Live data from Hacker News

An update on our security incident

blog.twitter.com

61–70 of 245 posts

Re: An update on our security incident

#61

Earlier quoted context omitted.

Dongles are rare here in the US. But I know that bloomberg uses them. I was shocked when I learned that retail banks in Singapore give everyone dongles to log in. In the US that's tyranny Lol

We're talking about companies , not users . Competent companies can and absolutely do require dongles (or equivalently trustable corporate hardware) to log in to their systems.

And as a Norwegian it boggles my mind that banks in the US only require username and password to access their bank. We have moved on to a authenticator living on a phone sim card, and you use either that or a "real" hardware dongle for all logins and (most) transactions to confirm your identity.

Re: An update on our security incident

#62
post #28

Earlier quoted context omitted.

Rare for employees or rare for consumers? Companies can push much higher security onto employees than onto consumers.

How do they deal with lost dongles?

Employees can revoke access for any of their keys/dongles once they realize they are missing. The company can also send an automated warning and auto-expire a key that's not been used for a while.

Re: An update on our security incident

#63
post #36
post #5

Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update... > The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all o…

I'd like to know more about these tools. That there's at least one which can bypass a user's 2FA settings without notification suggests that there are additional tools in the same vein.

Every network has to have tools to do that. How else will they enforce the laws they are required to enforce?

Re: An update on our security incident

#64
post #8

It is inexcusable that Twitter is employing people who are susceptible to social engineering attacks like this. This is simple training and seriousness.

You say this like human beings can be perfect.

Nobody is perfect.

Everyone is vulnerable given time/effort.

Re: An update on our security incident

#65
post #40

As someone who works to stop these, the most frustrating part is how even infosec people thik enough training or $vendor's email security solution will stop this. It's like boy scouts that think they will stop navy seals. There is too much focus on entry point of an attack,especially by news media.

Hey,

Any good literature which you'd recommend to read to avoid something like this?

Re: An update on our security incident

#66
Sorry if I am taking this on a tanget, but in one of the HN threads regarding this exact security incident, it was recommended that this is why something called as "Blast Radius" needs to be implemented.

Anyone here with any literature / sessions one could go through for a good gist of things with respect to Blast Radius?

Re: An update on our security incident

#67
post #12

Freaking Twitter needs a serious auth infra upgrade. Unless phishers hijacked employee devices, they accessed the tools remotely, meaning there's no form of client authentication?? Something like U2F which by now is pretty old seems like it would prevent this kind of attack

what if.. they used the authentication?

But yes u2f/webauthn would probably prevent this.

That said keep in mind they also do PR/damage control so we only know what they tell us. For all we know maybe they have u2f and an employee still did bad stuff while a phone was somehow involved. Or whatever else.

Re: An update on our security incident

#69
post #59

Earlier quoted context omitted.

AFIK, in a Zero Trust Architecture a VPN is considered a perimeter and therefore it becomes a vector of attack to access systems of authoritative decision. Many security researchers have already established that the benefits of a VPN especially in the modern distributed world are marginal at best. Basically, yes a VPN makes you a tiny bit safer but it also adds a lot of networking complexity and adds more friction to…

> On the other hand if every service you use has its own authentication... This would be a nightmare for the people managing any nontrivial system. There are good reasons to use something like Active Directory and tie systems and applications to it for easier policy enforcement and management. There are good reasons to avoid this centralization for certain things too. Either extreme would be an exercise in frustratio…

Certainly. That’s why things like Okta make sense. It allows people to use it as a Password Manager while keeping certain level of sanity in managing resources but without giving up individual authentication against services.

I’m not so sure that it works that well once it becomes the actual authentication middleware. But as a single sign on directory it definitely reduces the complexity for the employees and for IT departments.

Either way I think more than systems, people need training. I know there are sophisticated phishing attacks but someone who has been trained to understand and acknowledge these situations should be able to detect when someone is trying to steal information.

I think Twitter’s failure was to not properly train their employees especially when they are such a visible and juicy target for bad actors.

Re: An update on our security incident

#70
post #55

Earlier quoted context omitted.

We will do that now. We will start the competitive bidding process, and we expect the RFP paperwork to be returned by October, 2021. After that, if there are no injunctions filed because of the bidding process, preliminary design documents will start being created. Preliminary design review will occur August 2022. ...

I can’t tell if this is trolling or a serious comment of how this will roll out?

It's a comment on government inefficiency.
Post reply on HN