Live data from Hacker News

An update on our security incident

blog.twitter.com

211–220 of 245 posts

Re: An update on our security incident

#211
post #199
post #186

> We have zero tolerance for misuse of credentials or tools, actively monitor for misuse, regularly audit permissions, and take immediate action if anyone accesses account information without a valid business reason. Okay, so who has been fired? That's what "zero tolerance" means: no excuses, not even "someone tricked me." And no punishment but the maximum. Anything less would involve some degree of tolerance, and wh…

It’s possible to have zero tolerance and not fire anyone here. My understanding is that no employee misused their credentials or tools. The attackers misused them. I suppose you could argue that accidentally exposing credentials is misusing them, but I don’t think that’s what Twitter means there.

Maybe attackers/phishers are the same people who's accounts were used? Easy bypass.

Re: An update on our security incident

#212
post #186

> We have zero tolerance for misuse of credentials or tools, actively monitor for misuse, regularly audit permissions, and take immediate action if anyone accesses account information without a valid business reason. Okay, so who has been fired? That's what "zero tolerance" means: no excuses, not even "someone tricked me." And no punishment but the maximum. Anything less would involve some degree of tolerance, and wh…

Indeed... one can imagine scenarios were maybe attackers/phishers are the same people who's accounts are being used? This seems like the easiest way to get away with misusing your access. Just send yourself a phishing mail....

Re: An update on our security incident

#213
post #200

Earlier quoted context omitted.

>There is too much focus on entry point of an attack,especially by news media. That depends on what you mean by "entry point". If you define the entry point as a person, then yes don't focus on that. But if you define the entry point as phishable credentials, then focusing on that is good, it will prompt companies to switch to phishing-resistant credentials (U2F security keys).

Even u2f isn't fool proof (exploitation and cookie theft techniques). Execution,privesc,lateral movement are things focus should be on. You can't control the facg that people need to use email and they will for for a phish,but you can control your authentication system, alerting system,etc...

> Even u2f isn't fool proof (exploitation and cookie theft techniques)

What is "Exploitation" standing for here? Exploitation of... what? How and by who?

Re: An update on our security incident

#214
post #39

Earlier quoted context omitted.

How many? A fair number. Not 100%, though. If your system depends on your people 100% not falling for spear phishing, your security is dead.

Well, that’s what I meant when I said that it isn’t a solution. You shouldn’t rely on training, but it’s disingenuous to say it can’t help.

Ah. It seems I was in violent agreement with you.

Re: An update on our security incident

#215
post #186

> We have zero tolerance for misuse of credentials or tools, actively monitor for misuse, regularly audit permissions, and take immediate action if anyone accesses account information without a valid business reason. Okay, so who has been fired? That's what "zero tolerance" means: no excuses, not even "someone tricked me." And no punishment but the maximum. Anything less would involve some degree of tolerance, and wh…

It’s like when motorcyclists say “safety first” about wearing a helmet and other protective gear. If they really put safety first, they’d choose a safer form of transportation. They mean “given that I’m going to engage in this risky activity, I’m going to try to make this activity as safe as possible”. In this case “zero tolerance” is short for something like, “except for understandable slip-ups that aren’t fully you…

I think you can honestly say you follow safety first in terms of what is available to safely ride your bike.

Just like when I used to rock climb, I felt like we were basically following safe practices - but there was no one to adjudicate them, probably far less testing of various practices with stats than bikes. Also, where we climbed there wasn't expected rockfall. I had barely heard of that being an issue, and we never wore helmets. Later on I realized that was something I might have missed out on. And then the next step was "what other safety practices was I unaware of" ;-)

And of course I get that rock climbing is much more dangerous than hiking.

Re: An update on our security incident

#216
post #186

> We have zero tolerance for misuse of credentials or tools, actively monitor for misuse, regularly audit permissions, and take immediate action if anyone accesses account information without a valid business reason. Okay, so who has been fired? That's what "zero tolerance" means: no excuses, not even "someone tricked me." And no punishment but the maximum. Anything less would involve some degree of tolerance, and wh…

'Zero tolerance' doesn't in itself imply anything qualitative about the the actions that are taken as a result of that intolerance.

'Zero tolerance' only means that some action would happen without any subjective application of the rule.

Re: An update on our security incident

#217
post #83

Earlier quoted context omitted.

U2F are safe against simple phishing, but sophisticated attacks can include 2-factor input.

U2F protects against that because the signature is tied to the hostname. The browser reads the hostname. The browser is infallible when it reads the hostname, unlike a human.

In most scenarios a FIDO authenticator (for U2F/ WebAuthn) won't even sign your login attempt for the wrong site at all, because of how it works. We'll look at the original FIDO (second factor only) scenario because that's cheapest and apparently Twitter was very budget conscious on security?

This FIDO authenticator has absolutely no idea what your per-site keys are. Instead, the random-looking ID provided to the site when you register and then given back by the site when logging back in actually is your private key for that site... encrypted using AEAD with symmetric keys only the FIDO authenticator knows.

One of the ingredients for decrypting the key is rpIdHash which is SHA256(dnsName) where dnsName is the FQDN of the site you're looking at or some suffix of that FQDN chosen by the site. So here it could be news.ycombinator.com or ycombinator.com (Public Suffixes like com or co.uk are prohibited). The browser is responsible for calculating rpIdHash.

Thus on a phishing attempt usually the AEAD fails, the authenticator not only doesn't give the phishing site a signature that can be used to sign in on a different site, it will ignore this ID and act as though the user doesn't have a FIDO authenticator plugged in at all.

Re: An update on our security incident

#218

Earlier quoted context omitted.

Yes, I've been involved with such a program before, and it definitely helps a lot. Phishing email click rates go way down. This is carefully planned phone-based spear phishing, though, and that's a lot tougher to protect against. It can be easy for a skilled con artist to gain someone's confidence over the phone, no matter how much you warn about vishing (voice phishing). I'm sure training can still help there, but a…

Same principle can apply though. If email phishing can be simulated and used as training, voice can be added to that training drill. Any successful attack vector can be turned into a training scenario and repeated until better responses are trained into the target group. Military casualty drills are very effective at instilling near instinctive responses... same principle applies.

Absolutely. It's just that highly motivated, targeted, and sophisticated social engineering is really tough to totally prevent. It just takes one person to fall for it, and the attackers can keep cycling through people (quickly, to get ahead of company-wide warnings about the social engineering attempts) until they succeed.

Re: An update on our security incident

#219
post #80

Account access is one thing, yes, and a hardware 2FA key can help with that. But - what is the reason to allow support personnel to pose as specific users and send tweets from their accounts? There is more than a security issue here. There is a complete security breakdown.

I don't believe there was a tool allowing support personnel to pose as users. I believe the tool allows support personnel to reset emails on accounts. Then the attackers used did password resets on the accounts then logged into the accounts and tweeted.

I didn't see that in the page for this article. But, that's a good point.

The specific text is, "Using the credentials of employees with access to these tools, the attackers targeted 130 Twitter accounts, ultimately Tweeting from 45, accessing the DM inbox of 36, and downloading the Twitter Data of 7."

So, this doesn't say what actually happened. If it was employees posing as users in order to post, that is an permission which should not be granted. If it was as you suggest, a password reset, then there is a separate issue with 2fa that would be expected on these accounts.

Either way, there are serious security issue. This is similar to Oracle calling itself "Unbreakable" and then getting broken. If Twitter cannot safeguard against so many accounts getting injected with tweets, then something is broken with Twitter's security model.

Re: An update on our security incident

#220
post #142
post #123

Earlier quoted context omitted.

None of that sounds “ok”... Technical question for you, how does this time tracking work in practice? Do you pause every 6 minutes and note what you’re doing? Or just roughly remember at the end of the hour/day?

That's what time tracking software is made for. No need to pause, "just" remember to switch the software if you change tasks/projects.

It becomes a reflex. Commercial lawyers all do it, tracking time this way is a fact of life, not least because if you end up in court arguing about costs the judge is going to throw out hand-wavy "I spent about a week on this" claims from professional lawyers who should know better.
Post reply on HN