Live data from Hacker News

Hackers take over prominent Twitter accounts in simultaneous attack

coindesk.com

711–720 of 1001 posts

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#712

With so many accounts compromised, the hackers might actually have full access to Twitter's backend. The postmortem would be very interesting. I'll be looking forward to it. Imagine if the hackers timed the intrusion during github outage, and twitter's employees can't deploy a fix for the exploit fast enough because github was down!

If they had full access to Twitter’s backend, they probably would be tweeting from accounts like @POTUS or @jack. But this seems like they have access to limited accounts. Most likely gained access to a third party service that allows you to manage your tweets? Edit: they tweeted from the twitter support account. Just wow. They might have actually gotten into Twitter’s systems. Edit 2: To expand on my edit above, I s…

I do think it's odd that so many prominent accounts were hit but not Trump's. I remember there was an incident a couple years ago that a trust and safety employee at Twitter suspended Trump's account on their last day. It's very likely that after that incident, special guards were set in place to prevent admin tools from messing with Trump's account. This would align with speculation that this hack targeted an internal employee admin tool.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#713

Earlier quoted context omitted.

Quite possibly this isn't a hack and someone got a Twitter admin's account, then got access to the admin panel and "all" accounts without having to hack much of anything.

If there is such a level of privilege in Twitter's stack, that says a great deal about their technology. Insiders must not be able to act as users except in prescribed ways requiring two-person control, logged and 100% audited. Glass-breaking privilege escalation should set off every pager in the company.

Sorry, but would you mind expanding slightly on how you would implement such a system?

In my understanding once you remove all the layers of abstraction as some point it's a bunch of databases and data stores. Someone has to manage them. Why wouldn't a breach of those users be able to do whatever they want?

And a higher level, someone is writing the code to implement such a stringent access system. Why wouldn't a breach of those users (or a rogue employee) be able to accomplish bad things?

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#715
post #643

Is the attack now changing usernames to the BTC address or are these people just trolling? https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...

Many people were searching the wallet address looking for accounts being hit, so these people did this to show up in that search.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#716
post #356

Earlier quoted context omitted.

Even worse? How about POTUS declares war on China thru twitter? OMG, I just realized how dumb that would have been to say back in 2016. But these days?

This hack could absolutely get people killed. There are several tweets I can think of from POTUS that would begin immediate military mobilization from an unfriendly country.

Trump's account has additional non-public security measures for this reason.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#717
post #432

Earlier quoted context omitted.

It can‘t really be the first three, because Twitter will fix this problem soon. So it would be wasting the exploit. It‘s either incompetence or your fourth option.

I read about this in the news before I saw it in my Twitter feed. My trust in Twitter has dropped severely. Why weren’t these tweets deleted immediately and a note pinned to every users feed?

Arguably it was irresponsible of Twitter not to pull the plug on the servers at the first hint of an exploit at this scale. When you literally have no idea what's going on, job #1 is to keep it from getting worse.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#718

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

Quite possibly this isn't a hack and someone got a Twitter admin's account, then got access to the admin panel and "all" accounts without having to hack much of anything.

After one incident of insider account tampering their entire response was "we must protect Donald Trump's account."

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#720

Is it just me, or does this seem suspiciously poorly thought out? Perhaps there is a second stage involving stock plays. The BTC thing might be a diversion. Or we are incredibly lucky and the exploit was found by people with really bad foresight and imagination.

Or it's been exploited for months/years to read people's DMs and private accounts and they decided to burn it now mostly for lolz?

It was mentioned in another comment that something like a new Twitter API is released tomorrow, so maybe one of the last chances to use the exploit?
Post reply on HN