Live data from Hacker News

An update on our security incident

blog.twitter.com

151–160 of 308 posts

Re: An update on our security incident

#151

Earlier quoted context omitted.

I wonder if it was something like DUO and employees were told to just hit approve. Get employee's password Call employee "Hey [employee], I'm [coworker] from the security team and we noticed your DUO was locked. I just enabled it, but we want to make sure it works. Hit Approve when you get a notification." Log in with password Wait for employee to hit Approve.

That's why you need a phishing-resistant method of 2FA. U2F is phishing resistant. Any type of OTP, or anything that doesn't bind the user action to the url bar is susceptible to phishing. U2F has the computer verify the url bar so it's phishing-resistant.

I just find it ironic that the same people pushing for 2FA and arbitrary password rules are now saying "oh I guess 2FA is phishable"

The best defense against Phishing seems to be to hire competent people and to train them on that and to establish "No You-Know-Who-You're-Talking-To" policies, as if something gets failed to do by whomever that didn't follow security procedures (example: "CEO" asking for "urgent" favour) is not blamed

Re: An update on our security incident

#152

,,We became aware of the attackers’ action on Wednesday, and moved quickly to lock down and regain control of the compromised accounts.'' They don't write about the fact that they let the scam going on for hours destroying lives of people. Locking down the accounts actually helped.the scammers, as the owners of the accounts or other Twitter employees weren't able to delete the scam messages.

> the fact that they let the scam going on for hours destroying lives of people Source?

You can look at the blockchain how much money people lost, and for how long the scam went on. Or you can just read Twitter's announcement: they did nothing to mitigate the scam. I remember being scammed for about $200 when I was a teenager and it was awful. I was ashamed of myself.

Re: An update on our security incident

#153

Earlier quoted context omitted.

I think the average non-technical reader could figure out that "plain text" refers to some variant of "········" rather than "password," even if the understanding is lacking technical depth.

My point was a term such as 'unencrypted' would probably be the word I'd use to explain the concept of a 'plain text' password to a non technical user.

Encrypted implies that the passwords could possibly be decrypted with a key.

Re: An update on our security incident

#154
post #45

Earlier quoted context omitted.

Not really, this document is clearly intended for a general public audience (They define the term "social engineering" after all). I don't think its surprising they didn't go into the details of which algorithms they use on old passwords

They could've just said "...as this is not possible" or something like that. I wasn't suggesting they need to drop in acronyms like PBKDF2 or whatever. They go out of their way to say "through the tools used in the attack" which might as well imply there are other tools through which the passwords are available...

But technically you could try a dictionary-based brute-force attack on a user with a weak password and crack it regardless of the hashing scheme.

Re: An update on our security incident

#156
post #117

Earlier quoted context omitted.

The idea that someone would opt out of downloading Elon masks or Jeff bezos’ DMs is insane. Completely and perfectly insane. Not to mention the other people. Even if just in terms of profit, clearly the dms of the richest man in the world have enough value to just click download. It seems like the probability of this guy passing it up due to lack of interest is very small. Slightly more likely is that he was overwhel…

I'm not sure what you're thinking, but it's perfectly reasonable. People like you're talking about don't communicate anything of value over twitter. Bezos only follows his ex-wife who doesn't follow him back, barely uses twitter and would be unlikely to have any DMs at all. After the saudi hack, I would be surprised if he has much of anything installed on his phone. The only real reason to hack celebrity accounts in…

I always thought high profile accounts are run by media teams. I doubt the account owners know the credentials themselves or have direct access in most cases.

Re: An update on our security incident

#157
post #49

> 2FA compromised This is why sending or generating a OTP, that the user types in, is not secure. The user can be tricked into handing the OTP over the phone. Even the O365 system isn't secure (because the user can be told which number to tap over the phone). The only secure authentication these days is a non-communicable possession: Yubikey or similar. This reflects *very poorly on Twitter opsec.

[deleted]

Re: An update on our security incident

#158

Earlier quoted context omitted.

>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…

I think the hackers were going after OG accounts that were single, two-character, or common first name usernames. Many OG accounts aren’t verified.

But if they were going after OG accounts to resell them, would they really want to cause such a huge fuss that would have Twitter carefully examine the audit trail and undo the hackers' actions?

Re: An update on our security incident

#159
post #117

Earlier quoted context omitted.

The idea that someone would opt out of downloading Elon masks or Jeff bezos’ DMs is insane. Completely and perfectly insane. Not to mention the other people. Even if just in terms of profit, clearly the dms of the richest man in the world have enough value to just click download. It seems like the probability of this guy passing it up due to lack of interest is very small. Slightly more likely is that he was overwhel…

I'm not sure what you're thinking, but it's perfectly reasonable. People like you're talking about don't communicate anything of value over twitter. Bezos only follows his ex-wife who doesn't follow him back, barely uses twitter and would be unlikely to have any DMs at all. After the saudi hack, I would be surprised if he has much of anything installed on his phone. The only real reason to hack celebrity accounts in…

> Bezos only follows his ex-wife who doesn't follow him back

I honestly didn't believe you. But it's true. That's... kinda weird.

Re: An update on our security incident

#160

Earlier quoted context omitted.

>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…

This is by far the most eyebrow-raising part of the update. To take over such a large number of verified accounts and then run a download on only eight non-verified ones seems almost impossible to have been anything other than targeted. The original idea that the bitcoin scam was a diversion starts to look more plausible in this light, but in the absence of any information about the downloaded accounts, there’s reall…

> in the absence of any information about the downloaded accounts, there’s really no way to guess what their value may have been and to whom

One possibility I can think of is that a state actor, such as China, was investigating state enemies, such as suspected dissidents. They wanted to get the DMs, but also didn't want the general public to catch on. So they set things up so public discourse would be centered around the Bitcoin scam and celebrity hacks.

Post reply on HN