Live data from Hacker News

An update on our security incident

blog.twitter.com

201–210 of 245 posts

Re: An update on our security incident

#201
post #58
post #50

Earlier quoted context omitted.

I work for a crypto currency company and it was the first time in my career that I was issued a YubiKey (I once had an RSA 2fa token for vpn access). It took some getting used to but now I just keep in on my keychain and I always have it with me. I need it for SSO, git, VPN, and basically all internal services. They aren't sufficient by themselves however, they don't protect from is malicious internal employees.

Preparing for malicious internal employees seems to me like preparing for "the big one," in the northwest. Do a cursory amount of preparation. Outside of basic measures, you're probably doing more harm to the business than good. The likelihood of internal malicious attackers is very low in the grand scheme of things, and the attack surface is huge. Most companies are going to be compromised by outside attackers—its t…

The annual DBIR, which collects incident reports, has ~1/3rd marked as insider ;-)

From a defense-in-depth perspective, agreed: most attacks involve privelege escalation on the inside as soon as they switch from attack vector to breach, even if just host-level, so teams should absolutely "assume breach". Attackers will phish folks, get on their devices, get root, and then have fun there and potentially elsewhere. Ransomware is a more common goal than what Twitter got hit with as it is easily profitable, and it means a takeover. Controls on what most users can do and the ability to scope & report is part of growing up (in the US). It's good Twitter was able to map the attack - I bet many popular social networks couldn't, esp outside of the US or non-top-10.

Shameless plug: A lot of folks use our tool for mapping network logs, and I always encourage to also map out host / app / cloud logs as well, such as logins and the oftentimes black hole that is winlogs.

Re: An update on our security incident

#202
post #2

No employee should have the power to subvert 130 high value accounts in a short time period.

Why do we even have 'high value' accounts on a centralized platform? Why isn't there a whitehouse.gov ActivityPub instance that no single admin can censor or subvert?

> Why isn't there a whitehouse.gov ActivityPub instance that no single admin can censor or subvert?

Legislation is sorely needed for public institutions to make public announcement messages (microblog posts, or "tweets") using publicly managed and controlled infrastructure, contributing back to the commons[1].

Stop building into broken commercial services, the standards exist today to rebuild a commons-oriented Internet.

[1] https://en.wikipedia.org/wiki/Commons#Digital_commons

Re: An update on our security incident

#204
post #186

> We have zero tolerance for misuse of credentials or tools, actively monitor for misuse, regularly audit permissions, and take immediate action if anyone accesses account information without a valid business reason. Okay, so who has been fired? That's what "zero tolerance" means: no excuses, not even "someone tricked me." And no punishment but the maximum. Anything less would involve some degree of tolerance, and wh…

I don't really trust Twitter at all. When you consider how they shape public opinion on so many things, it gets scary.

They have been caught banning people based on their political stances, and refuse to remove the algorithmic timeline sorting method which is designed to strip adolescents (and easily persuaded adults) of their critical thinking skills.

Re: An update on our security incident

#205

Earlier quoted context omitted.

Why do we even have 'high value' accounts on a centralized platform? Why isn't there a whitehouse.gov ActivityPub instance that no single admin can censor or subvert?

Because the general public has no clue what ActivityPub is or the desire to learn how to consume feeds from dozen of instances when they could just download a single app onto their smartphone where all the celebrities already are.

> general public has no clue what ActivityPub is

The general public doesn't need to know anything about the underlying standards.

Does a salesperson care about how SMTP works in order to send and receive emails from their customers?

Re: An update on our security incident

#207
post #186

> We have zero tolerance for misuse of credentials or tools, actively monitor for misuse, regularly audit permissions, and take immediate action if anyone accesses account information without a valid business reason. Okay, so who has been fired? That's what "zero tolerance" means: no excuses, not even "someone tricked me." And no punishment but the maximum. Anything less would involve some degree of tolerance, and wh…

>That's what "zero tolerance" means: no excuses, not even "someone tricked me." That doesn't necessarily follow, as it depends on exactly what they have zero tolerance for. They say they have zero tolerance for "misuse of credentials." Misuse conceivably may not include insecure storage of credentials or accidentally exposing them, but only actively using them, eg logging in and using them for an inappropriate purpose.

I'm not trying to split hairs or be a Twitter apologist here but there is a meaningful distinction here. Intentional misuse of credentials is ultimately subordination (which is immediately fireable in most situations), whereas accidental exposure is a mistake. Twitter is effectively reinforcing that employees are forbidden to puruse private data. They are not making the point that they will fire anyone accidentally involved in a security breach.

Re: An update on our security incident

#208
Social engineering will never be stopped, people want to be helpful. And generally speaking the cost for stopping it at non-secure businesses is going to be too high until a security incident happens.

Phishing email attacks? Why do employees have business emails at all?

Phishing phone attacks? Why would employees have phones with external access?

Front of the house (dealing with users) should probably be disconnected from back the of the house (admin access).

Before you know it you're in DoD or Bank territory. No Wifi allowed etc, where's your badge buddy?!

Things get complex quickly with security.

Re: An update on our security incident

#209

Social engineering will never be stopped, people want to be helpful. And generally speaking the cost for stopping it at non-secure businesses is going to be too high until a security incident happens. Phishing email attacks? Why do employees have business emails at all? Phishing phone attacks? Why would employees have phones with external access? Front of the house (dealing with users) should probably be disconnected…

> Social engineering will never be stopped, people want to be helpful.

They really do. And so you should design security systems with the assumption that your employees will actively undermine security "to be helpful" to adversaries.

> And generally speaking the cost for stopping it at non-secure businesses is going to be too high until a security incident happens.

The cost for Yubico's "Security Key" is $20 and there is a volume discount. You should buy each employee a key, and if there's no secure means by which they can be re-authorised when they inevitably lose it, a second one to keep safely for that case.

The attackers correctly anticipated that while "Can you get me Jenny in user assistance's phone number?" is just being helpful, "Can you disable Elon Musk's 2FA and give me control over his account?" is a bit... obvious. So they got themselves credentials to do that stuff. But there is no need for Twitter employees to be able to give away those credentials.

Re: An update on our security incident

#210
post #186

> We have zero tolerance for misuse of credentials or tools, actively monitor for misuse, regularly audit permissions, and take immediate action if anyone accesses account information without a valid business reason. Okay, so who has been fired? That's what "zero tolerance" means: no excuses, not even "someone tricked me." And no punishment but the maximum. Anything less would involve some degree of tolerance, and wh…

Intent matters here. They ultimately fell prey to social engineering, they didn't give out their credentials or do this themselves.
Post reply on HN