Live data from Hacker News

Hackers take over prominent Twitter accounts in simultaneous attack

coindesk.com

541–550 of 1001 posts

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#541

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

I’m guessing DMs were the real loot. The public display with the BTC diversion validates any DMs that were stolen. Otherwise blackmail targets could deny them.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#542

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

This.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#544
post #524

Earlier quoted context omitted.

If they had full access to Twitter’s backend, they probably would be tweeting from accounts like @POTUS or @jack. But this seems like they have access to limited accounts. Most likely gained access to a third party service that allows you to manage your tweets? Edit: they tweeted from the twitter support account. Just wow. They might have actually gotten into Twitter’s systems. Edit 2: To expand on my edit above, I s…

Can you clarify your edit? All I see is this tweet ( https://twitter.com/TwitterSupport/status/128351803844522393... ) which reads We are aware of a security incident impacting accounts on Twitter. We are investigating and taking steps to fix it. We will update everyone shortly. Are you implying that this was tweeted by the attackers? or something else?

I edited my comment, but basically I saw tweets that showed a screenshot of the scam tweet from the twitter support account. Not sure if it’s real since they delete the scam tweets.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#545
post #256

What blows my mind is how does Twitter not have a "maintenance" mode -- where no new tweets can be posted and the site is essentially read-only?

As others in the thread have pointed out it has been pressed now, users with blue checkmarks can currently not post anything.

Edit: They have just enabled posting again.

Edit Edit: Or maybe not.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#546

Posts stopped for the other btc address (bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh) Here's a tweet from KimKardashian, for a different BTC address (bc1qwr30ddc04zqp878c0evdrqfx564mmf0dy2w39l) https://twitter.com/KimKardashian/status/1283523054874877953

How can it be still up after so much time? The response time from the SREs is extremely bad.

IKR? We expected so much more from anything Kardashian

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#547
post #256

What blows my mind is how does Twitter not have a "maintenance" mode -- where no new tweets can be posted and the site is essentially read-only?

Corporations don't do anything unless there is a executive sponsor and business need/attached revenue. Probably they have never needed a maintenance mode, aka self imposed downtime. The only thing worse that unexpected downtime is some manager causing the need to turn on maintenance mode. They would lose their job.

We had maintenance mode at MySpace. We could shutdown any part of the site with feature flags that can be turned on for ranges of users. Very useful for bringing back the site after an outage and allow the caches to fill without overloading the underlying dbs. I am sure twitter has the same, they had scalability issues at the beginning . I guarantee they have a mode to disable posts and mode to disable authentication so they can recover the underlying systems .

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#548

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

I think its mostly test of miners - prominent group of tech-related personas have been hacked, so I wonder if they end up asking miners not to validate/approve the list of incoming/outgoing transactions. If they choose to minimize priority of this transactions, they may get delayed over 14 days and eventually fell off a block as never processed bitcoins. Then spender gets their money back. In 14 days they may realize…

If I were a miner now, I would not reverse these transactions.

Setting the precident that transactions can be reversed will do more harm to the crypto ecosystem than than $100k being taken from gullible users.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#550

Earlier quoted context omitted.

Betting on inside / direct database access or admin account.

Well then we're royally fucked if all it takes is a single rogue admin at this single, societally ubiquitous company to expose everything and let people fire off false declarations of war on each other or short TSLA and additionally make the entire concept of 2FA meaningless . This was exactly what 2FA was supposed to prevent, and if this is to be believed then because of Twitter's implementation it was all worth pea…

You seem to be greatly overestimating the level of security at most internet companies. I suspect most companies, even some of the huge tech giants, would be susceptible to a sufficiently privileged rogue admin. Heck, the entire NSA had huge amounts of their most sensitive data accessed by a rogue admin contractor.
Post reply on HN