Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

401–410 of 477 posts

Re: Twitter internal panel linked to account hijackings

#401

Earlier quoted context omitted.

The rep can perform a password reset and/or change the sms/email pair and then attackers can do the rest and make the posts themselves.

One rep does password resets for scores of high value accounts?

There are probably other factors involved, like access to other information used for MFA and compromising those mediums or using information related to them to assume identity.

Re: Twitter internal panel linked to account hijackings

#402

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

Such measures are theoretically mandated under GDPR if you have >50 employees. I'm not sure how that looks like in practice though.

Re: Twitter internal panel linked to account hijackings

#403
post #383

Earlier quoted context omitted.

This is why IMO Google has almost no customer service. Their weakest attack vector would be people. Imagine paying your infosec employees hundreds of thousands a year to protect your clients data. Next to them (in terms of data access) is your customer service team at $30,000 per head. Which team is easier to crack?

You don't think part of the reason they don't have customer service is that the # of people they'd have to employ is huge?

They do have customer service, if you pay for their premium service Google One. They also have support agents for YouTube creators above a certain subscriber threshold.

Re: Twitter internal panel linked to account hijackings

#404
post #383

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

This is why IMO Google has almost no customer service. Their weakest attack vector would be people. Imagine paying your infosec employees hundreds of thousands a year to protect your clients data. Next to them (in terms of data access) is your customer service team at $30,000 per head. Which team is easier to crack?

I find it very hard to believe that the "real" reason for Google's shitty customer service is that it's for our own good.

Re: Twitter internal panel linked to account hijackings

#405

Earlier quoted context omitted.

Here[0] are the supposed pics of the admin panel the hackers accessed. Assuming their legit, it seems like Twitter has some blacklist features. Can't find any info detailing how they exactly work, but it seems an admin can blacklist a user from the trending page or from search results. Pretty interesting. Oddly enough, posting the screenshots resulted in some users getting their account suspended or Twitter pulling t…

This could end up being a big deal in the days to come if legitimate. Twitter has made strong public statements that they don't have shadow banning tools[0]. Apparently sworn statements have been made about this. [0]: https://blog.twitter.com/en_us/topics/company/2018/Setting-t...

I'm sure they've publicly spoken about also having search and trending blacklisting, I've heard about it before. So these statements are not incompatible.

Re: Twitter internal panel linked to account hijackings

#406

Earlier quoted context omitted.

Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right. Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do. So a random customer service rep couldn't access my account without my phone in their hand, even if they managed t…

What happens when you forget your code and lose your phone ?

I dunno but I have been unable to get back my Gmail account after changing phone numbers, and unable to change email on Netflix account after credit card I used to open account expired.

Re: Twitter internal panel linked to account hijackings

#407

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

I have worked on controls in this area for a few US health insurance companies.

From what I have seen, it is common to have additional restrictions on accessing high profile individuals and specific groups data. There is also a ton of auditing around this stuff.

It is more primitive than what you described, but things are heading in that direction. It is a somewhat harder problem space because many parties need access to a customer's records in that domain.

Ultimately, the only reason things are even this far along in health insurance is the regulatory environment. It'd be nice to have stronger privacy laws that compel companies to build good controls.

Re: Twitter internal panel linked to account hijackings

#408
post #229

Why have employees have the ability to do anything with accounts except closing them?

Apparently admins could post only on behalf of bluechecks. I still can't think of a reason why they would need to create posts. Edit maybe, but create? Why? Of course with access to the database anything at all can be done, but this was apparently an explicit feature of the admin dashboard.

Source? This is the first I've heard of the dashboard allowing for post creation.

Re: Twitter internal panel linked to account hijackings

#409
post #243

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

> I'd like to see a system where it is physically impossible for a customer service rep to discover any info about me until I authenticate and authorize it. Isn't this the objective of Tim Berners-Lee Solid Project and their Personal Online Data storage (PODs) in the spec? https://solidproject.org

No. POD is about who you share with, not what happens after you share.
Post reply on HN