Live data from Hacker News

An update on our security incident

blog.twitter.com

181–190 of 245 posts

Re: An update on our security incident

#181

Earlier quoted context omitted.

Speaking from experience at a major infosec company, the impression I got internally was "we offer phishing tests, but we don't recommend them, because phishing succeeds 100% of the time". So I'm confused by the idea "even infosec people think training will stop this".

I disagree. There are services that regularly send fake phishing emails on a regular basis. If they click a link or fail to flag enough emails, their boss gets notified that more training is necessary. At the bank that I see this used at, the employees are far less trusting of emails and such. Training works if it's done right.

Yes, I've been involved with such a program before, and it definitely helps a lot. Phishing email click rates go way down.

This is carefully planned phone-based spear phishing, though, and that's a lot tougher to protect against. It can be easy for a skilled con artist to gain someone's confidence over the phone, no matter how much you warn about vishing (voice phishing). I'm sure training can still help there, but attackers just keep trying again and again until they find someone it works on.

Re: An update on our security incident

#182

Earlier quoted context omitted.

Speaking from experience at a major infosec company, the impression I got internally was "we offer phishing tests, but we don't recommend them, because phishing succeeds 100% of the time". So I'm confused by the idea "even infosec people think training will stop this".

I disagree. There are services that regularly send fake phishing emails on a regular basis. If they click a link or fail to flag enough emails, their boss gets notified that more training is necessary. At the bank that I see this used at, the employees are far less trusting of emails and such. Training works if it's done right.

Fake phishing emails work to remind users to check emails. Ask me how I know :-)

I also believe if a real phishing email makes it to a user then there’s a problem. Some of the real ones I get were easy to spot, “we tried to deliver a package” or “your order is on its way” type stuff. Spam filters should’ve picked them up.

Re: An update on our security incident

#183
post #40

As someone who works to stop these, the most frustrating part is how even infosec people thik enough training or $vendor's email security solution will stop this. It's like boy scouts that think they will stop navy seals. There is too much focus on entry point of an attack,especially by news media.

Speaking from experience at a major infosec company, the impression I got internally was "we offer phishing tests, but we don't recommend them, because phishing succeeds 100% of the time". So I'm confused by the idea "even infosec people think training will stop this".

Maybe infosec company is different than infosec at $bigcorp. I worked at a few places and the sentiment is the same.

Re: An update on our security incident

#184

Earlier quoted context omitted.

Speaking from experience at a major infosec company, the impression I got internally was "we offer phishing tests, but we don't recommend them, because phishing succeeds 100% of the time". So I'm confused by the idea "even infosec people think training will stop this".

I think badrabbit should have said "even some infosec people think training will stop this". As-is the grammar is ambiguous whether badrabbit meant "some" or "all".

I meant many not all

Re: An update on our security incident

#185
post #87

Earlier quoted context omitted.

Nope, seasoned pros I respect think trainig+$vendor is good enough. If it isn't, blame the user or the vendor! There are shops where the goal is to have someone to blame when you get owned and there are rare shops where the goal is to do it right to catch/stop bad guys even if it means you get blamed (because management understand security is not absolute)

Well in the end we are all just human. We can't expect to blame things on each thing a human does to human.

I agree,but tell that to the people that fire employees for failing phishing tests

Re: An update on our security incident

#186
> We have zero tolerance for misuse of credentials or tools, actively monitor for misuse, regularly audit permissions, and take immediate action if anyone accesses account information without a valid business reason.

Okay, so who has been fired?

That's what "zero tolerance" means: no excuses, not even "someone tricked me." And no punishment but the maximum.

Anything less would involve some degree of tolerance, and when you say "zero" that means no tolerance whatsoever.

It's obviously stupid to manage any organization that way, of course. It's a fatuous, dishonest phrase.

So stop talking about "zero tolerance" since all it means is "we make hyperbolic claims that we have no intention of living up to."

Re: An update on our security incident

#187
post #150

> the attackers targeted 130 Twitter accounts, ultimately Tweeting from 45, accessing the DM inbox of 36, and downloading the Twitter Data of 7 So much effort for so little gain... With proper preparation (i.e. a simple app ready to download everything from an account), they could have made out with the whole data of 130 accounts, silently, before tweeting the hopeless scam message. Instead, this seems like a mostly-…

I wish I knew why security does this character assassination routine with low-skill hacks. They clearly got in, bumbled attempt or not. Is it somehow helping everyone to know they fucked up? Whose expectations are we changing here?

Re: An update on our security incident

#188

Earlier quoted context omitted.

Speaking from experience at a major infosec company, the impression I got internally was "we offer phishing tests, but we don't recommend them, because phishing succeeds 100% of the time". So I'm confused by the idea "even infosec people think training will stop this".

I disagree. There are services that regularly send fake phishing emails on a regular basis. If they click a link or fail to flag enough emails, their boss gets notified that more training is necessary. At the bank that I see this used at, the employees are far less trusting of emails and such. Training works if it's done right.

[deleted]

Re: An update on our security incident

#189
post #186

> We have zero tolerance for misuse of credentials or tools, actively monitor for misuse, regularly audit permissions, and take immediate action if anyone accesses account information without a valid business reason. Okay, so who has been fired? That's what "zero tolerance" means: no excuses, not even "someone tricked me." And no punishment but the maximum. Anything less would involve some degree of tolerance, and wh…

Well besides claims of restricting access to the tools they obviously need to further have restricted access to certain user accounts. We have support persons whose account support is locked from superior accounts or special users and this seems like something Twitter should be doing.

Perhaps have another layer where each use of specific functions require unlocking through an incident management tool?

Post reply on HN