Live data from Hacker News

Hackers take over prominent Twitter accounts in simultaneous attack

coindesk.com

301–310 of 1001 posts

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#301

Earlier quoted context omitted.

Yeah, I would have guessed a platform like Twitter would have anti-abuse systems with at least term filters.

At this point I'd advocate for a huge red button or a gong that someone can smash and it just halts the platform

Kill-switches are dangerous, since they get built and never get used. I work on an anti-abuse system. It caused two user-visible outages in the last couple of years, one of which was an accidentally triggered kill-switch that had not been used in years and had some unexpected side-effects.

So I can see why they wouldn't have one of those pre-built for setting the entire site to a read-only mode. It's not at all obvious whether the risks are larger with or without that capability built in. But a spam filter with configs you can push quickly seems like table stakes, and should be a system that gets excercised weekly if not daily.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#303
post #269

Earlier quoted context omitted.

You mean shutdown Twitter? I think that's a bit extreme in this case.

It's not too hyperbolic to say that WW3 could be started on a platform like Twitter. Having a "shutdown" button doesn't seem that extreme when essentially the entire site seems to be compromised. I'd bet my bottom dollar that Congressional hearings are going to happen.

Ok but a few accounts asking for Bitcoin from rubes isn't WWIII

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#304
post #29

Earlier quoted context omitted.

You would think they would do something with Trump if it was arbitrary accounts. But maybe his has additional protections

They're clearly trying to avoid the risk of being tracked. For example, they could have done stock manipulation and made more money. Trump is someone with the power and craziness to spend a hundred million tracking you down and literally dropping bombs on your head. So it'd be poor risk management to go after his account.

I agree, but only until the bombings, I mean he's the most anti-war president in living memory.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#305
post #256

What blows my mind is how does Twitter not have a "maintenance" mode -- where no new tweets can be posted and the site is essentially read-only?

Corporations don't do anything unless there is a executive sponsor and business need/attached revenue. Probably they have never needed a maintenance mode, aka self imposed downtime. The only thing worse that unexpected downtime is some manager causing the need to turn on maintenance mode. They would lose their job.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#306

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

Or a distraction while a bigger hack is going on?

Bingo, they're probably walking away with all of Twitter's internal data as we speak...

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#307

With so many accounts compromised, the hackers might actually have full access to Twitter's backend. The postmortem would be very interesting. I'll be looking forward to it. Imagine if the hackers timed the intrusion during github outage, and twitter's employees can't deploy a fix for the exploit fast enough because github was down!

There is no way Twitter depends on Github CI/CD to push updates. I refuse to believe this.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#308
I can't imaging some of those hacked people not having extremely good security habits. 2FA, long unique ramdom-generated passwords not used anywhere else, and secured phones that would be hard to do a SIM swap on.

Which leads me to believe someone has really hacked twitter in a bad way or there's someone on the inside helping them.

Post reply on HN