Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

191–200 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#191

Should there be citizenship requirements for access to customer data at that scale? Background checks? Security clearances?[1] When you have so much private data and the ability to put words into people’s mouths, aren’t you a national security asset at that point? Today it’s some bitcoin scammers, tomorrow it’s Russian or Chinese intelligence. If I was in charge of Russian or Chinese intelligence, I’d make sure that…

You know, I used to think that locking down certain websites to citizens of the country the website resides in was a bad thing. Now with the advent of all these apparent "bots", "state actors", etc. etc. I'm starting to think it might not be a bad idea. There's a bunch of "what-ifs" however like "what if the government starts removing content it doesn't like", "should you be able to be banned from the platform?", etc…

At least within the US, I think sufficiently large platforms should not be allowed to censor on the basis of viewpoint. But that is exactly the kind of political question that nation states, not international forces, should be answering.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#192

For comparison, at Google in 2011, I was one of ~10 or so engineers that had the ability to view private Gmail or Gplus data (access that was heavily documented and audited). That being said, Google did have to go through it's own public humiliation [1] to put a system like that in place. https://gawker.com/5637234/gcreep-google-engineer-stalked-te...

I almost wonder if government officials should be outright banned from using any private messaging platform that isn't hosted by the government itself.

There is just too much power in information.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#193

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

> There's thousands of people that have the ability to drain your bank account right now.

That's false equivalence. If a bank employee drains my account without authorization, it won't be difficult to prove and get back. But once your data leaks, it's out there.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#194

Earlier quoted context omitted.

That's a very US-centric view. Twitter has a lot of non-US users as well. In fact, a Dutch right-wing politician was apparently targeted in this attack.[1] How would such a requirement help in this case? [1]: https://www.reuters.com/article/us-twitter-cyber-netherlands...

Maybe the Dutch should do the same thing. Or throw their lot in with a country or group of countries they trust (EU, EU+x, NATO, etc.). The geopolitics of this would be complicated. But that has been life for small polities for thousands of years.

So I, a European citizen, wouldn't be allowed to see the Instagram posts of my American friends anymore? That doesn't seem practical.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#195

Earlier quoted context omitted.

Maybe the Dutch should do the same thing. Or throw their lot in with a country or group of countries they trust (EU, EU+x, NATO, etc.). The geopolitics of this would be complicated. But that has been life for small polities for thousands of years.

So I, a European citizen, wouldn't be allowed to see the Instagram posts of my American friends anymore? That doesn't seem practical.

You can federate services in ways that allow entities in different countries to control their own user data, while still allowing interactions between users in different countries.

Your private messages with other EU users might be stored only in Europe, with only Europeans able to access it. To the extent you message with people in another country, those controlling the federated service in that other country would have only the needed access. I don’t think this is groundbreaking technologically.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#196
post #86

Title corrected : More than 1k people at Twitter had ability to aid hack and chose not to.

> Title corrected : More than 1k people at Twitter had ability to aid hack and chose not to.

This is a stupid way of looking at it. Similarly:

- X number of people owned guns but they chose not to go do a mass shooting.

- X number of cops could kill a black person, they chose not to.

While it's a good thing that majority of the people know right from wrong, morality, etc, we still need to ensure one person can't do significant damage.

The fact that there are 1000s of individuals that could have hacked is not a good thing.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#197

Earlier quoted context omitted.

The key trick isn't so much the two as that they're randomly selected. I moved a large amount of money a few years back to buy my home (I do not like debt, so I saved up until I could afford somewhere to live, then I bought it) The bank's web site lets you type in any amount of money but then it says politely that you can't do this from the web site, please call the bank. I called the bank (they always pick up in 2-3…

In your story the bank trusted a phone call more than you being logged in the website? How did they authenticate you over the phone?

After I identify myself I have to give them letters from a telephone password and a series of arbitrary questions I selected like "Memorable date" to answer. The very large transfer was years before I received a physical two factor authenticator, it's possible that these days I'd need to prove I had the authenticator too, I don't know.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#198
post #93

Worth mentioning only 5,000 people work at Twitter.

There are ~330 million active twitter users, which means 330,000 users per employee with access to admin accounts. That ratio is massively high compared to a large corporate (i.e, a global bank). In a typical global bank lets says there are 100,000 employees, with about 25-50 IT people with the rights to admin accounts (from first line support to third line engineers) that's only 2,000-4,000 users per IT admin person…

> There are ~330 million active twitter users, which means 330,000 users per employee with access to admin accounts.

I think we should look at how many daily requests they get to reset account access settings (that cannot be done automatically - via some system rather than through these 1k users).

Re: More than 1k people at Twitter had ability to aid hack of accounts

#199
post #92

Earlier quoted context omitted.

There's not much detail but how would they gain access from a password reset if they didn't have access to the email account? And if they had email access then they already have everything. The reset via admin tools must have bypassed the normal email workflow.

Admin tools used to change account email address to one attacker controlled, then password reset requested which now sends to the attacker controlled email address

Then that's the vulnerable bypass.

Changing the email is effectively changing the identity attached. It's akin to an account recovery and should require several verification steps before it can be done.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#200
post #113

Earlier quoted context omitted.

> If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. Not really, a blue checkmark is just a status symbol.

This is exactly the problem with the blue tick. It's basically meaningless other than as a budge of honour. It's also restricted to large companies and 'public' figures. What I'd like to see is, the Blue Tick being restored to be an actual mark of Verification, and be something that anyone can apply for with the appropriate identification documentation. Additionally, there should then be a toggle switch, where only V…

This problem has been solved for decades - cryptographic signatures. Twitter and their users are uninterested in a real solution, they just want engagement.
Post reply on HN