Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

281–290 of 477 posts

Re: Twitter internal panel linked to account hijackings

#282
post #94

Anyone else unimpressed with Twitter's U2F/FIDO token support? They support a total of 1 (one) U2F token on an account :( The only other company I know that does that is AWS and one U2F token. Every other site I use allows multiples, usually at least 5 or more. I setup U2F on Twitter but then got rid of it after realizing they only allow one.

the entirety of AWS seems to be half assed in general as you've described: the U2F functionality is completely useless because if you lose/break your single U2F key then you're completely screwed and they still have no support for ed25519 keys (which were added to OpenSSH in 2013), unlike every other cloud service I have to have an RSA key just for AWS (particuraly annoying as I have all my other ssh keys stored in a…

You can script your vm creation pretty easily and pipe your hardware key to the script

Re: Twitter internal panel linked to account hijackings

#283
post #95

Earlier quoted context omitted.

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

Lots of uncertainty, but I could see it being relatively mundane. It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts. It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid. Of course, could also be s…

It would surprise me if a lot of Twitter support people had access to tools that allowed them to post tweets as another user. That's not functionality that should be available to a Twitter support person.

Re: Twitter internal panel linked to account hijackings

#284
post #40

According to some images, Twitter low level employees can see email address of all accounts (and I guess phone numbers). I know some celebrities have their real email address and phone numbers on those accounts. Isn't that something bad?

The management of individual accounts is generally performed by low-level employees at companies like this. It's operational work that is thought to scale poorly and the costs of it are looked upon unfavorably by public market investors. Hence, there is constant pressure to push it to as low of a level as possible. Perhaps a higher tier of user support personnel handles verified accounts (or accounts somehow flagged…

Having access to some is not the same as having access to all. Rate limiting , or restricting to ones I am managing and approval processes are pretty easy . It does not like Twitter is doing any of that .

Re: Twitter internal panel linked to account hijackings

#285
post #230

Earlier quoted context omitted.

I didnt even know I wanted to know this. My guess is between Jeff and Bill. They're the leading ones who can afford giving twice the money back ;)

I'd assume one closer to crypto, probably Elon Musk or Coinbase. Because the audience needs to know how to quickly send BTC. In addition, it's a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his. So, maybe some thought today Musk is having it and finally doing it for real! If there is a person to run such a campaign for real, it would be him - so it could even be pl…

> a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his.

How does twitter allow this spam?

Re: Twitter internal panel linked to account hijackings

#286

To me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisti…

I think there are three possible explanations here: 1- (Tinfoil hats please) This is a state owned attack, which is a retaliation from US Government to ruin Twitter's credibility and introduce social media regulations. 2- The hackers are gray hat hackers, who know that reporting this vulnerability will not make them any money and they want to get what they think they deserve, so they make it public and get some good…

Regarding #1, my thinking was this is China or their allied nations (North Korea, Iran etc). The US has taken extremely forceful steps on China in the last couple of days. This could be their response; discrediting a huge piece of the American crown jewels (big tech companies) and making it a laughing stock.

Just the massive blast radius of the hack reminded me of the NK Sony hack and release of documents. Big up yours to Hollywood from Kim Jong.

Re: Twitter internal panel linked to account hijackings

#287
post #171

Wait a second...they were hacked in a way that makes it so we can't trust any tweets. Does it make sense, then, for them to use tweets to report their progress on addressing this?

Why not? They're not updating HN with those but media and shareholders.

Because for all we know , it is not them posting this tweet and is the attackers . How can you trust it is them when the attack clearly showed any account can be manipulated.

This kind of compromised messaging is not unknown while being attacked , when browserstack got hacked few years back, the attackers send official email to all customers whose emails they got in the leak saying the company was shutting down.

Re: Twitter internal panel linked to account hijackings

#288

Did the attackers have direct access to the database, or why does their internal admin dashboard allow employees to tweet on behalf of any account?

Perhaps the admin dashboard allows support staff to reset emails/passwords, and they simply logged in as the users to tweet.

It doesn’t make sense that they’d let it go on like that and play whack-a-mole with the tweets for hours. I don’t buy it.

Re: Twitter internal panel linked to account hijackings

#289

Earlier quoted context omitted.

But that's not really identity then right? That just becomes my hnews/reddit username that's unverified. I read @elonmusk because I trust it's him and I'm interested in what he says. Personally, I genuinely like Starship + Starlink updates... I ignore most the other stuff. But still, I want to see those awesome rocket tweets! So, I want to know what he says. He can change his username because it got hacked/whatever..…

Your hnews username is an identity. A small, weak, and reasonably disposable one, that you can have many of. Why do you want to use your God damn real name on the Internet unless you are a public person already? What do you have to gain? Hate mail, Death threats and calls for your firing? I've always wanted more of those. You do not WANT to be verified. Verified is a euphemism for doxxed. You could trust it was Elon…

How can we evaluate previous performance of (new) disposable accounts?

Re: Twitter internal panel linked to account hijackings

#290
post #95

The Vice article ( https://news.ycombinator.com/item?id=23853786 ) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take ov…

This makes things sound even fishier. I think there has to be something else going on we don't yet know about. The amount of money this scam will actually earn the hacker is tiny compared to the potential of this hack and yet they still have enough money left over to bribe a presumably highly paid Twitter employee? Or maybe the Twitter employee is a low paid person which leads back to a question I raised elsewhere in…

The same guy used to use his connection/social engineering to overtake "nice" twitter handles and resell them for money. He just got too greedy.

I don't think there is something super nefarious involved. Probably some unpaid intern in a third world country where Twitter outsources tech support.

Post reply on HN