Live data from Hacker News

An update on our security incident

blog.twitter.com

171–180 of 308 posts

Re: An update on our security incident

#171

Earlier quoted context omitted.

>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…

This is by far the most eyebrow-raising part of the update. To take over such a large number of verified accounts and then run a download on only eight non-verified ones seems almost impossible to have been anything other than targeted. The original idea that the bitcoin scam was a diversion starts to look more plausible in this light, but in the absence of any information about the downloaded accounts, there’s reall…

> The original idea that the bitcoin scam was a diversion starts to look more plausible in this light,

This is still absurd to me. What diversion? Twitter knows exactly what was downloaded, and in fact they’re looking at this even closer due to the supposed diversion.

Re: An update on our security incident

#172
post #120

Earlier quoted context omitted.

Why do we assume it's a young person doing the hacking?

Because it's becoming increasingly hard to explain this hack otherwise. Imagine you walk by the beach, and see that the sea has washed up a pirate treasure chest. You crack it open, and see it full of gold, jewelry, old manuscripts, letters. Would you just throw the chest back into the sea, taking only a single ring, and a nail from the chest to hang a price list on your lemonade stand with? Because that's what happe…

More like the attackers rifled through the chest to find the map of the real treasure, leaving the meaningless trinkets behind.

Re: An update on our security incident

#173

Earlier quoted context omitted.

> There is a lot speculation about the identity of these 8 accounts. We will only disclose this to the impacted accounts, however to address some of the speculation: none of the eight were Verified accounts.[0] [0]: https://twitter.com/TwitterSupport/status/128433914877449830...

I wonder how many high-profile celebrities and other people with verified public accounts also keep private duplicate ones? Maybe that's going too far down the rabbit hole but I'm really curious now.

Yes, this seems an obvious answer to me, famous people's alt accounts, I'm not up on Twitter though.

Verified accounts, are surely mostly media-company controlled?

Re: An update on our security incident

#175
I believe it's much more interesting to know that the attackers got the email and personal phones of the involved targeted users, that means they will explore new vectors to attack them from other sources. That alone is more valuable than 100K USD, I guess all affected users going to change their emails and phones asap, but probably it will be late. My theory is the public tweet storm was just to kill the exploit in public, they can be accesing and using the tools for very long time without anyone from twitter noticing.

Re: An update on our security incident

#176
post #175

I believe it's much more interesting to know that the attackers got the email and personal phones of the involved targeted users, that means they will explore new vectors to attack them from other sources. That alone is more valuable than 100K USD, I guess all affected users going to change their emails and phones asap, but probably it will be late. My theory is the public tweet storm was just to kill the exploit in…

If they got access by triggering a password reset, it probably wouldn’t go unnoticed for long.

Re: An update on our security incident

#177
post #49

> 2FA compromised This is why sending or generating a OTP, that the user types in, is not secure. The user can be tricked into handing the OTP over the phone. Even the O365 system isn't secure (because the user can be told which number to tap over the phone). The only secure authentication these days is a non-communicable possession: Yubikey or similar. This reflects *very poorly on Twitter opsec.

[deleted]

Re: An update on our security incident

#179

Earlier quoted context omitted.

> the fact that they let the scam going on for hours destroying lives of people Source?

You can look at the blockchain how much money people lost, and for how long the scam went on. Or you can just read Twitter's announcement: they did nothing to mitigate the scam. I remember being scammed for about $200 when I was a teenager and it was awful. I was ashamed of myself.

Has anyone stepped forward and claimed they were scammed yet?

It's normal for scammers to pay themselves to make their scam look more legitimate.

If no one steps forward... it's not impossible that they actually didn't manage to scam anyone.

Re: An update on our security incident

#180

I like how Twitter wrote this post. It's apologetic, transparent, and clear. I feel like Cloudflare and Twitter have been really good with communicating what has happened and that is impressive. I'm glad these companies have learned from others' mistakes. Being transparent is the starting point of gaining back lost trust.

Agree, this is transparent, self aware, and takes responsibility. Kudos to Twitter.

It's in stark contrast to how FB wrote the post this week about their SDK crashing a bunch of third party apps. Some PR firm did all sorts of verbal gymnastics to avoid actually apologizing and taking real responsibility by shifting blame. [1]

[1] https://news.ycombinator.com/item?id=23827885

Post reply on HN