Earlier quoted context omitted.
Many startups and hip companies don't do VPNs anymore - unfortunately they also dont do Zero Trust (which would require machine certs for everything and be enforced) - so stuff is often available over Internet with password auth + maybe MFA. Attacker who gets hold of cookie or bearer token wins. And the best part, support personnel often doesnt have MFA, because its outsourced to countries where smart phones with Aut…
Really stupid question. A key employee leaves, with their personal 2FA. Is there a standardized corporate solution for this yet? Sorry if that’s weirdly worded
Who’s behind Wednesday’s epic Twitter hack?
201–210 of 536 posts
Re: Who’s behind Wednesday’s epic Twitter hack?
#202Earlier quoted context omitted.
Many startups and hip companies don't do VPNs anymore - unfortunately they also dont do Zero Trust (which would require machine certs for everything and be enforced) - so stuff is often available over Internet with password auth + maybe MFA. Attacker who gets hold of cookie or bearer token wins. And the best part, support personnel often doesnt have MFA, because its outsourced to countries where smart phones with Aut…
Really stupid question. A key employee leaves, with their personal 2FA. Is there a standardized corporate solution for this yet? Sorry if that’s weirdly worded
Re: Who’s behind Wednesday’s epic Twitter hack?
#203man who falls for this stuff. i've been seeing "send me money to this account to get double that" scam for like 20 years, its hard to believe there are people who still don't know better.
I think they could have done a lot better by having Elon tweet out a new product preorder page (limited edition Tesla merch?), which accepts payments in crypto. Really anything other than give me X so I can give you 2X, which has been done to death already. 100k is chump change, historically for this class of scam. Another idea is, hijack customer service request DM's from crypto exchanges, and lead customer to phish…
Re: Who’s behind Wednesday’s epic Twitter hack?
#204Earlier quoted context omitted.
It's almost as if web services that let people post whatever they want at any time, vulnerable to whatever security flaws may be present, shouldn't be used as a reliable source for up-to-the-minute information about literally anything important at all.
The same could be said for radio, whether Orson Wells "Alien Invasion" broadcast or the multitude of April 1st jokes that got out of hand.
It's perfectly feasible for every trusted source of knowledge to run a web server, and they actually do it, so it's sad that consumers don't connect directly to those servers and instead use middlemen.
Re: Who’s behind Wednesday’s epic Twitter hack?
#205I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…
People keep saying it could have started a war. Excuse me for being naive but come on—really? This is total sensationalism. What party wouldn’t verify something on twitter through diplomatic channels before going to war? Equity destruction: sure. War: no way.
I dont even have a twitter, facebook, instagram, or... anything i think. just you people : )
Re: Who’s behind Wednesday’s epic Twitter hack?
#206Funny that Krebs refers to Lucky225 as a longtime friend of Adrian Lamo. I thought it was very well-known that Lucky225 made that story up as a cover to hide the fact that he gained control of Adrian Lamo’s @6 Twitter via a SIM swap hack himself, and also took control of Lamo’s Facebook in order to hijack ownership of the 2600 Magazine group on Facebook.
It's a very awkward thread where Lucky225 accidentally demonstrates that he has indeed taken over Adrian Lamo's email account. Note this doesn't say anything about whether they were or weren't friends. They definitely had overlapping interests.
Re: Who’s behind Wednesday’s epic Twitter hack?
#207Earlier quoted context omitted.
People keep saying it could have started a war. Excuse me for being naive but come on—really? This is total sensationalism. What party wouldn’t verify something on twitter through diplomatic channels before going to war? Equity destruction: sure. War: no way.
Donald Trump?
Re: Who’s behind Wednesday’s epic Twitter hack?
#208Re: Who’s behind Wednesday’s epic Twitter hack?
#209Earlier quoted context omitted.
People keep saying it could have started a war. Excuse me for being naive but come on—really? This is total sensationalism. What party wouldn’t verify something on twitter through diplomatic channels before going to war? Equity destruction: sure. War: no way.
War is perhaps an exaggeration, but if its wrong its wrong quantitatively, not qualitatively. In other words, lives unquestionably hung in the balance. I dont even have a twitter, facebook, instagram, or... anything i think. just you people : )
Re: Who’s behind Wednesday’s epic Twitter hack?
#210Earlier quoted context omitted.
On the off-chance that you're serious - doxxing someone who is suspected to be linked to a crime is staggeringly irresponsible, because you are then effectively convicting them in the court of public opinion. If they are innocent, but you have not only levelled accusations at them, but provided ways to access them, then you are partially responsible for what others choose to do with that information.
Isn’t most crime journalism the same? Three examples from the front page of the NY post right now. I am having a hard time figuring out how to distinguish this and the OP doxxing. The organizationS fact-checking process? Solidness of the evidence? > Allegations were made against longtime radio broadcaster Larry Michael (retired Wednesday), director of pro personnel Alex Santos (fired last week), assistant director of…