Earlier quoted context omitted.
Didn’t the hack need internal access? VPN maybe?
Sure, but if they connected to the VPN from their own IP, then that's not going to hide anything.
Tampa teen accused of being ‘mastermind’ behind Twitter hack
341–350 of 702 posts
Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack
#342Earlier quoted context omitted.
What I said was "not reversible by legal authority". That's true for both gold coins and bitcoin if the legal authority don't have them to give. I'm not saying bitcoin is less accountable and giving 6000$ in gold coins to a stranger promising to double them would only be slightly more responsible since then you'd at least know a physical jurisdiction. What I'm saying is that when bitcoin X leaves wallet Y to wallet Z…
You are not wrong but you are glossing over the fact that by "digital transactions" you seem to actually mean "transactions brokered by a third party". USD also works the way you describe. I may write someone a check based on a fraudulent premise then later demand my money back. If they have already cashed that check and run then the money is gone from their account and there is no way to reverse the transaction. The…
Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack
#343The story has been updated, three people have now been charged, the teen, a man from Orlando and a man from the UK. https://www.theverge.com/2020/7/31/21349920/twitter-hack-arr...
> Originally, “Kirk” claimed to be a Twitter employee, according to a Discord chat log So these guys were able to get into Twitter but they chatted freely on Discord without considering everything would be recorded? And then they make one of the most public hacks in recent history without considering someone would go through all the logs with all the noise they made?
It's because social engineering attacks are noisy as heck. Within 30 minutes of them posting these tweets, you can bet the FBI was already on the line with Twitter's security team.
The fact that they chose to do this attack at all demonstrates how amateur they were.
Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack
#344Earlier quoted context omitted.
From memory, I recall the FBI did a study, and found that half of their employees would plug in a USB drive that they found on the ground in the parking lot. After training, that number was reduced to a quarter. If a security-focused government police agency is so vulnerable, it is unreasonable to expect perfection from a (less paranoid) company.
>>If a security-focused government police agency is so vulnerable I think calling FBI "security-focused" is a bit too generous. They are essentially glorified police detectives, with greater authority and jurisdiction. I don't believe the average FBI agent is particularly competent, in terms of technical (i.e. computer) skill or knowledge.
Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack
#345Earlier quoted context omitted.
It means they're tracking US visitors in ways intrusive enough to be illegal in Europe, yes.
Only if you enable javascript. This is exactly equivalent to opening every email attachment you receive. It's absurd this is considered the norm. You can take individual responsibility and disable JS by default. Also, don't visit sites that you disagree with. This is much more ethical than the European choice to bring in people with guns to coerce sites into behaving how they want. It's easy to understand why interna…
First, it puts the blame on the victim. “Oh you got hacked? Should have turned off Javascript.” Stop blaming the victim. Browsers come with Javascript turned on by default and many sites expect Javascript will work, so it’s a reasonable expectation that users leave Javascript enabled.
Secondly there are a lot of devices that people access the web from. It’s not possible or easy to turn off Javascript on all platforms. If I ran my iPhone with Javascript disabled, every site I visited that needed Javascript would make me stop, go to Settings, scroll down to find Safari, scroll all the way to the bottom to find Advanced, then toggle the Javascript button. Then go back to Safari, view the site I wanted to see, then do it all over again to disable Javascript again. That’s not a reasonable workflow to even suggest.
Lastly... ah nevermind, I don’t actually want to know if you honestly believe anyone is enforcing GDPR with a gun. It’s not true in any way but it’s such a ludicrous statement that I honestly don’t even want to hear if you’re being serious or not. For my own mental health I will pretend you’re joking.
Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack
#346Probably could have earned a lot more from his exploits if he went the formal route and directly confronted Twitter. But then who even knows if Twitter are a good 'first responder' when it comes to high-profile exploits of their system. There was a recent post about some researcher who exposed flaws in Tor's architecture (which allowed third parties to detect Tor traffic easily) and Tor's staff didn't respond; so she…
Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack
#347The story has been updated, three people have now been charged, the teen, a man from Orlando and a man from the UK. https://www.theverge.com/2020/7/31/21349920/twitter-hack-arr...
> Originally, “Kirk” claimed to be a Twitter employee, according to a Discord chat log So these guys were able to get into Twitter but they chatted freely on Discord without considering everything would be recorded? And then they make one of the most public hacks in recent history without considering someone would go through all the logs with all the noise they made?
Didn't even layer the Bitcoin through an anonymiser like Monero and extra Bitcoin wallets. Just sent and received BTC directly to an account linked with photo ID on multiple exchanges. Incredible really!
Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack
#348Hitting a 17yo with 30 felony charges feels a bit steep to me. Also should any repercussions be considered against Twitter that a 17yo was able to gain access to the private messages of potentially some of the most important individuals in the world? If a 17yo could do it, I'm sure a nation state could do it.
Personally I suspect the security of the systems could be improved best over time by a radical measure of legalizing hacking and social engineering. Going after hackers is a bandaid measure. It would be unapologetically darwinistic but this domain doesn't behave the same as meatspace and imposing its assumptions on it is a mistake just as much as putting closing times on websites.
Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack
#349Earlier quoted context omitted.
The age of the attacker is irrelevant to Twitter's role in this story. However your underlying point still stands. If we want these types of attacks to stop, we can't just let all these companies off with a public embarrassment being the primary punishment. At a certain point we have to start calling it negligence when companies fall for these attacks and fail to have proper precautions in place to prevent them.
From memory, I recall the FBI did a study, and found that half of their employees would plug in a USB drive that they found on the ground in the parking lot. After training, that number was reduced to a quarter. If a security-focused government police agency is so vulnerable, it is unreasonable to expect perfection from a (less paranoid) company.
Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack
#350Earlier quoted context omitted.
Twitter is a meme service with a bunch of self absorbed individuals talking over each other... just FYI in case you lived under the rock for last 10 years.
Well, maybe it was until a certain individual started using it to conduct matters of foreign and domestic policy.