Earlier quoted context omitted.
Dongles are rare here in the US. But I know that bloomberg uses them. I was shocked when I learned that retail banks in Singapore give everyone dongles to log in. In the US that's tyranny Lol
We're talking about companies , not users . Competent companies can and absolutely do require dongles (or equivalently trustable corporate hardware) to log in to their systems.
An update on our security incident
61–70 of 245 posts
Re: An update on our security incident
#62Earlier quoted context omitted.
Rare for employees or rare for consumers? Companies can push much higher security onto employees than onto consumers.
How do they deal with lost dongles?
Re: An update on our security incident
#63Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update... > The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all o…
I'd like to know more about these tools. That there's at least one which can bypass a user's 2FA settings without notification suggests that there are additional tools in the same vein.
Re: An update on our security incident
#64It is inexcusable that Twitter is employing people who are susceptible to social engineering attacks like this. This is simple training and seriousness.
Nobody is perfect.
Everyone is vulnerable given time/effort.
Re: An update on our security incident
#65As someone who works to stop these, the most frustrating part is how even infosec people thik enough training or $vendor's email security solution will stop this. It's like boy scouts that think they will stop navy seals. There is too much focus on entry point of an attack,especially by news media.
Any good literature which you'd recommend to read to avoid something like this?
Re: An update on our security incident
#66Anyone here with any literature / sessions one could go through for a good gist of things with respect to Blast Radius?
Re: An update on our security incident
#67Freaking Twitter needs a serious auth infra upgrade. Unless phishers hijacked employee devices, they accessed the tools remotely, meaning there's no form of client authentication?? Something like U2F which by now is pretty old seems like it would prevent this kind of attack
But yes u2f/webauthn would probably prevent this.
That said keep in mind they also do PR/damage control so we only know what they tell us. For all we know maybe they have u2f and an employee still did bad stuff while a phone was somehow involved. Or whatever else.
Re: An update on our security incident
#68Re: An update on our security incident
#69Earlier quoted context omitted.
AFIK, in a Zero Trust Architecture a VPN is considered a perimeter and therefore it becomes a vector of attack to access systems of authoritative decision. Many security researchers have already established that the benefits of a VPN especially in the modern distributed world are marginal at best. Basically, yes a VPN makes you a tiny bit safer but it also adds a lot of networking complexity and adds more friction to…
> On the other hand if every service you use has its own authentication... This would be a nightmare for the people managing any nontrivial system. There are good reasons to use something like Active Directory and tie systems and applications to it for easier policy enforcement and management. There are good reasons to avoid this centralization for certain things too. Either extreme would be an exercise in frustratio…
I’m not so sure that it works that well once it becomes the actual authentication middleware. But as a single sign on directory it definitely reduces the complexity for the employees and for IT departments.
Either way I think more than systems, people need training. I know there are sophisticated phishing attacks but someone who has been trained to understand and acknowledge these situations should be able to detect when someone is trying to steal information.
I think Twitter’s failure was to not properly train their employees especially when they are such a visible and juicy target for bad actors.
Re: An update on our security incident
#70Earlier quoted context omitted.
We will do that now. We will start the competitive bidding process, and we expect the RFP paperwork to be returned by October, 2021. After that, if there are no injunctions filed because of the bidding process, preliminary design documents will start being created. Preliminary design review will occur August 2022. ...
I can’t tell if this is trolling or a serious comment of how this will roll out?