Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

281–290 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#281

Very tangential: That's a surprisingly childlike & adorable UI design for a security admin dashboard!

Doesn't really surprise me much. Internal tools get 0.00001% of the UI design effort that production tools do. It looks like an old version of Bootstrap too.

Re: Who’s behind Wednesday’s epic Twitter hack?

#282

I don’t really think he should be naming who his unnamed sources “think” is behind an attack on this scale, especially with full name, city of origin, Instagram, suggested current location, age, etc. It feels a very, very small step away from doxxing to me. Added to which he has somebody in the comments essentially calling for the death penalty over this. If he has this personal information and evidence, pass it to t…

> Added to which he has somebody in the comments essentially calling for the death penalty over this

Don't feed the trolls. If anything we've seen a lot of praise for this person. That has probably been the most responsible hack when you think about it.

Re: Who’s behind Wednesday’s epic Twitter hack?

#283

Earlier quoted context omitted.

People keep saying it could have started a war. Excuse me for being naive but come on—really? This is total sensationalism. What party wouldn’t verify something on twitter through diplomatic channels before going to war? Equity destruction: sure. War: no way.

Here's how I think it could be done: Get Trump's account, and tweet something like, "I've ordered a NUCLEAR STRIKE on China! The missiles are already in the air. The DEEP STATE is trying to take me out. They will try to silence me and delete these tweets and use deep fakes to say this was a hoax! The storm is here, Q is real, it's time to take up arms and kill democrats." Then continue tweeting escalating things over…

If this indeed had happened, I wonder how it would have played out. It would not be pretty, that is for sure.

Re: Who’s behind Wednesday’s epic Twitter hack?

#285

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

Oh please. The rest of the world doesn’t take Twitter as seriously as Americans do. And truth be told, Americans shouldn’t take it seriously either.

The platform derives power from the audience. Stop giving it your power.

Re: Who’s behind Wednesday’s epic Twitter hack?

#286

The among taken in this scam is chump change compared to the YouTube scammers. YouTube is a vastly bigger website than twitter and way slower to respond to accounts begin stolen by scammers. I remember seeing an Ripple giveaway scam that in a single day made 100k with just a single account ,. And fake bill gates one made 40k. the list goes on and on. My guess is the total taken is in the $3-5 million range from youtu…

How do we know the bitcoins was the actual target/purpose? At this point I would be very hesitant to make any sort of judgement like that.

Re: Who’s behind Wednesday’s epic Twitter hack?

#287
post #200

I'm sure it's been said before, but I just continue to be surprised that the admin panel used to carry out this attack wasn't locked behind a VPN. I've worked for multiple fully-remote companies that were easily able to protect tools like this from the outside world. The company I currently work for (fully remote) has tons of internal services that our engineers (who we trust) can access as needed in order to debug p…

Internal networks only accessible via VPN is considered an anti-pattern now in terms of security. It puts authorization firmly on the VPN. If the account with VPN access is compromised, then the attacker has full access to these sensitive systems. This hack probably underscores the importance of zero trust. Although if the system is compromised from within (like this hack is) then there is not much you can do.

> Internal networks only accessible via VPN is considered an anti-pattern now in terms of security.

"Defense in depth" is not an anti-pattern. Using an VPN as the only layer is, certainly, but that is a straw man.

Re: Who’s behind Wednesday’s epic Twitter hack?

#288
post #283

Earlier quoted context omitted.

Here's how I think it could be done: Get Trump's account, and tweet something like, "I've ordered a NUCLEAR STRIKE on China! The missiles are already in the air. The DEEP STATE is trying to take me out. They will try to silence me and delete these tweets and use deep fakes to say this was a hoax! The storm is here, Q is real, it's time to take up arms and kill democrats." Then continue tweeting escalating things over…

If this indeed had happened, I wonder how it would have played out. It would not be pretty, that is for sure.

Well let’s see...since all countries with ICBMs also have technology in place to detect or verify via satellite a nuclear launch, absolutely nothing would happen. If a real launch had taken place, they would have known about it far before they heard about a post on Twitter. The alarmism here on HN is really disappointing. This is the kind of foolishness usually reserved for Reddit.

Re: Who’s behind Wednesday’s epic Twitter hack?

#289
post #200

Earlier quoted context omitted.

Internal networks only accessible via VPN is considered an anti-pattern now in terms of security. It puts authorization firmly on the VPN. If the account with VPN access is compromised, then the attacker has full access to these sensitive systems. This hack probably underscores the importance of zero trust. Although if the system is compromised from within (like this hack is) then there is not much you can do.

I would be curious as to who is citing that using a vpn is some "anti-pattern", to what? Not protecting your network accessible assets? If you have the means, certainly use a corporate/smb/personal vpn. It is one layer in a multitude of layers you should be using to protect your network. Its not as if once you achieve vpn access you have no other authz gates to internal applications. Its a "great filter" to help narr…

https://www.beyondcorp.com/

Yes, basically you should consider all networks untrusted including your internal network. You can still have a VPN but it shouldn't be the thing that protects the services inside your corp net because if it is then any breach means the intruder gets access to all your stuff.

Re: Who’s behind Wednesday’s epic Twitter hack?

#290

Earlier quoted context omitted.

>> Also, it seems clear that this Twitter hack could have let the attackers view the direct messages of anyone on Twitter, information that is difficult to put a price on but which nevertheless would be of great interest to a variety of parties, from nation states to corporate spies and blackmailers. It is not as much money as pundits probably think it is worth. And also, trying to negotiate a blackmail is time consu…

> Do you really think someone like elon musk will pay a bitcoin ransom A somewhat odd blog post by Jeff Bezos about blackmail from last year is quite interesting in this context. [1] [1] https://medium.com/@jeffreypbezos/no-thank-you-mr-pecker-146...

They grossly overestimated their leverage in that story though.

Anything illegal might've been actually good for black mail purposes, but dick pics? As if someone would actually look for that or even take a business decision based on that.

Post reply on HN