Live data from Hacker News

Hackers take over prominent Twitter accounts in simultaneous attack

coindesk.com

661–670 of 1001 posts

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#661

Tweet from TwitterDev team yesterday: https://twitter.com/TwitterDev/status/1283068902331817990 > 2 days to go… #TwitterAPI https://twitter.com/TwitterDev/status/1283433096780677122 > Thank you to all of you who have engaged with us and shared your feedback. Your input has been vital, and we’re committed to continuing these conversations with you. There’s so much more we’re doing to build a better #TwitterAPI… and Ea…

Or someone making one last use of an exploit on the old API, since ostensibly there is a day to go before the new API is released on the public net.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#662

Earlier quoted context omitted.

And it seems that it's still compromised. Tweets get deleted and then they re-appear.

30 minutes later and it still happens, just after "Elon" posted a normal message. Hopefully most users have caught on to the scam by now.

Crazy twitter can’t pin a warning to everyone’s feed... or just kill the site.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#663

Earlier quoted context omitted.

It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.

But then why set up a rather simply scam instead of getting the bug bounty from twitter? That wallet is currently sitting at about 150k USD and these are rather hard to pay out. Why not just go for 100k USD bug bounty, completely legal and with fame?

Some men aren’t looking for anything logical.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#664

Are very high profile accounts (like Trump) more secure than a usual password + 2FA, somehow ? EDIT: Not that it would matter here. Just curious.

Someone on here said Twitter set up some special security for just his account

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#665
post #617

Hackers still actively tweeting out from everyone's accounts https://twitter.com/search?q=All%20Bitcoin%20sent%20to%20the...

is it just me or are they now mass altering users' names? https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...

Not sure if the hackers are doing that or people are just trying to get attention from the search results

e.g. tweets like this look like people are consciously looking for attention: https://twitter.com/Statist_Sam/status/1283533522536411136

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#666
post #393

This is what happens when you put all of your communication eggs into a single basket. Twitter needed to be taken down a couple of pegs. I think accounts of a high enough profile may want to closely examine the ActivityPub ecosystem.

We had a decentralized system before. It was called the mainstream medias. But they lost so much trust from the public that now we turn to social medias.

Ah yes the lame stream media. Which such huge gaffes such as......

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#667
post #256

What blows my mind is how does Twitter not have a "maintenance" mode -- where no new tweets can be posted and the site is essentially read-only?

What if the attackers disabled this? Unlikely, but still worth considering when designing a maintenance mode...

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#669
I was thinking the other day about a digital signature for limited character tweets.

Provided I’m not a cryptography expert and you should explore my ideas with caution, why not even just sign every tweet with an ed25519 signature? It’s on 64 bytes tacked onto the message and easy to verify...

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#670

With so many accounts compromised, the hackers might actually have full access to Twitter's backend. The postmortem would be very interesting. I'll be looking forward to it. Imagine if the hackers timed the intrusion during github outage, and twitter's employees can't deploy a fix for the exploit fast enough because github was down!

Selfhost. If you rely on Github for your service you are rightfully doomed.
Post reply on HN