Hackers take over prominent Twitter accounts in simultaneous attack
711–720 of 1001 posts
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#712With so many accounts compromised, the hackers might actually have full access to Twitter's backend. The postmortem would be very interesting. I'll be looking forward to it. Imagine if the hackers timed the intrusion during github outage, and twitter's employees can't deploy a fix for the exploit fast enough because github was down!
If they had full access to Twitter’s backend, they probably would be tweeting from accounts like @POTUS or @jack. But this seems like they have access to limited accounts. Most likely gained access to a third party service that allows you to manage your tweets? Edit: they tweeted from the twitter support account. Just wow. They might have actually gotten into Twitter’s systems. Edit 2: To expand on my edit above, I s…
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#713Earlier quoted context omitted.
Quite possibly this isn't a hack and someone got a Twitter admin's account, then got access to the admin panel and "all" accounts without having to hack much of anything.
If there is such a level of privilege in Twitter's stack, that says a great deal about their technology. Insiders must not be able to act as users except in prescribed ways requiring two-person control, logged and 100% audited. Glass-breaking privilege escalation should set off every pager in the company.
In my understanding once you remove all the layers of abstraction as some point it's a bunch of databases and data stores. Someone has to manage them. Why wouldn't a breach of those users be able to do whatever they want?
And a higher level, someone is writing the code to implement such a stringent access system. Why wouldn't a breach of those users (or a rogue employee) be able to accomplish bad things?
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#714Re: Hackers take over prominent Twitter accounts in simultaneous attack
#715Is the attack now changing usernames to the BTC address or are these people just trolling? https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#716Earlier quoted context omitted.
Even worse? How about POTUS declares war on China thru twitter? OMG, I just realized how dumb that would have been to say back in 2016. But these days?
This hack could absolutely get people killed. There are several tweets I can think of from POTUS that would begin immediate military mobilization from an unfriendly country.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#717Earlier quoted context omitted.
It can‘t really be the first three, because Twitter will fix this problem soon. So it would be wasting the exploit. It‘s either incompetence or your fourth option.
I read about this in the news before I saw it in my Twitter feed. My trust in Twitter has dropped severely. Why weren’t these tweets deleted immediately and a note pinned to every users feed?
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#718Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.
Quite possibly this isn't a hack and someone got a Twitter admin's account, then got access to the admin panel and "all" accounts without having to hack much of anything.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#719Re: Hackers take over prominent Twitter accounts in simultaneous attack
#720Is it just me, or does this seem suspiciously poorly thought out? Perhaps there is a second stage involving stock plays. The BTC thing might be a diversion. Or we are incredibly lucky and the exploit was found by people with really bad foresight and imagination.
Or it's been exploited for months/years to read people's DMs and private accounts and they decided to burn it now mostly for lolz?