Live data from Hacker News

An update on our security incident

blog.twitter.com

121–130 of 245 posts

Re: An update on our security incident

#121
post #83
post #21

Earlier quoted context omitted.

Note that not all hardware security devices are safe. U2F security devices are safe against phishing; OTP security devices are not safe against phishing.

U2F are safe against simple phishing, but sophisticated attacks can include 2-factor input.

U2F protects against that because the signature is tied to the hostname. The browser reads the hostname. The browser is infallible when it reads the hostname, unlike a human.

Re: An update on our security incident

#122
post #84

Earlier quoted context omitted.

Google requires its employees to use a security key for access to all internal systems including admin tools, source code and email. Every since google started enforcing this policy the number of successful phishing attacks has gone down to basically zero.

I believe the Twitter attack involved tricking a user into installing proxy software on their machine (to be in twitter's internal network). If that is the case, that same proxy software could proxy the security key requests too.

If there's malware involved I don't consider that phishing. Although some would debate that.

Re: An update on our security incident

#123
post #116

Earlier quoted context omitted.

It's a comment on government inefficiency.

Seriously I worked on projects subject to government scrutiny and it was ok, but you had to be the right kind of person. Account for your time in 6-minute increments. Milestones I recall off the top of my head were preliminary design, detailed design, 3-5% of your time coding, software integration, hardware software integration, acceptance. It was stable, predictable, and (to me) very soul-crushing.

None of that sounds “ok”...

Technical question for you, how does this time tracking work in practice? Do you pause every 6 minutes and note what you’re doing? Or just roughly remember at the end of the hour/day?

Re: An update on our security incident

#124
post #101
post #89

Earlier quoted context omitted.

No disrespect to those challenged with protecting such a huge target, but why do admin tools even have these capabilities? I could see needing to disable a user account or change some attributes, but why would an admin ever need to tweet from it? There shouldn't be tools with God privileges even for admins. Not surprising human error was involved in a breach this huge. So, how many people had access to this tool? Is…

You have a need for a tool allows you to see the UI “as the user does” so you can respond to support requests and maybe someone thinks it’s easier to just copy the cookie. This isn’t the right way to do it, but given they work at Twitter I could imagine this isn’t the first big mistake they’ve made.

This sounds like speculation. Is there evidence that Twitter has a tool that allows employees to see the UI as the user does?

Re: An update on our security incident

#125

Earlier quoted context omitted.

Were the spear fishing attacked also used to get 2FA, or did these accounts not have 2FA? Would hardware based 2FA not have stopped this?

It says right there in the linked page that the phishing attack was able to manipulate multiple employees into giving access past their 2FA.

Yeah, that answers 1 of the questions. But we still don't know what type of 2FA was being used, or what technique the attackers used.

Re: An update on our security incident

#126

Earlier quoted context omitted.

Were the spear fishing attacked also used to get 2FA, or did these accounts not have 2FA? Would hardware based 2FA not have stopped this?

Maybe? I imagine a spear fishing attack could entail the target is sent to a false panel to login where it sends a true 2FA request. The target then freely gives this 2FA code to the attacker.

That compromise OTP 2FA, but not U2F 2FA.

Re: An update on our security incident

#127

What I find most problematic about the attac is the incident response by Twitter. As people pointed out here, hijacking Twitter accounts can lead to big stock market crashes, mass panics ("bomb found at XXX") and maybe even military escalations. Under this circumstances, leaving a platform with an unknown number of compromised accounts online, seems irresponsible to me. In such a case you must stop the bleeding ASAP,…

No. We need more things like these to happen so people lose trust on everything they read on the stupid internet.

This was good. I hope it keeps happening.

Re: An update on our security incident

#128
post #89

Earlier quoted context omitted.

No disrespect to those challenged with protecting such a huge target, but why do admin tools even have these capabilities? I could see needing to disable a user account or change some attributes, but why would an admin ever need to tweet from it? There shouldn't be tools with God privileges even for admins. Not surprising human error was involved in a breach this huge. So, how many people had access to this tool? Is…

The admin tool was used to change the email on an account, then the attacker reset the password and got full access to the account. Apparently having 2FA enabled did not stop this attack (admin tool probably had the power to strip 2FA from accounts). So while the tool did not directly have the ability to tweet, it effectively did.

I feel like the power to reset emails and remove 2fa should be only held by a very small subset of customer support, with proper training.

Re: An update on our security incident

#129

> We’re acutely aware of our responsibilities to the people who use our service and to society more generally. We’re embarrassed, we’re disappointed, and more than anything, we’re sorry. We know that we must work to regain your trust, and we will support all efforts to bring the perpetrators to justice. We hope that our openness and transparency throughout this process, and the steps and work we will take to safeguar…

I think it's a mistake to personify organisations like this.

Re: An update on our security incident

#130
post #40

As someone who works to stop these, the most frustrating part is how even infosec people thik enough training or $vendor's email security solution will stop this. It's like boy scouts that think they will stop navy seals. There is too much focus on entry point of an attack,especially by news media.

Speaking from experience at a major infosec company, the impression I got internally was "we offer phishing tests, but we don't recommend them, because phishing succeeds 100% of the time". So I'm confused by the idea "even infosec people think training will stop this".

I think badrabbit should have said "even some infosec people think training will stop this".

As-is the grammar is ambiguous whether badrabbit meant "some" or "all".

Post reply on HN