Live data from Hacker News

Tampa teen accused of being ‘mastermind’ behind Twitter hack

wfla.com

411–420 of 702 posts

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#411
post #295

Earlier quoted context omitted.

In "2020 Commission Report" by Jeffrey Lewis, North Korea nukes the US because of one twit. This looks very plausible to me.

Are you arguing against something I've said? Because if so I don't understand what or how.

I'm arguing that Twitter is now critical infrastructure, like banking or power grid, and needs to take security seriously. If they don't do it themselves, they'll get regulation like HIPAA.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#412
post #286

Earlier quoted context omitted.

Bitcoin transactions take place between addresses, which are hashes of public keys. It's actually better to call bitcoin "pseudonymous", since the addresses are pseudonyms that may or may not be tied to an irl identity. So if you, a hacker, tell someone to submit Bitcoin to an address, that address is only really "anonymous" until you use your private keys to reroute the money to other addresses. As soon as the graph…

> It's very silly to try to cash in on ill-gotten bitcoin... What's the alternative? Sit on the coins or use them for purchases?

Launder them.

Possibilities are endless. Coolest thing I heard was use the bitcoin to rent bitcoin miners. Then spend the resultant cleanly mined coins.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#413

Numerous sources covering this: At NYTimes, from another submission: https://www.nytimes.com/2020/07/31/technology/twitter-hack-a... Reuters: https://www.reuters.com/article/us-twitter-cyber/florida-tee...

also the DOJ release and complaints: https://news.ycombinator.com/item?id=24012968

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#414
post #399

Earlier quoted context omitted.

People did say things like you could have made a fortune shorting stock by tweeting something insane from Elon Musks account. I don't buy that as necessarily better than a Bitcoin account. Stock transactions are heavily regulated and monitored. You'd leave a pretty large paper trail of any stock manipulation you hoped to profit from. Of course Bitcoin is highly traceable as well, so maybe the lesson is hacking into h…

If they knew up front they would be doing this, they could’ve shorted Tesla in smaller positions, over multiple accounts. There’s tons of people shorting Tesla, would it really be traceable to any of those?

Yes, because the SEC isn't stupid, and would trawl through the data, until they found:

* A set of freshly opened accounts.

* That only shorted a single stock.

* Right before a major hack.

* That cashed out all at once.

* That never traded again.

And then they'd start calling the owners of those accounts, and asking questions. Most of those accounts would be legitimate traders, but that's fine - there's not that many accounts that satisfy four of those five criteria. A few sql queries can narrow it down to the point that basic detective work can solve the rest.

The problem with playing stupid games on the stock market is that there's a very clear paper trail that will link you, as a human being, to the money that you're hoping to make. At least with bitcoin, you can theoretically isolate yourself from the source of the funds, through tumblers, transferring money in and out of shady exchanges, etc.

This is also exactly how the SEC catches insider-traders. By analyzing the flow of trades, and following up on suspicious ones. If the first and only trade you've ever done in your life is a $200,000 short[1] on your employer twenty minutes before a disastrous earnings, you might soon be talking to a very nicely dressed man who would love to get another conviction under his belt.

[1] If you think you're playing 34-d chess, and have done a bunch of other options trades surrounding it, to disguise it, you're just as likely to piss away all of your money before you even get a chance to insider-trade. That's the beauty of options - they will part a fool from their money before they can spit.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#415

I personally lost $6000 dollars, is there any way I could prove that I was a victim and get my crypto back?

I don’t mean to be rude, but I have to ask - what were you thinking?

In EVE online, many doubling scams would actually pay out the first few times. This to encourage others to commit bigger sums. Hence, if you 'get in early' it might be worth it to try and get your money doubled.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#416

I personally lost $6000 dollars, is there any way I could prove that I was a victim and get my crypto back?

I thought Bitcoin's biggest feature was No Chargebacks

No central party can issue chargebacks. But if the FBI got the funds, they can just send the funds back.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#417
post #322
post #17

Interesting to see that he's being charged in Florida, instead of federally. I mean yes, normally, when one commits a crime in a particular area, they're charged in that area. But my understanding is that once stuff crosses state lines, it becomes a federal issue, and this is part of why its usually the FBI that comes knocking.

Anything involving a computer connected to the internet (even firewalled or rarely connected) is considered to be a "protected computer" since it is involved in interstate commerce or communication and thus open to federal charges under 1030 (a).

Exactly. Thus why I am somewhat surprised to see that he's being charged in Florida. By the letter of the law, this is an issue for the feds to handle.

Edit: Another post on HN[1] covers the federal charges. So, it sounds like this kid is being charged by both the state and the feds. I don't envy him.

1. https://news.ycombinator.com/item?id=24012968

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#418
post #349
post #183

Earlier quoted context omitted.

From memory, I recall the FBI did a study, and found that half of their employees would plug in a USB drive that they found on the ground in the parking lot. After training, that number was reduced to a quarter. If a security-focused government police agency is so vulnerable, it is unreasonable to expect perfection from a (less paranoid) company.

Except this is not expecting perfection, it is expecting a level of security that can prevent children, literal children, from walking right through it. Which would not even be a problem except for the fact that this is far, far less than what Twitter has led their average user and stockholder to believe. To illustrate my point, if Twitter told the truth in big bold print at the top of every page so every user knows:…

> expecting a level of security that can prevent children, literal children, from walking right through it

Well, that's your problem.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#419
post #243
post #183

Earlier quoted context omitted.

From memory, I recall the FBI did a study, and found that half of their employees would plug in a USB drive that they found on the ground in the parking lot. After training, that number was reduced to a quarter. If a security-focused government police agency is so vulnerable, it is unreasonable to expect perfection from a (less paranoid) company.

I remember an article a few years ago saying that large % of office employees would trade their password for chocolate. Ah yes here we go, large scale study, 43% of participants gave away their password when bribed with a chocolate bar. People just don't realize how valuable passwords are. https://www.sciencedaily.com/releases/2016/05/160512085123.h...

the study says 29% gave the password without chocolate as well .

Some where given chocolate before and after , nowhere it says chocolate was offered as payment for sharing the password. Small gifts could have been inducement to establish relationship and trust not the same as a bribe as you characterises it

I find it hard to believe 25 /40 % plus people readily share their password to total strangers , without knowing more details it seems unrealistic

Social engineering is still a problem but am not sure bribes are the real concern . And to insinuate the cost of bribing is as low as candy for significant chunk of the population is just wrong

Post reply on HN