Live data from Hacker News

An update on our security incident

blog.twitter.com

171–180 of 245 posts

Re: An update on our security incident

#171
post #67
post #12

Freaking Twitter needs a serious auth infra upgrade. Unless phishers hijacked employee devices, they accessed the tools remotely, meaning there's no form of client authentication?? Something like U2F which by now is pretty old seems like it would prevent this kind of attack

what if.. they used the authentication? But yes u2f/webauthn would probably prevent this. That said keep in mind they also do PR/damage control so we only know what they tell us. For all we know maybe they have u2f and an employee still did bad stuff while a phone was somehow involved. Or whatever else.

Yes they gained working credentials from an internal slack channel by reading them in plaintext.

https://www.dailymail.co.uk/news/article-8536603/British-tee...

Re: An update on our security incident

#173
post #81
post #40

As someone who works to stop these, the most frustrating part is how even infosec people thik enough training or $vendor's email security solution will stop this. It's like boy scouts that think they will stop navy seals. There is too much focus on entry point of an attack,especially by news media.

What infosec people think $vendor email security solutions are going to solve phishing attacks? I was under the impression that the people that buy those solutions (like many security solutions) are primarily non-infosec people that want to paper over their real problem without fixing it. Granted, there is a place for some of these things temporarily while working to fix the actual problem, but that's a mitigation, n…

FWIW email security training is something you'll probably be forced to provide, to some degree, as a matter of compliance. It's another case of compliance wasting time by driving companies to do security work that isn't meaningful.

Re: An update on our security incident

#174

What I find most problematic about the attac is the incident response by Twitter. As people pointed out here, hijacking Twitter accounts can lead to big stock market crashes, mass panics ("bomb found at XXX") and maybe even military escalations. Under this circumstances, leaving a platform with an unknown number of compromised accounts online, seems irresponsible to me. In such a case you must stop the bleeding ASAP,…

At the same time, it's hard to take down a site that has the type of impact that you're referring to.

Re: An update on our security incident

#175
post #150

> the attackers targeted 130 Twitter accounts, ultimately Tweeting from 45, accessing the DM inbox of 36, and downloading the Twitter Data of 7 So much effort for so little gain... With proper preparation (i.e. a simple app ready to download everything from an account), they could have made out with the whole data of 130 accounts, silently, before tweeting the hopeless scam message. Instead, this seems like a mostly-…

I imagine that the limited damage the attackers did will help them evade being caught. Ultimately, they just stole some 100k$ in Bitcoin and that's it, so investigations by the FBI et al. will probably not go to great lengths to locate the hackers. On the other hand, attempts to blackmail someone like Tim Cook or Elon Musk would probably be riskier. For the same reason, I suspect the attackers may have intentionally…

In the great scheme of things, knowing what Trump (or any other US politician) says to other people is worth relatively little.

Having insider knowledge of what certain billionaires say to whom, though, can be immensely valuable. It might well be that a few of them will lit a fire under FBI and friends. We'll see.

Re: An update on our security incident

#176
post #19

Earlier quoted context omitted.

Why are internal employee tools publically accessible? Minimum they should require VPN access, but really go further with Zero Trust.

What if the attackers phish the VPN credentials too? Does Zero Trust imply phishing-resistant credentials? What Twitter needed was phishing-resistant credentials (security keys, aka U2F).

Zero Trust != VPN. Zero Trust means that the network is not what determines trust.

Consider this: * You go to your office, connect to the network * Now you have access to internal services, by virtue of being on the network

In a Zero Trust network it does not matter what network you are on. Trust is handed out individually, based on the identity/ role of the user and the context of their session (is their os patched? running security tools?).

Re: An update on our security incident

#177
post #175

Earlier quoted context omitted.

I imagine that the limited damage the attackers did will help them evade being caught. Ultimately, they just stole some 100k$ in Bitcoin and that's it, so investigations by the FBI et al. will probably not go to great lengths to locate the hackers. On the other hand, attempts to blackmail someone like Tim Cook or Elon Musk would probably be riskier. For the same reason, I suspect the attackers may have intentionally…

In the great scheme of things, knowing what Trump (or any other US politician) says to other people is worth relatively little. Having insider knowledge of what certain billionaires say to whom, though, can be immensely valuable. It might well be that a few of them will lit a fire under FBI and friends. We'll see.

Most of those famous people don't manage their own accounts though. Some do, like Musk. That's why I'd consider stealing his DMs to be more dangerous than running a Bitcoin scam - it could easily upset Musk enough that he bugs the FBI to investigate seriously or, more likely, uses his own considerable resources to run an investigation. See how Bezos hired investigators when his data was leaked, and they did get to the bottom of it.

Trump is a bit of a special case because he's POTUS. I'm pretty sure there are no remotely interesting DMs on his account, but if there's one thing the US doesn't like, it's anyone even perceived of messing with national security. An attacker merely logging into Trump's account could be seen as a national security issue, and attract an entirely different level of law enforcement attention.

Re: An update on our security incident

#178
post #61

Earlier quoted context omitted.

And as a Norwegian it boggles my mind that banks in the US only require username and password to access their bank. We have moved on to a authenticator living on a phone sim card, and you use either that or a "real" hardware dongle for all logins and (most) transactions to confirm your identity.

US banks do commonly use SMS messages as a second factor, for what it's worth.

> SMS messages as a second factor, for what it's worth

Almost nothing :(

Re: An update on our security incident

#179

> We’re acutely aware of our responsibilities to the people who use our service and to society more generally. We’re embarrassed, we’re disappointed, and more than anything, we’re sorry. We know that we must work to regain your trust, and we will support all efforts to bring the perpetrators to justice. We hope that our openness and transparency throughout this process, and the steps and work we will take to safeguar…

I think it's a mistake to personify organisations like this.

Agree. That reads like pure PR-corporatespeak to me - oops sorry, wont happen again, business as usual.

“They” only “care” to the extent it materially affects the business.

Post reply on HN