Live data from Hacker News

An update on our security incident

blog.twitter.com

131–140 of 308 posts

Re: An update on our security incident

#131

Earlier quoted context omitted.

Twitter is not an average company. As one of the top 40 internet companies, they are in the position of setting industry standards. I think it's fair to expect more than what the average company does from Twitter.

For security internally, sure. Mandating that every one of your customers has a Yubikey is somewhat trickier to do in practice, and a nightmare to manage the logistics around lost keys. I personally have 3 Yubikeys, one on my keyring, one in my small first aid kit (which is kept in my backpack and usually close to me) and one that doesn't ever travel with me. We give our staff yubikeys and require them to use them fo…

> Mandating that every one of your customers has a Yubikey is somewhat trickier to do in practice, and a nightmare to manage the logistics around lost keys.

Mandating that everyone that has access to your admin console has a U2F key, on the other hand, seems like a perfectly reasonable expectation for a company of Twitter's stature.

Re: An update on our security incident

#132
post #117

Earlier quoted context omitted.

This is by far the most eyebrow-raising part of the update. To take over such a large number of verified accounts and then run a download on only eight non-verified ones seems almost impossible to have been anything other than targeted. The original idea that the bitcoin scam was a diversion starts to look more plausible in this light, but in the absence of any information about the downloaded accounts, there’s reall…

The idea that someone would opt out of downloading Elon masks or Jeff bezos’ DMs is insane. Completely and perfectly insane. Not to mention the other people. Even if just in terms of profit, clearly the dms of the richest man in the world have enough value to just click download. It seems like the probability of this guy passing it up due to lack of interest is very small. Slightly more likely is that he was overwhel…

Where do you think you will find more info -- the DMs of a PR account or the someone's private alt? Or the DMs of a twitter celebrity or the DMs of a hedge fund manager or member of the board of directors of a bank?

Re: An update on our security incident

#134
post #33

I will use this as an ugly reminder that it's better to assume that any DMs could be public at any moment. I don't subscribe to the "nothing to fear, if you have nothing to hide", I had conversations that are not illegal, lewd or even non-politically correct jokes, but would still hate to made public by a 3rd entity; from secrets that were shared by friends, to sensitive data like addresses, or information with clien…

If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him.

Re: An update on our security incident

#135
post #81

Earlier quoted context omitted.

I don't mean this in any kind of condescending way, but I honestly think you might be in a bubble. If I was only looking at my immediate friend group, I would think the same way, as none of them use Twitter DMs at all . However, I recently met up with some old acquaintances from high school, and they use Twitter DMs and Instagram DMs as one of their main methods of communication. There's a reason "slide into the DMs"…

Yes, introductions get made on Twitter, "slide into the DMs" does not mean that you're trying to conduct a three year romantic relationship on it. Usually people are going to get off it, and onto a real messenger application, even if they just want sex.

I communicate with (counts) 4 people regular over Instagram DM. These are people I know IRL, people I have other means of messaging. For me, and from what I can tell some of my friends as well, I’m constantly switching between messaging apps for even the same person. If JS posted an Instagram story and I want to talk about it, then I just start the conversation in Instagram and this turns into a continuation of our conversation elsewhere. If I want to ask someone if they want to get food my first instinct is to open Messages/SMS but if I’ve recently (like same day) chatted with them over Facebook Messenger then I just open that app instead. I couldn’t give a damn which app I use because it’s all the same to me.

Edit: The person I would consider my “best friend” we chat 100% over Instagram DM. This is a person that I can invite myself over for dinner to, that’s how close we are in case you feel like assuming we must not be good friends if we don’t just call each other or whatever. Another of my good friends, we switch between iMessages and WhatsApp I’d say 50/50, just depending on if I’m already in WhatsApp talking to someone else and decide to message her too or not.

Re: An update on our security incident

#136
post #106

Earlier quoted context omitted.

As long as they’re continually bumping the work factor it should be good for now.

If passwords are peppered as well as salted, is the bcrypt work factor a factor?

When the pepper is compromised, the work factor still matters.

Re: An update on our security incident

#137
post #127
post #109

We need the guys at CMU (who also operate CERT) to engineer a replacement and setup a program for interns to operate it as a private non-profit for the rest of time. The system that is out there now has been a running technological joke since it was (sort of) running on Windows and it would be My_ dust now if it weren't for the President who they now (rightly or wrongly) scorn. Some seriously bad things can (and prob…

Could you provide more context?

Did hackers download DIRECT MESSAGES from some Twitter accounts, something that should not be possible were the system correctly engineered and professionally operated?

Would it be naive to expect that this is the first time this mechanism has been used just because it is new to the Public?

If this mechanism has been used before, would it not be safe to assume that sponsors with virtually unlimited resources (such as foreign states) would have employed it to spy on their adversaries?

Would it be logical to conclude that the consequences of such adversaries having their DIRECT MESSAGES revealed resulted in personal injury and loss to those individuals and their associated social graph?

Wasn't Twitter a system setup by some beach bums using a bunch of old buggy Windows systems that barely worked and although it has been reengineered, isn't that same group still calling the shots (only now amplified ten orders of magnitude by additional funding)?

Shouldn't there be a better system, setup and operated by the best software engineers (like those at CMU) available to the Public along with a clear indication of why? --You know, before anyone else realizes personal injury or loss due to the actions of distracted beach bums calling the shots on the current system?

Re: An update on our security incident

#138
post #9

> did the attackers see any of my private information? For the vast majority of people, we believe the answer is, no. This is such a weasel-y answer. “Yes, most of Earth’s population was not affected by this breach” - sure, but those that were affected, how would you be certain that they didn’t have their private information, such as DMs, pulled?

That's kind of a cynical take. I parsed that statement as saying: > did the attackers see any of my private information? For the vast majority of people [who we previously mentioned were affected by this hack], we believe the answer is, no.

> That's kind of a cynical take.

Disagree. The statement could be parsed more applicably as saying:

> The most important question for people who use Twitter is likely — did the attackers see any of my private information? For the vast majority of people [who use Twitter], we believe the answer is, no.

Re: An update on our security incident

#139
post #76
post #63

Earlier quoted context omitted.

very poorly is a bit much. Yes yubikey would be much better, but its not exactly standard across the industry yet. For something to reflect very poorly on twitter opsec, I would expect it to be something that is below what the average tech company was doing. e.g. There was some news article claiming [Without a whole lot of evidence] that the compromised tool used a shared password that was posted as the topic of a sl…

Google has made it a requirement to use hardware keys internally since early 2017 and has noted there have been zero successful phishing attempts since. Twitter would have done the same if they had competent security staff.

> competent security staff

Between this breach, the hacking of Jack Dorsey, the “rogue employee” account deactivation of Donald Trump, and I’m sure more that I’m not aware of, would any reasonable IT/security person claim that Twitter takes security seriously?

I believe I’m quite right in saying that Twitter as a platform has been one of the most damaging things to happen to our democracy in recent history. Its toxic effects on discourse and polarization are well documented.

With that, and the revelation that they couldn’t take security less seriously if they tried, I would implore all reading to delete their Twitter accounts.

Post reply on HN