Earlier quoted context omitted.
Note that not all hardware security devices are safe. U2F security devices are safe against phishing; OTP security devices are not safe against phishing.
U2F are safe against simple phishing, but sophisticated attacks can include 2-factor input.
An update on our security incident
121–130 of 245 posts
Re: An update on our security incident
#122Earlier quoted context omitted.
Google requires its employees to use a security key for access to all internal systems including admin tools, source code and email. Every since google started enforcing this policy the number of successful phishing attacks has gone down to basically zero.
I believe the Twitter attack involved tricking a user into installing proxy software on their machine (to be in twitter's internal network). If that is the case, that same proxy software could proxy the security key requests too.
Re: An update on our security incident
#123Earlier quoted context omitted.
It's a comment on government inefficiency.
Seriously I worked on projects subject to government scrutiny and it was ok, but you had to be the right kind of person. Account for your time in 6-minute increments. Milestones I recall off the top of my head were preliminary design, detailed design, 3-5% of your time coding, software integration, hardware software integration, acceptance. It was stable, predictable, and (to me) very soul-crushing.
Technical question for you, how does this time tracking work in practice? Do you pause every 6 minutes and note what you’re doing? Or just roughly remember at the end of the hour/day?
Re: An update on our security incident
#124Earlier quoted context omitted.
No disrespect to those challenged with protecting such a huge target, but why do admin tools even have these capabilities? I could see needing to disable a user account or change some attributes, but why would an admin ever need to tweet from it? There shouldn't be tools with God privileges even for admins. Not surprising human error was involved in a breach this huge. So, how many people had access to this tool? Is…
You have a need for a tool allows you to see the UI “as the user does” so you can respond to support requests and maybe someone thinks it’s easier to just copy the cookie. This isn’t the right way to do it, but given they work at Twitter I could imagine this isn’t the first big mistake they’ve made.
Re: An update on our security incident
#125Earlier quoted context omitted.
Were the spear fishing attacked also used to get 2FA, or did these accounts not have 2FA? Would hardware based 2FA not have stopped this?
It says right there in the linked page that the phishing attack was able to manipulate multiple employees into giving access past their 2FA.
Re: An update on our security incident
#126Earlier quoted context omitted.
Were the spear fishing attacked also used to get 2FA, or did these accounts not have 2FA? Would hardware based 2FA not have stopped this?
Maybe? I imagine a spear fishing attack could entail the target is sent to a false panel to login where it sends a true 2FA request. The target then freely gives this 2FA code to the attacker.
Re: An update on our security incident
#127What I find most problematic about the attac is the incident response by Twitter. As people pointed out here, hijacking Twitter accounts can lead to big stock market crashes, mass panics ("bomb found at XXX") and maybe even military escalations. Under this circumstances, leaving a platform with an unknown number of compromised accounts online, seems irresponsible to me. In such a case you must stop the bleeding ASAP,…
This was good. I hope it keeps happening.
Re: An update on our security incident
#128Earlier quoted context omitted.
No disrespect to those challenged with protecting such a huge target, but why do admin tools even have these capabilities? I could see needing to disable a user account or change some attributes, but why would an admin ever need to tweet from it? There shouldn't be tools with God privileges even for admins. Not surprising human error was involved in a breach this huge. So, how many people had access to this tool? Is…
The admin tool was used to change the email on an account, then the attacker reset the password and got full access to the account. Apparently having 2FA enabled did not stop this attack (admin tool probably had the power to strip 2FA from accounts). So while the tool did not directly have the ability to tweet, it effectively did.
Re: An update on our security incident
#129> We’re acutely aware of our responsibilities to the people who use our service and to society more generally. We’re embarrassed, we’re disappointed, and more than anything, we’re sorry. We know that we must work to regain your trust, and we will support all efforts to bring the perpetrators to justice. We hope that our openness and transparency throughout this process, and the steps and work we will take to safeguar…
Re: An update on our security incident
#130As someone who works to stop these, the most frustrating part is how even infosec people thik enough training or $vendor's email security solution will stop this. It's like boy scouts that think they will stop navy seals. There is too much focus on entry point of an attack,especially by news media.
Speaking from experience at a major infosec company, the impression I got internally was "we offer phishing tests, but we don't recommend them, because phishing succeeds 100% of the time". So I'm confused by the idea "even infosec people think training will stop this".
As-is the grammar is ambiguous whether badrabbit meant "some" or "all".