Live data from Hacker News

Tampa teen accused of being ‘mastermind’ behind Twitter hack

wfla.com

401–410 of 702 posts

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#401
post #22

No where in the article it mentions how did they nail him or how did he do. With Twitter saying that this entire process was done by social engineering some employee and then gaining system access of others by monitoring the process - this seems to have been done by someone with Corporate process understanding and hard to believe it could be a 18 yold.

If you are not 100% perfect in your opsec as a wannabe hacker you will get caught. It takes just one small slip-up.

Totally, but opening a bitcoin account with your license driver and moving stolen bitcoins there without any anonymization is another thing altogether.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#402

Earlier quoted context omitted.

Cue the entire movie "Burn after reading." Kid had the whole attention of the world for a few minutes, could've walked away a billionaire, start WW3, casino royale stock trading - everything, anything - CREATIVELY there's so much that could've been done and it all fell down to a bitcoin scam that netted less that 150K (wallet shows about 128k.) That's a yearly salary of a help desk engineer on the west coast. --I'm n…

you cannot start world war 3 or become a billionaire through some tweets, this is not a movie.

I feel like it would have been relatively trivial to make decent 7-9 figures depending on your initial leverage just by manipulating some key accounts. Ie: short Tesla, musks account says solar roof delays, firmware error has started bricking cars, self driving is 10 years away, delivery numbers going to fall well short

Trump (surprised they didn’t hit that) - no new stimulus for unemployed, CORPORATE WELFARE MUST STOP, I WILL NOT BE RESPONSIBLE FOR MASSIVE DEFICITS, then pick a couple small cap companies that are going to receive massive boosts like the Kodak thing.

Tim Cook: Apple sales flagging, iPhone production issues due to supply chain issues

Take a bit of timing to get it right and be able to walk away from the markets relatively untraced (market trade interrogation is a useful way to trace inside information so hard to do in a way that leaves no trace but if you know you can perform your hack at leisure you can set up the initial trades well forward, wait for the market and some other external condition to walk into your ambush and then pounce

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#403
post #399

If this turns out to be true, then we can conclude two things: 1. It's incredible that the security of Twitter allows for a solitary 17-year old to gain full access to (any) account. 2. This also explains why the profit of the hack was 'only' ~$100k. Many speculated about how incredibly valuable such a hack could be and how much more a group could have profited from this hack. Using it for two hours of bitcoin scammi…

People did say things like you could have made a fortune shorting stock by tweeting something insane from Elon Musks account. I don't buy that as necessarily better than a Bitcoin account. Stock transactions are heavily regulated and monitored. You'd leave a pretty large paper trail of any stock manipulation you hoped to profit from. Of course Bitcoin is highly traceable as well, so maybe the lesson is hacking into h…

If they knew up front they would be doing this, they could’ve shorted Tesla in smaller positions, over multiple accounts. There’s tons of people shorting Tesla, would it really be traceable to any of those?

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#404
post #349
post #183

Earlier quoted context omitted.

From memory, I recall the FBI did a study, and found that half of their employees would plug in a USB drive that they found on the ground in the parking lot. After training, that number was reduced to a quarter. If a security-focused government police agency is so vulnerable, it is unreasonable to expect perfection from a (less paranoid) company.

Except this is not expecting perfection, it is expecting a level of security that can prevent children, literal children, from walking right through it. Which would not even be a problem except for the fact that this is far, far less than what Twitter has led their average user and stockholder to believe. To illustrate my point, if Twitter told the truth in big bold print at the top of every page so every user knows:…

One underestimates the capability of determined teenagers at one's peril.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#405
post #349
post #183

Earlier quoted context omitted.

From memory, I recall the FBI did a study, and found that half of their employees would plug in a USB drive that they found on the ground in the parking lot. After training, that number was reduced to a quarter. If a security-focused government police agency is so vulnerable, it is unreasonable to expect perfection from a (less paranoid) company.

Except this is not expecting perfection, it is expecting a level of security that can prevent children, literal children, from walking right through it. Which would not even be a problem except for the fact that this is far, far less than what Twitter has led their average user and stockholder to believe. To illustrate my point, if Twitter told the truth in big bold print at the top of every page so every user knows:…

Exactly. At least one of these kids used their personal gmail account on the hacking forum. These are not advanced hackers.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#406
post #76
post #43

Probably could have earned a lot more from his exploits if he went the formal route and directly confronted Twitter. But then who even knows if Twitter are a good 'first responder' when it comes to high-profile exploits of their system. There was a recent post about some researcher who exposed flaws in Tor's architecture (which allowed third parties to detect Tor traffic easily) and Tor's staff didn't respond; so she…

> It's just unfortunate that the various channels like HackerOne[0] or wherever the skiddies flock to these days are not utilized thoroughly. A lot of the bug bounty programs don't pay as well as using exploits to steal money. Some estimates put this particular breach at having netted upwards of $120k. I don't think I've ever seen a bug bounty that high. The highest I've ever heard of or see documentation describing…

> Some estimates put this particular breach at having netted upwards of $120k.

> I don't think I've ever seen a bug bounty that high. The highest I've ever heard of or see documentation describing is in the range of $40k.

You're not paying attention.

https://www.microsoft.com/en-us/msrc/bounty-hyper-v?rtc=1

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#407
post #46

Earlier quoted context omitted.

does hackerone cover social engineering exploits? I doubt it.

They should. You should get $200 if you can get an employee's password.

> You should get $200 if you can get an employee's password.

That's never going to fly; all Twitter bounties are multiples of $140.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#408
post #275
post #183

Earlier quoted context omitted.

From memory, I recall the FBI did a study, and found that half of their employees would plug in a USB drive that they found on the ground in the parking lot. After training, that number was reduced to a quarter. If a security-focused government police agency is so vulnerable, it is unreasonable to expect perfection from a (less paranoid) company.

Security training improves security but it doesn't get close to stopping 100% of attacks. I know it's obvious, but it feels like it's only obvious to those that think about security. It's the same reason that putting your developers through a yearly OWASP Top 10 secure coding course isn't going to get you to 100% secure code. Locking down systems seems draconian, but it's the only way: - Disabling USB storage - Movin…

in a remote only or remote first working environment, many of these policies are not feasible , ultimately employees have to be able work somewhat productively .

Such clean room requirements could perhaps work when the threat model include nation state actors or your are handling sensitive financial applications.

Most companies are not defence contractors or banks the security levels you propose won’t be worth the cost to a typical internet tech company .

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#409
post #243
post #183

Earlier quoted context omitted.

From memory, I recall the FBI did a study, and found that half of their employees would plug in a USB drive that they found on the ground in the parking lot. After training, that number was reduced to a quarter. If a security-focused government police agency is so vulnerable, it is unreasonable to expect perfection from a (less paranoid) company.

I remember an article a few years ago saying that large % of office employees would trade their password for chocolate. Ah yes here we go, large scale study, 43% of participants gave away their password when bribed with a chocolate bar. People just don't realize how valuable passwords are. https://www.sciencedaily.com/releases/2016/05/160512085123.h...

> If the chocolate was only given out afterwards, 29.8 per cent of participants revealed their passwords.

Nearly 30% of people just gave out their password and didn't even know they were getting chocolate! They gave it away for literally nothing.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#410
post #76

Earlier quoted context omitted.

> It's just unfortunate that the various channels like HackerOne[0] or wherever the skiddies flock to these days are not utilized thoroughly. A lot of the bug bounty programs don't pay as well as using exploits to steal money. Some estimates put this particular breach at having netted upwards of $120k. I don't think I've ever seen a bug bounty that high. The highest I've ever heard of or see documentation describing…

> Some estimates put this particular breach at having netted upwards of $120k. > I don't think I've ever seen a bug bounty that high. The highest I've ever heard of or see documentation describing is in the range of $40k. You're not paying attention. https://www.microsoft.com/en-us/msrc/bounty-hyper-v?rtc=1

Thank you! That's absolutely amazing reading.

Have any of those $250k bounties been paid out? The $40k figure was something I found from a bounty that's actually been paid, rather than a hypothetical one.

Post reply on HN