Live data from Hacker News

An update on our security incident

blog.twitter.com

31–40 of 245 posts

Re: An update on our security incident

#31
post #14

Are account support tools available off premises? I know nothing about security for big companies like Twitter but it seems like tools that enable you to post from any verified user (outside of Trump, someone here once mentioned he had additional account controls) should only be accessible from secure offices regardless of individual credentials.

That would probably not work well during the pandemic...

It could with an appropriately secured private VPN.

Re: An update on our security incident

#32
post #24
post #18

Earlier quoted context omitted.

Training that is notorious for being ineffective in practise and usually more about box ticking. Assuming that none of your employees fall for phising, much less targeted phising, is woefully unrealistic. Especially at twitter's scale. Assuming humans won't do stupid things 100% of the time is never an effective security control.

This is an excessively pessimistic take on security training. How many spear phishing attempts have been thwarted because the employee knew better? It’s not a solution to the problem, but it certainly helps.

I would actually be interested in seeing some studies on that.

My gut feeling is for engineers, the phising training that most companies use is wholly ineffective at doing anything, and in particular it is especially ineffective against targeted attacks. But i have yet to see any research one way or another.

I suspect less technical users might benefit from such training a bit more (but still not that much)

Re: An update on our security incident

#33
post #31
post #14

Earlier quoted context omitted.

That would probably not work well during the pandemic...

It could with an appropriately secured private VPN.

Original poster said on premise. An appropriately secured vpn may or may not help security, but it is still "virtual" and does not meet the definition of on premise.

Re: An update on our security incident

#34
post #24
post #18

Earlier quoted context omitted.

Training that is notorious for being ineffective in practise and usually more about box ticking. Assuming that none of your employees fall for phising, much less targeted phising, is woefully unrealistic. Especially at twitter's scale. Assuming humans won't do stupid things 100% of the time is never an effective security control.

This is an excessively pessimistic take on security training. How many spear phishing attempts have been thwarted because the employee knew better? It’s not a solution to the problem, but it certainly helps.

How many? A fair number. Not 100%, though. If your system depends on your people 100% not falling for spear phishing, your security is dead.

Re: An update on our security incident

#35

They should require hardware security devices (dongles). Really Twitter should be ashamed of their poor internal security.

Dongles are rare here in the US. But I know that bloomberg uses them. I was shocked when I learned that retail banks in Singapore give everyone dongles to log in. In the US that's tyranny Lol

rare? I worked at Facebook and every employee needs one.

Re: An update on our security incident

#36
post #5

Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update... > The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all o…

I'd like to know more about these tools. That there's at least one which can bypass a user's 2FA settings without notification suggests that there are additional tools in the same vein.

Re: An update on our security incident

#37
post #18
post #8

It is inexcusable that Twitter is employing people who are susceptible to social engineering attacks like this. This is simple training and seriousness.

Training that is notorious for being ineffective in practise and usually more about box ticking. Assuming that none of your employees fall for phising, much less targeted phising, is woefully unrealistic. Especially at twitter's scale. Assuming humans won't do stupid things 100% of the time is never an effective security control.

Where I work there is training software that is somewhat effective at preventing phising - it actually sends out phising emails itself. Then employees who fall for it are given extra training (in a no fault sort of way).

Re: An update on our security incident

#38

Earlier quoted context omitted.

Why are internal employee tools publically accessible? Minimum they should require VPN access, but really go further with Zero Trust.

AFIK, in a Zero Trust Architecture a VPN is considered a perimeter and therefore it becomes a vector of attack to access systems of authoritative decision. Many security researchers have already established that the benefits of a VPN especially in the modern distributed world are marginal at best. Basically, yes a VPN makes you a tiny bit safer but it also adds a lot of networking complexity and adds more friction to…

Depends on what you're defending.

If your enterprise is a global network with millions of nodes operating a blend of modern and legacy systems accumulated through hundreds of acquisitions in 100+ countries over the course of the last 50 years, a VPN with hardware tokens isn't a bad additional layer. It isn't even mutually exclusive with zero trust, it's just another layer of auth and access.

Twitter? Largely a different story and commando zero trust might be a viable option. As observed many other places, this sounds like a poor authentication model and probably poor governance for highly privileged access. Presumably they will take a look at their authentication, which sounds like it's making some bad assumptions, and improve.

Re: An update on our security incident

#39
post #24

Earlier quoted context omitted.

This is an excessively pessimistic take on security training. How many spear phishing attempts have been thwarted because the employee knew better? It’s not a solution to the problem, but it certainly helps.

How many? A fair number. Not 100%, though. If your system depends on your people 100% not falling for spear phishing, your security is dead.

Well, that’s what I meant when I said that it isn’t a solution. You shouldn’t rely on training, but it’s disingenuous to say it can’t help.

Re: An update on our security incident

#40
As someone who works to stop these, the most frustrating part is how even infosec people thik enough training or $vendor's email security solution will stop this. It's like boy scouts that think they will stop navy seals. There is too much focus on entry point of an attack,especially by news media.
Post reply on HN