Earlier quoted context omitted.
The only calls I get any more are recruiters (80%) scammers (15%) and family 5%.
Recruiters call ? I would have expected them to use other more asynchronous methods like text or email, unless you strongly indicate a preference.
Twitter internal panel linked to account hijackings
451–460 of 477 posts
Re: Twitter internal panel linked to account hijackings
#452Its pretty amazing that realdonaldtrump@ was not a part of this. I guess the controls on that account are at an even higher level than elon musk/obama.
NYT article says that Trump's account is under special "lock and key" protection.
Re: Twitter internal panel linked to account hijackings
#453> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
i would bet that most of the places you are thinking about (banks, credit card, and so on) where you get on the phone with a rep, with a phone entry system ahead of the agent, the agent can only access that specific data during the call, the access is logged, and any other access (some other account) is flagged for review. by calling in you are granting access. most users simply don't care about privacy and extra hurdles are just asking for complaints. limiting access to specific accounts during live calls is a fair compromise and a tight control.
xero (they suck, so this is not an endorsement) requires you to give the rep access explicitly, as an option, when requesting tech support. of course i have zero doubt that senior reps can get access anyway (which would be audited), so the explicit control is more about signalling comfort to you about their security measures.
after google had the SRE stalker incident they implemented very tight access controls to user data.
i walked into a verizon store the other day to buy a hotspot. the rep could not get access to any info whatsoever (even billing status) until i acknowledged a message on my phone. it's clear they only had access to my specific data (ie, they don't get to enter any phone number and get access) for that specific interaction.
Re: Twitter internal panel linked to account hijackings
#454> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
This is simply not true. For example with banks, high-profile accounts can't be accessed by regular tellers. If someone attempts to, it is logged and someone is notified that Teller X tried to access the account.
Now that Twitter is being used for high-profile official communications, they need to re-design their employee control panels to limit, alert, and control what an employee can do with an account.
The fact that important credentials on so many high-profile verified accounts could be changed without notifying employees or locking the affected accounts until the actions are verified is unacceptable.
Re: Twitter internal panel linked to account hijackings
#455> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
* > Every customer service rep that works at any of those places can pull up info on anyone at any time. * This is simply not true. For example with banks, high-profile accounts can't be accessed by regular tellers. If someone attempts to, it is logged and someone is notified that Teller X tried to access the account. Now that Twitter is being used for high-profile official communications, they need to re-design thei…
Re: Twitter internal panel linked to account hijackings
#456Earlier quoted context omitted.
The problem is that customers don't remember basically anything. I don't know my telephone banking password for any bank. When I call, I get asked to tell them what my last transaction was, or my mother's maiden name and DOB (public info), or what town I last used my card. I've been wrong about the recent usage questions more often than I've been right, and they say "close enough". The technological measures have to…
When I bought my house a couple years ago, I had to put my signature to make a big and urgent money transfer. The bank however didn't accept my signature for some reason, though I had been using it every time with them. It appeared that normally they not really check if it matches, but this time given the transfer amount they did. And it just so happened that the signature they had scanned in their system was the fir…
Re: Twitter internal panel linked to account hijackings
#457> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…
E-government services in Estonia have nice features, aimed at giving more control to the owner of the data [1]. Among other: "It allows the Citizen to query who has accessed his/her records. [...] In Estonia, this feature has led to some very public cases of government officials being caught accessing private data of Citizens - without any legitimate and authorized reason for such access."
Re: Twitter internal panel linked to account hijackings
#458RE: social engineering, as long as a human is involved somewhere, the system can be compromised. IT security is a very depressing field because of this fact. I also hope these incidents remind people of how little control you really have over your online identity. We're all just IDs in a database somewhere, waiting to be impersonated. Decentralization is the only solution for this IMO.
Often, what people think is "good customer service" really means "allowing me to socially engineer you". I don't think there is any solution to this. "Decentralization" in this context seems equivalent to a centralized system that simply gives up on any ability to recover accounts. Whoever owns the authentication details of an account is the owner, period. If you lose the password or the account gets hacked and stole…
As far as I’m aware they didn’t even make him create a new one and he thought everything was totally fine.
It was the moment where I realized I want nothing to do with IT Management/Security in the future and am actively working to distance myself from that aspect.
Re: Twitter internal panel linked to account hijackings
#459Earlier quoted context omitted.
The problem is that customers don't remember basically anything. I don't know my telephone banking password for any bank. When I call, I get asked to tell them what my last transaction was, or my mother's maiden name and DOB (public info), or what town I last used my card. I've been wrong about the recent usage questions more often than I've been right, and they say "close enough". The technological measures have to…
This is a more general and larger problem where society is constantly bending over backwards to cater to the 2% lowest performers. If you added up all the costs of the people at the lowest extremes (by various metrics), I'd venture to guess that we could increase our prosperity (by various metric) by an order of magnitude. Example: When I started my startup, we made the decision not to hire any salesperson who wasn't…
As your parent said, it's not 2%, it's more like everyone. No one is perfect all the time.
More importantly, it's one thing when hiring, but are you seriously suggesting 2% of the population shouldn't be able to use Twitter or online banking or other online services? 140,000,000 people should effectively face social death because you can't be fucked to help them?
This is backwards, we should be sacrificing profits and convenience to be more inclusive.
Re: Twitter internal panel linked to account hijackings
#460Earlier quoted context omitted.
Regarding #1, my thinking was this is China or their allied nations (North Korea, Iran etc). The US has taken extremely forceful steps on China in the last couple of days. This could be their response; discrediting a huge piece of the American crown jewels (big tech companies) and making it a laughing stock. Just the massive blast radius of the hack reminded me of the NK Sony hack and release of documents. Big up you…
I would expect state actors to have gone for a lot more damage than "make Twitter look stupid". Also, all the high-profile state actor hacks I'm aware of were a lot more clandestine - it was months before they were discovered. State actors are highly professional, they're in it for the long haul, and they do serious damage. The "massive blast radius" of this hack lies more in the damage it could have done, rather tha…
Remember when Twitter fact checked those Trump tweets?
Trump is the type of petty person to not let something like this go.