Live data from Hacker News

An update on our security incident

blog.twitter.com

191–200 of 245 posts

Re: An update on our security incident

#191
post #92

Earlier quoted context omitted.

Hey, Any good literature which you'd recommend to read to avoid something like this?

Use U2F for 2FA. If Twitter had all their employees using U2F keys it's very unlikely they'd be phished. With U2F it's impossible to "enter" a 2FA code on the wrong domain, making you immune to phishing attacks by most definitions. This Kerbs article from awhile back says that Google had zero phishing incidents after making this switch: https://krebsonsecurity.com/2018/07/google-security-keys-neu...

"If Twitter had all their employees using U2F keys it's very unlikely they'd be phished."

I don't know that they even need to go that far. Just U2F on the god-mode admin tool would have been reasonable.

Re: An update on our security incident

#192
post #150

> the attackers targeted 130 Twitter accounts, ultimately Tweeting from 45, accessing the DM inbox of 36, and downloading the Twitter Data of 7 So much effort for so little gain... With proper preparation (i.e. a simple app ready to download everything from an account), they could have made out with the whole data of 130 accounts, silently, before tweeting the hopeless scam message. Instead, this seems like a mostly-…

I wish I knew why security does this character assassination routine with low-skill hacks. They clearly got in, bumbled attempt or not. Is it somehow helping everyone to know they fucked up? Whose expectations are we changing here?

Who is “security” here? In my experience, if you ask most working security professionals, they would agree that social engineering is by far their largest vulnerability. All the cryptography stuff is fun and cool but really the work is all about preventing phishing, so I don’t know any working security engineers who would call this a low-skill hack.

Re: An update on our security incident

#193
post #150

> the attackers targeted 130 Twitter accounts, ultimately Tweeting from 45, accessing the DM inbox of 36, and downloading the Twitter Data of 7 So much effort for so little gain... With proper preparation (i.e. a simple app ready to download everything from an account), they could have made out with the whole data of 130 accounts, silently, before tweeting the hopeless scam message. Instead, this seems like a mostly-…

I wish I knew why security does this character assassination routine with low-skill hacks. They clearly got in, bumbled attempt or not. Is it somehow helping everyone to know they fucked up? Whose expectations are we changing here?

Well, I see 2 reasons here: 1/ when an attack is deemed a low-profile one, it is a way to say that the targeted company might be to blame, at least in part, for not having adequate security protocols; 2/ in this instance, some people might be frustrated that the DM of high profile people won't leak on the internet because of a lack of preparation from the attackers.

Most of the time, the "character assassination routine" is to emphasize the first point.

Re: An update on our security incident

#194

Earlier quoted context omitted.

I disagree. There are services that regularly send fake phishing emails on a regular basis. If they click a link or fail to flag enough emails, their boss gets notified that more training is necessary. At the bank that I see this used at, the employees are far less trusting of emails and such. Training works if it's done right.

Yes, I've been involved with such a program before, and it definitely helps a lot. Phishing email click rates go way down. This is carefully planned phone-based spear phishing, though, and that's a lot tougher to protect against. It can be easy for a skilled con artist to gain someone's confidence over the phone, no matter how much you warn about vishing (voice phishing). I'm sure training can still help there, but a…

Same principle can apply though. If email phishing can be simulated and used as training, voice can be added to that training drill.

Any successful attack vector can be turned into a training scenario and repeated until better responses are trained into the target group.

Military casualty drills are very effective at instilling near instinctive responses... same principle applies.

Re: An update on our security incident

#195
post #12

Freaking Twitter needs a serious auth infra upgrade. Unless phishers hijacked employee devices, they accessed the tools remotely, meaning there's no form of client authentication?? Something like U2F which by now is pretty old seems like it would prevent this kind of attack

Jack Dorsey's twitter account getting hacked via a SIM swap attack last year[1], should've been a wake up call for them.

The recent hack just shows how lackadisical their attitude to security is.

I used to work at FB some years ago and they had U2F for everyone, even back then. Also, regular phishing test drills and red-team exercises.

[1]: https://www.wired.com/story/jack-dorsey-twitter-hacked/

Re: An update on our security incident

#196
post #186

> We have zero tolerance for misuse of credentials or tools, actively monitor for misuse, regularly audit permissions, and take immediate action if anyone accesses account information without a valid business reason. Okay, so who has been fired? That's what "zero tolerance" means: no excuses, not even "someone tricked me." And no punishment but the maximum. Anything less would involve some degree of tolerance, and wh…

It’s like when motorcyclists say “safety first” about wearing a helmet and other protective gear. If they really put safety first, they’d choose a safer form of transportation. They mean “given that I’m going to engage in this risky activity, I’m going to try to make this activity as safe as possible”.

In this case “zero tolerance” is short for something like, “except for understandable slip-ups that aren’t fully your fault, we’re not going to tolerate any slip-ups”.

Re: An update on our security incident

#197
post #90

Earlier quoted context omitted.

That's the thing, you can't,not with the way current tech is. But you can read up about having good monitoring/detection and hardening on your endpoints. Microsoft for example recommenda privileged access workstations. If twitter's employees used a separate set of credentials and workstations for privileged twitter moderation than their regular account/machine used for email and day to day stuff I bet the attack wolf…

There are probably Twitter employees whose job it is to reset emails all day long. Having 2 separate computers and accounts, one for for resetting emails (which is done all day) and one for responding to email sounds like quite a burden on employees. How are they going to get the name of the account from one computer to the other? Copy and paste won't work. Retyping from one computer to the other surely will result i…

I'd say a typo rate is an acceptable tradeoff for air-gapping privileged access.

Re: An update on our security incident

#198
post #81

Earlier quoted context omitted.

What infosec people think $vendor email security solutions are going to solve phishing attacks? I was under the impression that the people that buy those solutions (like many security solutions) are primarily non-infosec people that want to paper over their real problem without fixing it. Granted, there is a place for some of these things temporarily while working to fix the actual problem, but that's a mitigation, n…

FWIW email security training is something you'll probably be forced to provide, to some degree, as a matter of compliance. It's another case of compliance wasting time by driving companies to do security work that isn't meaningful.

I think some amount of email security training is worthwhile. I was specifically talking about so-called "solutions".

Re: An update on our security incident

#199
post #186

> We have zero tolerance for misuse of credentials or tools, actively monitor for misuse, regularly audit permissions, and take immediate action if anyone accesses account information without a valid business reason. Okay, so who has been fired? That's what "zero tolerance" means: no excuses, not even "someone tricked me." And no punishment but the maximum. Anything less would involve some degree of tolerance, and wh…

It’s possible to have zero tolerance and not fire anyone here. My understanding is that no employee misused their credentials or tools. The attackers misused them. I suppose you could argue that accidentally exposing credentials is misusing them, but I don’t think that’s what Twitter means there.

Re: An update on our security incident

#200
post #40

As someone who works to stop these, the most frustrating part is how even infosec people thik enough training or $vendor's email security solution will stop this. It's like boy scouts that think they will stop navy seals. There is too much focus on entry point of an attack,especially by news media.

>There is too much focus on entry point of an attack,especially by news media. That depends on what you mean by "entry point". If you define the entry point as a person, then yes don't focus on that. But if you define the entry point as phishable credentials, then focusing on that is good, it will prompt companies to switch to phishing-resistant credentials (U2F security keys).

Even u2f isn't fool proof (exploitation and cookie theft techniques). Execution,privesc,lateral movement are things focus should be on. You can't control the facg that people need to use email and they will for for a phish,but you can control your authentication system, alerting system,etc...
Post reply on HN