Earlier quoted context omitted.
I'm no lawyer either, but I imagine that the definition of authorisation is key here. If you're a sysadmin on a company email system, then you do technically have access to everyone's data on that system. However, you're generally limited by company policy that you are not permitted to access/modify that data without direct authorisation, say from the employee themselves or from HR. So, therefore, if you go and read…
But that's gross misconduct or some other fireable offense - a civil matter at best. The only item I can see here is fraud (impersonating the people whose accounts have been taken over), of which the mole would be complicit.
Twitter internal panel linked to account hijackings
391–400 of 477 posts
Re: Twitter internal panel linked to account hijackings
#392Is nobody bothered by the shadow-banning? "Trends blacklist" and "Search blacklist"? Talk about transparency...
Re: Twitter internal panel linked to account hijackings
#393Earlier quoted context omitted.
Imagine the potential damage if an attacker tweeted something on behalf of the US President (let's say Biden in 2022), that China or Iran or Russia ships could be sunk at any moment if they didn't withdraw (due to some ongoing real incident)... The other side might fire on US ships before the tweet could be corrected. Twitter is a disaster waiting to happen.
Right, because all these other parties would totally not think Twitter might be hacked? I'm truly baffled by this kind of hysteria.
Re: Twitter internal panel linked to account hijackings
#394> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
AT&T claims my security PIN will prevent agents and in store associates from accessing my account. The store rep said there’s no way for him to help me doing anything until we called a special hotline to give my PIN and approval. Doesn’t mean there isn’t a way around it for some reps with special access. If you don’t have a PIN someone can go and open up multiple new accounts separate from your primary account in you…
Re: Twitter internal panel linked to account hijackings
#395> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
The technological measures have to account for human behaviour. Otherwise you just end up with almost everyone not being able to access almost everything almost all of the time. People are forgetful, irrational, stubborn and stupid. So are institutions. Put them together and you have a social engineering dream world (literally our current world).
Re: Twitter internal panel linked to account hijackings
#396> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
I work in banking. You’d be amazed at how serious the information and enterprise architecture is around PII and confidential data.
Re: Twitter internal panel linked to account hijackings
#397> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
This is why IMO Google has almost no customer service. Their weakest attack vector would be people. Imagine paying your infosec employees hundreds of thousands a year to protect your clients data. Next to them (in terms of data access) is your customer service team at $30,000 per head. Which team is easier to crack?
Re: Twitter internal panel linked to account hijackings
#398Earlier quoted context omitted.
Make sure that even with a hacked SIM a malicious CSR can't access your account without your knowledge.
Also ensuring that a hacker can get the 2FA token directly from the owner by pretending to be customer service...
Re: Twitter internal panel linked to account hijackings
#399> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
Yup. Doubly so for sysadmins, many of which have abhorrent data security practices.
My personal solution is to use cover names, disposable phone numbers, and unique email addresses (the + trick is insufficient) for most services. My assumption is that the data is eventually either going to leak, or be used to threaten or harm me in some way.
If none of the PII overlaps with me, it becomes a lot harder for such an event to affect me.
The only downside is that sometimes you get companies (Airbnb, Instacart, some others) that have CSRs that demand a government photo ID to do certain tasks. Of course I don’t have any documents for these cover names, so usually the workaround is to just abandon that account, make another, and re-place the order or transaction in a way that doesn’t flag it for manual review/intervention.
Works pretty well for me most of the time.
Re: Twitter internal panel linked to account hijackings
#400To me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisti…
I think there are three possible explanations here: 1- (Tinfoil hats please) This is a state owned attack, which is a retaliation from US Government to ruin Twitter's credibility and introduce social media regulations. 2- The hackers are gray hat hackers, who know that reporting this vulnerability will not make them any money and they want to get what they think they deserve, so they make it public and get some good…