Live data from Hacker News

An update on our security incident

blog.twitter.com

71–80 of 308 posts

Re: An update on our security incident

#71

How did they manipulate their employees? that's the most important part don't you think?

For sure. And how did the hackers access the Twitter backend from an unknown IP? Surely Twitter has that locked down. My guess is the hackers managed to gain access to laptops of remote support staff and controlled them with Teamviewer type software. Going remote for covid might have made this all possible.

Re: An update on our security incident

#72
post #63
post #49

> 2FA compromised This is why sending or generating a OTP, that the user types in, is not secure. The user can be tricked into handing the OTP over the phone. Even the O365 system isn't secure (because the user can be told which number to tap over the phone). The only secure authentication these days is a non-communicable possession: Yubikey or similar. This reflects *very poorly on Twitter opsec.

very poorly is a bit much. Yes yubikey would be much better, but its not exactly standard across the industry yet. For something to reflect very poorly on twitter opsec, I would expect it to be something that is below what the average tech company was doing. e.g. There was some news article claiming [Without a whole lot of evidence] that the compromised tool used a shared password that was posted as the topic of a sl…

Twitter is not an average company. As one of the top 40 internet companies, they are in the position of setting industry standards. I think it's fair to expect more than what the average company does from Twitter.

Re: An update on our security incident

#73
post #65
post #60

Earlier quoted context omitted.

Here's my suspicions. I may well be wrong, but this is what it feels like... I was wondering what kind of thing some actors (possibly state-based) were going to do this election cycle since the 2016 one (hacks of Republican and Democratic emails) worked so darn well. Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. And there's no big reason to think that the exfiltration of privat…

> Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. Nobody is communicating anything valuable over Twitter. This is such a ridiculous point that people bring up all the time. Scandalous relationships? Most of that will be on true messenger applications. Business deals? Business email. Many more mainstream prominent people don't even run their own account. It's not that everyone is…

> Nobody is communicating anything valuable over Twitter. This is such a ridiculous point that people bring up all the time. Scandalous relationships? Most of that will be on true messenger applications. Business deals? Business email. Many more mainstream prominent people don't even run their own account.

GP was talking about the 2016 election, where Julian Assange and Roger Stone literally communicated strategies, for how to coordinate if the FBI came down on Assange for the leaks, via Twitter DMs. Many things going on with no Signal, PGP, etc.

https://www.businessinsider.com/fbi-reveals-roger-stone-was-...

Re: An update on our security incident

#74
post #65
post #60

Earlier quoted context omitted.

Here's my suspicions. I may well be wrong, but this is what it feels like... I was wondering what kind of thing some actors (possibly state-based) were going to do this election cycle since the 2016 one (hacks of Republican and Democratic emails) worked so darn well. Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. And there's no big reason to think that the exfiltration of privat…

> Exfiltrating DMs seems like it's going to accomplish just about as much, if not more. Nobody is communicating anything valuable over Twitter. This is such a ridiculous point that people bring up all the time. Scandalous relationships? Most of that will be on true messenger applications. Business deals? Business email. Many more mainstream prominent people don't even run their own account. It's not that everyone is…

I don't mean this in any kind of condescending way, but I honestly think you might be in a bubble. If I was only looking at my immediate friend group, I would think the same way, as none of them use Twitter DMs at all. However, I recently met up with some old acquaintances from high school, and they use Twitter DMs and Instagram DMs as one of their main methods of communication.

There's a reason "slide into the DMs" is a saying: https://www.dictionary.com/e/slang/slide-into-the-dms/

Re: An update on our security incident

#75

Earlier quoted context omitted.

I think it likely varies on the person we're talking about. Is Obama personally tweeting and sending private memes in his DMs? Doubtful. Kanye or Elon Musk? I'd guess yes, actually.

Ah, Elon, forgot about that one. I fully believe he runs his own twitter. How else is he going to control the stock market!? ;) You’re right, I assume his would be one of the accounts that was exfil’ed

He's verified though, and they claim the only exfil'd accounts weren't.

Re: An update on our security incident

#76
post #63
post #49

> 2FA compromised This is why sending or generating a OTP, that the user types in, is not secure. The user can be tricked into handing the OTP over the phone. Even the O365 system isn't secure (because the user can be told which number to tap over the phone). The only secure authentication these days is a non-communicable possession: Yubikey or similar. This reflects *very poorly on Twitter opsec.

very poorly is a bit much. Yes yubikey would be much better, but its not exactly standard across the industry yet. For something to reflect very poorly on twitter opsec, I would expect it to be something that is below what the average tech company was doing. e.g. There was some news article claiming [Without a whole lot of evidence] that the compromised tool used a shared password that was posted as the topic of a sl…

Google has made it a requirement to use hardware keys internally since early 2017 and has noted there have been zero successful phishing attempts since. Twitter would have done the same if they had competent security staff.

Re: An update on our security incident

#77
post #4

I wish they mentioned what kind of social engineering attack it was. It could be a case study for any such incidents in the future. P.S. I feel bad for the employees who were manipulated to give away the info.

I want to know how they social engineered an employee at a 2FA-enabled company into bypassing 2FA. Was the employee able to disable 2FA for their own account? Was the employee social engineered into adding someone else's 2FA key to their account? Did the employee read a 2FA code to the attacker, and that somehow enabled all the evil things the attacker did, without any additional checks or 2FA codes? Did the attacker…

Too lazy to provide a link (sorry) but KrebsOnSecurity had some screenshots of a forum user offering up access to internal tooling. The access may have been deliberately sold, not necessarily coerced.

Re: An update on our security incident

#78

How did they manipulate their employees? that's the most important part don't you think?

I actually don't think it's as important as identifying how and why those employees were able to do things like tweet on behalf of Obama. Proper access controls would have high-profile accounts extremely locked down, ideally such that no single person could independently choose to access this info.

I understand what you are saying, but the thing is they compromised accounts of multiple employees (according to them), so I still think it's important.

Re: An update on our security incident

#79
post #9

> did the attackers see any of my private information? For the vast majority of people, we believe the answer is, no. This is such a weasel-y answer. “Yes, most of Earth’s population was not affected by this breach” - sure, but those that were affected, how would you be certain that they didn’t have their private information, such as DMs, pulled?

That's kind of a cynical take. I parsed that statement as saying: > did the attackers see any of my private information? For the vast majority of people [who we previously mentioned were affected by this hack], we believe the answer is, no.

There is no indication that the accounts whose data was accessed were the accounts which tweeted the crypto scam.

Therefore, I'm not sure that's a straightforward explanation.

Re: An update on our security incident

#80
post #69

Earlier quoted context omitted.

I think it likely varies on the person we're talking about. Is Obama personally tweeting and sending private memes in his DMs? Doubtful. Kanye or Elon Musk? I'd guess yes, actually.

Kanye West and Elon Musk have absolutely nothing of value in their DMs. Anything you could do with access to Musk's DMs you could do better just by tweeting as Musk. There is no value in Twitter DMs.

Why do you dismiss hypothetical questions out of hand, without evidence? Can one prove a negative or disprove a counterfactual statement? I just don’t know why you think that you must be right, as the actions of the hackers indicate otherwise. It’s hard to tell what is intent and what is misdirection when it comes to hacks of this nature, all the same.

> Hitchens has phrased the razor in writing as "What can be asserted without evidence can also be dismissed without evidence."

https://en.wikipedia.org/wiki/Hitchens%27s_razor

Post reply on HN