. Basically, yes a VPN makes you a tiny bit safer but it also adds a lot of networking complexity and adds more friction to…

> On the other hand if every service you use has its own authentication...

This would be a nightmare for the people managing any nontrivial system. There are good reasons to use something like Active Directory and tie systems and applications to it for easier policy enforcement and management. There are good reasons to avoid this centralization for certain things too. Either extreme would be an exercise in frustration.

Re: An update on our security incident

#60
post #55

Earlier quoted context omitted.

Why do we even have 'high value' accounts on a centralized platform? Why isn't there a whitehouse.gov ActivityPub instance that no single admin can censor or subvert?

We will do that now. We will start the competitive bidding process, and we expect the RFP paperwork to be returned by October, 2021. After that, if there are no injunctions filed because of the bidding process, preliminary design documents will start being created. Preliminary design review will occur August 2022. ...

I can’t tell if this is trolling or a serious comment of how this will roll out?
Post reply on HN