How did they manipulate their employees? that's the most important part don't you think?
An update on our security incident
71–80 of 308 posts
Re: An update on our security incident
#72> 2FA compromised This is why sending or generating a OTP, that the user types in, is not secure. The user can be tricked into handing the OTP over the phone. Even the O365 system isn't secure (because the user can be told which number to tap over the phone). The only secure authentication these days is a non-communicable possession: Yubikey or similar. This reflects *very poorly on Twitter opsec.
very poorly is a bit much. Yes yubikey would be much better, but its not exactly standard across the industry yet. For something to reflect very poorly on twitter opsec, I would expect it to be something that is below what the average tech company was doing. e.g. There was some news article claiming [Without a whole lot of evidence] that the compromised tool used a shared password that was posted as the topic of a sl…
Re: An update on our security incident
#73Earlier quoted context omitted.
Here's my suspicions. I may well be wrong, but this is what it feels like... I was wondering what kind of thing some actors (possibly state-based) were going to do this election cycle since the 2016 one (hacks of Republican and Democratic emails) worked so darn well. Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. And there's no big reason to think that the exfiltration of privat…
> Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. Nobody is communicating anything valuable over Twitter. This is such a ridiculous point that people bring up all the time. Scandalous relationships? Most of that will be on true messenger applications. Business deals? Business email. Many more mainstream prominent people don't even run their own account. It's not that everyone is…
GP was talking about the 2016 election, where Julian Assange and Roger Stone literally communicated strategies, for how to coordinate if the FBI came down on Assange for the leaks, via Twitter DMs. Many things going on with no Signal, PGP, etc.
https://www.businessinsider.com/fbi-reveals-roger-stone-was-...
Re: An update on our security incident
#74Earlier quoted context omitted.
Here's my suspicions. I may well be wrong, but this is what it feels like... I was wondering what kind of thing some actors (possibly state-based) were going to do this election cycle since the 2016 one (hacks of Republican and Democratic emails) worked so darn well. Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. And there's no big reason to think that the exfiltration of privat…
> Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. Nobody is communicating anything valuable over Twitter. This is such a ridiculous point that people bring up all the time. Scandalous relationships? Most of that will be on true messenger applications. Business deals? Business email. Many more mainstream prominent people don't even run their own account. It's not that everyone is…
There's a reason "slide into the DMs" is a saying: https://www.dictionary.com/e/slang/slide-into-the-dms/
Re: An update on our security incident
#75Earlier quoted context omitted.
I think it likely varies on the person we're talking about. Is Obama personally tweeting and sending private memes in his DMs? Doubtful. Kanye or Elon Musk? I'd guess yes, actually.
Ah, Elon, forgot about that one. I fully believe he runs his own twitter. How else is he going to control the stock market!? ;) You’re right, I assume his would be one of the accounts that was exfil’ed
Re: An update on our security incident
#76> 2FA compromised This is why sending or generating a OTP, that the user types in, is not secure. The user can be tricked into handing the OTP over the phone. Even the O365 system isn't secure (because the user can be told which number to tap over the phone). The only secure authentication these days is a non-communicable possession: Yubikey or similar. This reflects *very poorly on Twitter opsec.
very poorly is a bit much. Yes yubikey would be much better, but its not exactly standard across the industry yet. For something to reflect very poorly on twitter opsec, I would expect it to be something that is below what the average tech company was doing. e.g. There was some news article claiming [Without a whole lot of evidence] that the compromised tool used a shared password that was posted as the topic of a sl…
Re: An update on our security incident
#77I wish they mentioned what kind of social engineering attack it was. It could be a case study for any such incidents in the future. P.S. I feel bad for the employees who were manipulated to give away the info.
I want to know how they social engineered an employee at a 2FA-enabled company into bypassing 2FA. Was the employee able to disable 2FA for their own account? Was the employee social engineered into adding someone else's 2FA key to their account? Did the employee read a 2FA code to the attacker, and that somehow enabled all the evil things the attacker did, without any additional checks or 2FA codes? Did the attacker…
Re: An update on our security incident
#78How did they manipulate their employees? that's the most important part don't you think?
I actually don't think it's as important as identifying how and why those employees were able to do things like tweet on behalf of Obama. Proper access controls would have high-profile accounts extremely locked down, ideally such that no single person could independently choose to access this info.
Re: An update on our security incident
#79> did the attackers see any of my private information? For the vast majority of people, we believe the answer is, no. This is such a weasel-y answer. “Yes, most of Earth’s population was not affected by this breach” - sure, but those that were affected, how would you be certain that they didn’t have their private information, such as DMs, pulled?
That's kind of a cynical take. I parsed that statement as saying: > did the attackers see any of my private information? For the vast majority of people [who we previously mentioned were affected by this hack], we believe the answer is, no.
Therefore, I'm not sure that's a straightforward explanation.
Re: An update on our security incident
#80Earlier quoted context omitted.
I think it likely varies on the person we're talking about. Is Obama personally tweeting and sending private memes in his DMs? Doubtful. Kanye or Elon Musk? I'd guess yes, actually.
Kanye West and Elon Musk have absolutely nothing of value in their DMs. Anything you could do with access to Musk's DMs you could do better just by tweeting as Musk. There is no value in Twitter DMs.
> Hitchens has phrased the razor in writing as "What can be asserted without evidence can also be dismissed without evidence."