Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

401–410 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#401

Earlier quoted context omitted.

This is true I think. Twitter is mostly a US thing

Consider your biases. 80% of twitter users are outside the US [0], [1]. [0]: https://www.statista.com/statistics/274565/monthly-active-in... [1]: https://www.omnicoreagency.com/twitter-statistics/

True, 60% of those are Russian bots. /s

Re: Who’s behind Wednesday’s epic Twitter hack?

#402
post #343

Earlier quoted context omitted.

many of the affected accounts had 2fa.

GP was saying "to post anything", not only to authenticate.

Good point.

This would potentially add a lot of friction for those users, but maybe that is a fine thing.

Unless we hear more details, it sounds like this attack was able to get around the 2fa for the authentication, so it seems likely they could get around it for posting. Not sure how much would be added with this 2nd level 2fa.

Re: Who’s behind Wednesday’s epic Twitter hack?

#403

I'm sure it's been said before, but I just continue to be surprised that the admin panel used to carry out this attack wasn't locked behind a VPN. I've worked for multiple fully-remote companies that were easily able to protect tools like this from the outside world. The company I currently work for (fully remote) has tons of internal services that our engineers (who we trust) can access as needed in order to debug p…

Using VPN as a layer of security is basically like 2FA, where the second factor are credentials to enter the VPN. Wouldn't it be easier to just have any other additional factor, like a physical security key, or some (additional) authenticator mobile app?

Entering a VPN is usually multi factor by default, because you need both a certificate and a login. Also, there's often a token as a third factor. So you're adding many more levels of security that way.

Re: Who’s behind Wednesday’s epic Twitter hack?

#404
post #283

Earlier quoted context omitted.

If this indeed had happened, I wonder how it would have played out. It would not be pretty, that is for sure.

Well let’s see...since all countries with ICBMs also have technology in place to detect or verify via satellite a nuclear launch, absolutely nothing would happen. If a real launch had taken place, they would have known about it far before they heard about a post on Twitter. The alarmism here on HN is really disappointing. This is the kind of foolishness usually reserved for Reddit.

"absolutely nothing would happen"

With tensions already high and military maneuvers are beeing held closes to each other ... such a twitter comment for sure would have had an effect.

No one would have pushed any red button because of that, but fighter jets on both sides would have been put on alarm and in the air and close to each other(as well as submarines, warships, tanks on the border..) , with a high chance of clashes. Which could have increased the escalation to the point, that someone would feel forced to put the red button.

Re: Who’s behind Wednesday’s epic Twitter hack?

#405

Earlier quoted context omitted.

This is true I think. Twitter is mostly a US thing

Consider your biases. 80% of twitter users are outside the US [0], [1]. [0]: https://www.statista.com/statistics/274565/monthly-active-in... [1]: https://www.omnicoreagency.com/twitter-statistics/

Speaking of biases, English-speaking twitter is a powervul vector bringing US biases (whatever they are) through the world.

I have to regularly stop and check that "ha, yes, that's a very USA-centric take on things and does not represent reality outside of it".

Re: Who’s behind Wednesday’s epic Twitter hack?

#406
post #274

The thing I'm most concerned about is that if Brian Krebs is right and they had access to their DM's, that the very obvious crypto scam they ran was just a facade, some kind of distraction because they knew they would have been noticed, but the true goal were the DM's. Imagine a celebrity saying some 'not so politically correct' things to a friend in private 8 years ago, and now imagine this becoming public while the…

Why are you so concerned about some celebs being called out on stuff they said? To me, the most concerning is innocent people having lost money to a scammer, not some celebrity's public image being hurt by something they actually wrote.

Re: Who’s behind Wednesday’s epic Twitter hack?

#407

Earlier quoted context omitted.

While I am 10000% onboard with decentralizing communication, I am not sure if that would help in cases like this though. Back in 2013, only a single news outlet AP's twitter was hacked and had similar consequences. Decentralizing wouldn't have helped there I think.

Signing the message would be but who uses that nonsense right

Then you need to make sure people cannot under any circumstances be sloppy with securing private keys, since once they can, some important people will, and then such things happen again, any maybe they'll have actual consequences, people die, markets collapse, economies collapse, wars break out ...

And then? Doing damage control on a fake post by the CEO of Supercorp saying they're faltering financially, or whatever, when it has that green badge of crypto-authenticity, and you've spun your marketing in such a way to tell people "if that's there, it is 100% authentic, just look for that badge" ... that would be a nightmare. It's an issue with "verified" already, but cryptography is essentially magic; many in tech believe they get the nuances but don't really, and most outside of tech don't even begin to get the nuances. Would that damage people's trust in cryptography in general? Maybe?

After all, most people don't know, understand and/or care that their Whatsapp E2E is effectively broken for police and similar actors when they enable backups, because most people care about the details of these things about as much as I care about the exact things my hairdresser does to make my hair look good, which is pretty much not at all unless they want to use a chainsaw or something. If that were to be abused in a major way, that'd probably make big headlines.

I don't think that, at this point, cryptography is even generally helpful with fundamentally social problems like these, because it tends to be incredibly hard to build a product and UX around it that works for everyone and fails in a way that is somewhat understandable and actionable – the amount of work that HTTPS has required and still requires to mostly get there has been and still is huge.

Re: Who’s behind Wednesday’s epic Twitter hack?

#408

Earlier quoted context omitted.

People keep saying it could have started a war. Excuse me for being naive but come on—really? This is total sensationalism. What party wouldn’t verify something on twitter through diplomatic channels before going to war? Equity destruction: sure. War: no way.

Exactly! Nothing major could have come out of this. If you disagree, please let me try to convince you; Tweets were about bitcoin, therefore broad public was not the target of the attack. Hence Twitter just prevented verified accounts from posting and deleted some messages. Had president's account been hijacked and threats of imminent nuclear strike etc. were thrown around, DoD would have been quick to contact to Twi…

> Tweets were about bitcoin, therefore broad public was not the target of the attack.

No. Bitcoin was used because it's the only way to get money without being tracked (hence why drug dealers and even hitmen use it).

The rest of your argument is all speculation. Nobody knows what would've happened, so you can't convince anyone you're right, just like no one can convince you you're wrong.

I will just say that with the current distrust of Russia/China and in recent years, the US becoming an "unreliable" ally for Europe, a few tweets from a President and perhaps some other senior members of Government could easily have started a disastrous series of events (if unlikely to cause war directly).

Re: Who’s behind Wednesday’s epic Twitter hack?

#409
post #303

Earlier quoted context omitted.

Really stupid question. A key employee leaves, with their personal 2FA. Is there a standardized corporate solution for this yet? Sorry if that’s weirdly worded

There are various vendor products that support automated deprovisioning when an employee is terminated in the master HR system. You're 1000x more likely to see them in a corporate setting than a startup.

My previous startup had a bit of both. My access to things like mail and Atlassian stuff was automatically revoked, while I could still access the production database months later.

Re: Who’s behind Wednesday’s epic Twitter hack?

#410

Earlier quoted context omitted.

Here's how I think it could be done: Get Trump's account, and tweet something like, "I've ordered a NUCLEAR STRIKE on China! The missiles are already in the air. The DEEP STATE is trying to take me out. They will try to silence me and delete these tweets and use deep fakes to say this was a hoax! The storm is here, Q is real, it's time to take up arms and kill democrats." Then continue tweeting escalating things over…

That already happened, back in 1984. President Reagan was joking during a sound check, and said the following: > My fellow Americans, I'm pleased to tell you today that I've signed legislation that will outlaw Russia forever. We begin bombing in five minutes.

As dumb as Reagan was it was so out of character for him to say that that people clued in to it being a joke. In Trump's case it is not so far out that it might be believed.

Conspiracy nuts don't need much to set them off, see 'pizzagate'.

Post reply on HN