Live data from Hacker News

An update on our security incident

blog.twitter.com

221–230 of 308 posts

Re: An update on our security incident

#221
post #49

> 2FA compromised This is why sending or generating a OTP, that the user types in, is not secure. The user can be tricked into handing the OTP over the phone. Even the O365 system isn't secure (because the user can be told which number to tap over the phone). The only secure authentication these days is a non-communicable possession: Yubikey or similar. This reflects *very poorly on Twitter opsec.

There is no secure authentication method because if you compromise the client (i.e. the desktop PC or phone they are using to perform operations) then you can just take control after the user authenticated regardless of authentication method.

What you need is a secure client, such as a dedicated tablet that is only used to access that service, along with a tamper-proof self-destruction system and a camera and set of sensors that can identify that only the intended person is present.

Even then the user can still be blackmailed to act in the attacker's interest, so you also need to offer the user a secure place to live in and make sure they are fully happy.

Re: An update on our security incident

#222

To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…

I think that the fact the world will continue to spin without twitter is exactly why the hesitated to make that type of call.

I bet they put profit over security. They considered lost ad revenue.

Re: An update on our security incident

#223
post #218

Earlier quoted context omitted.

They disabled the account that were identified to be compromised. That isn’t enough?

Disabling everything would have been quicker, and there's no way they could have been certain which accounts were compromised, certainly not so early. Even now - you have to make do with the traces the attackers leave behind, but it's unlikely you have complete certainty that some traces weren't removed, or fallback backdoors perhaps placed. Also, disabling everything would have likely been only a very short term sol…

> How many people saw the tweets and transferred bitcoins during the period in which twitter likely could have turned off everthing, but not yet blocked access to the respective accounts

At most 475 greedy idiots, average $266 each

https://www.coindesk.com/chainalysis-says-bitcoin-scammed-fr...

"The most prevalent address received $120,000 in bitcoin from 375 transactions. Secondary addresses received $6,700 in bitcoin from 100 transactions. An XRP wallet netted nothing."

Re: An update on our security incident

#224

‘ we are deliberately limiting the detail we share on our remediation steps at this time to protect their effectiveness ’ Translation - it’s not fixed. Security through obscurity. Also timeline says ‘Wednesday’ post-mortem should be accurate to the minute or second.

Actually, it’s good that they’re communicating proactively. It’s not supposed to be a postmortem. This post sucks

Re: An update on our security incident

#225
post #183

Like many of you, I watched this rolling on Wednesday night using live verified accounts link that was widely shared. I was also just looking at the 'regular people' tab without verified accounts and saw many, many, many accounts tweeting the same "double your bitcoin" link, with the same BTC address. These weren't retweets. I'd assumed these accounts had also been compromised - was I wrong? It was far more than 130…

Yes! I’m confused at what the automated attack was about. Possibly botnets tweeting it to distract from the real account access or to make the attack look worse than it was?

Re: An update on our security incident

#226
post #49

> 2FA compromised This is why sending or generating a OTP, that the user types in, is not secure. The user can be tricked into handing the OTP over the phone. Even the O365 system isn't secure (because the user can be told which number to tap over the phone). The only secure authentication these days is a non-communicable possession: Yubikey or similar. This reflects *very poorly on Twitter opsec.

Problem is that the category of users who can be tricked over the phone to tell someone OTP are people who just won't be bothered to use external devices like yubikeys - they're a hassle, you need to carry it around, can loose it, costs money, etc. 2FA is a middle ground, it's free, it's already with you as you carry the phone anyway. Most of ordinary people can be talked into actually using it, and while not perfect it provides a lot more security than just passwords...

Security always goes against user's convenience, just like the privacy... and in real life, as a rule of thumb people tend to almost always choose convenience, first of anything else...

Re: An update on our security incident

#227
> Attackers were able to view personal information including email addresses and phone numbers, which are displayed to some users of our internal support tools.

Can anyone explain to me why the phone number is stored in plain text for them to see?

Re: An update on our security incident

#228

To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…

it is unlikely but not inconceivable that a bunch of accounts would tweet a similar solicitation, so obviously they needed enough data before knowing for sure twitter was under attack.So that meant the attacker probably had a solid 30-60 minutes of being undeterred. Even if a considerable number of people get scammed, the lost ad revenue would from shutting down the site would vastly exceed the cost of some users leaving twitter. Twitter knows its verified users are forgiving and loyal and will not leave the site if occasionally hacked. Twitter is a for-profit business. People need to keep this in mind, so their actions will be motivated to some degree by what is profitable for them. They are not a public service, even if they play a major role un public discource and politics.

Re: An update on our security incident

#229

To me the really irresponsible bit is that they kept the service up knowing full well there was a live attack in progress and they had not yet found a way to stop it. The Big Red Button has a place and the time to use it was last week. Given the prominence of the accounts that were compromised there isn't a shadow of doubt that shutting it down was the only responsible course of action. The world will continue to spi…

If total shutdown you suggest was done, I'd consider it a successful DoS attack.

Re: An update on our security incident

#230

Earlier quoted context omitted.

> There is a lot speculation about the identity of these 8 accounts. We will only disclose this to the impacted accounts, however to address some of the speculation: none of the eight were Verified accounts.[0] [0]: https://twitter.com/TwitterSupport/status/128433914877449830...

>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them…

What if the 8 non-verified accounts are alt-accounts used by celebs/VIPs for personal communication?

Let us imagine that I am Jeff Bezos, why would I use my official account to DM people? I would rather use one where I look like everybody so that it is less likely to be the target of an attack.

Post reply on HN