Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

441–450 of 477 posts

Re: Twitter internal panel linked to account hijackings

#441
post #417
post #395

Earlier quoted context omitted.

The problem is that customers don't remember basically anything. I don't know my telephone banking password for any bank. When I call, I get asked to tell them what my last transaction was, or my mother's maiden name and DOB (public info), or what town I last used my card. I've been wrong about the recent usage questions more often than I've been right, and they say "close enough". The technological measures have to…

When I bought my house a couple years ago, I had to put my signature to make a big and urgent money transfer. The bank however didn't accept my signature for some reason, though I had been using it every time with them. It appeared that normally they not really check if it matches, but this time given the transfer amount they did. And it just so happened that the signature they had scanned in their system was the fir…

> The sale went through, luckily, and immediately after I ditched that bank account.

I believe most banks allow their customers to change their signature to something they can replicate more consistently — but it probably relies on showing up to a branch and producing sufficient ID.

Re: Twitter internal panel linked to account hijackings

#442
post #431

Earlier quoted context omitted.

Whenever I call into E*Trade, first they send me a text with a code. They can't see the code, they just get a box and have to enter in the code I give them and it tells them if they are right. Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do. So a random customer service rep couldn't access my account without my phone in their hand, even if they managed t…

I’ve long considered why apps don’t have some VOIP client in them; if one can Face ID into their account, and use the VOIP client to connect to a rep - then the metadata associated with the call can inform the rep you are who you say you are. Seems E* is almost there!

I may be wrong, but Face ID should be performed entirely in the SEP, and only returns a boolean.

Re: Twitter internal panel linked to account hijackings

#443
post #17

> Hawley said "please reach out immediately to the Department of Justice and the Federal Bureau of Investigation and take any necessary measures to secure the site before this breach expands It's kind of bizarre when you have the highest levels of government doing their critical communication on a free social media service to the point where they are critically dependent on it, then begging for support when things go…

The next time we swing the other way: "Maybe government should embrace popular communication media instead of spending billions on custom IT infrastructure to post a message on a custom page that everyone screenshots and copies to their timeline anyway." (Also if they don't create an "official account", someone else will do it for them)

I don't know, it'd probably take 18F like a month to add a page to whitehouse.gov called "Things the President said", add 2FA and whatever else it needs to be installed on his government phone, and a little bot that listens for whenever he writes something on there and tweets it on Twitter. Then you have a source of truth that we know wasn't modified between the government and the reader, and it doesn't break the social following.

But I guess its easier to just complain about Twitter.

Re: Twitter internal panel linked to account hijackings

#444
post #438
post #435

Earlier quoted context omitted.

For reasons I cannot fully remember my voicemail broke many years ago. It goes something like: I’d switched to google voice for vm, where T-Mobile handled my line generally. Then google did something to google voice, some sort of discontinuation + merging with gmail and my vm broke. This occurred in tandem with me moving to a house with terrible cell reception and before wide spread WiFi calling support. The result w…

The only calls I get any more are recruiters (80%) scammers (15%) and family 5%.

My family texts me (whatsapp) asking if/when they can call me.

Re: Twitter internal panel linked to account hijackings

#445
post #403

Earlier quoted context omitted.

You don't think part of the reason they don't have customer service is that the # of people they'd have to employ is huge?

They do have customer service, if you pay for their premium service Google One. They also have support agents for YouTube creators above a certain subscriber threshold.

Yeah that sure as hell makes it sound like the reasons for having or not having customer support are economic in nature.

Re: Twitter internal panel linked to account hijackings

#446

Earlier quoted context omitted.

I think there are three possible explanations here: 1- (Tinfoil hats please) This is a state owned attack, which is a retaliation from US Government to ruin Twitter's credibility and introduce social media regulations. 2- The hackers are gray hat hackers, who know that reporting this vulnerability will not make them any money and they want to get what they think they deserve, so they make it public and get some good…

Another option is that the BTC was nothing but proof that they compromised those accounts. They had full access to the compromised accounts including any private messages. Now there is public proof that they compromised those accounts and a BTC account they can send funds from to prove it is the same group. This allows them to sell those private DMs along with proof of authenticity.

This possibility makes quite a bit of sense to me. It explains why the attackers went to so much trouble, given that world leader and major CEO DMs could be quite valuable, while also explaining why they bothered with the seemingly trivial crypto scam.

Re: Twitter internal panel linked to account hijackings

#447
post #446

Earlier quoted context omitted.

Another option is that the BTC was nothing but proof that they compromised those accounts. They had full access to the compromised accounts including any private messages. Now there is public proof that they compromised those accounts and a BTC account they can send funds from to prove it is the same group. This allows them to sell those private DMs along with proof of authenticity.

This possibility makes quite a bit of sense to me. It explains why the attackers went to so much trouble, given that world leader and major CEO DMs could be quite valuable, while also explaining why they bothered with the seemingly trivial crypto scam.

They also don't even need incriminating DMs, they can release fake DMs and use the BTC address to prove "authenticity" to the media. Released at the right time that could be quiet valuable to certain people.

Re: Twitter internal panel linked to account hijackings

#448

Earlier quoted context omitted.

It would be pretty easy. You could just post on reddit or 4chan and ask "If you could make anyone on Twitter post anything, what's the most you could earn?" And people who know a lot about a lot of things would give you ideas. It's just not smart to use the hack for just this. Example: Contact Trump's kids. Demonstrate your power. Tell them you'll make Joe Biden tweet "8 year old girl nude hair" at a time of their ch…

> Example: Contact Trump's kids. Demonstrate your power. Tell them you'll make Joe Biden tweet "8 year old girl nude hair" at a time of their choosing, in exchange for 5 million BTC held in escrow. This doesn't require anything more than knowing that Trump is rich and corrupt and that Biden is his opponent. And then you get tracked down and killed by a three-letter agency. I think people underestimate how risk-free r…

> I think people underestimate how risk-free receiving small amounts of btc from random schmucks is,

I agree with this

> and how risk-averse these hackers may be.

And I agree with this statement in most cases, but not in this particular one. The wide spread and super high profile nature of this attack makes it a high risk play no matter what. Being cautious when it comes time to collecting the loot seems like too little too late for them to get away easily.

Re: Twitter internal panel linked to account hijackings

#449
post #438
post #435

Earlier quoted context omitted.

For reasons I cannot fully remember my voicemail broke many years ago. It goes something like: I’d switched to google voice for vm, where T-Mobile handled my line generally. Then google did something to google voice, some sort of discontinuation + merging with gmail and my vm broke. This occurred in tandem with me moving to a house with terrible cell reception and before wide spread WiFi calling support. The result w…

The only calls I get any more are recruiters (80%) scammers (15%) and family 5%.

Recruiters call? I would have expected them to use other more asynchronous methods like text or email, unless you strongly indicate a preference.

Re: Twitter internal panel linked to account hijackings

#450

Earlier quoted context omitted.

Also ensuring that a hacker can get the 2FA token directly from the owner by pretending to be customer service...

In this case it sounds like the user is calling ETrade, so unless the user calls a wrong number that just so happens to be a hacker it's unlikely this would be an issue.

[deleted]
Post reply on HN