I was thinking the other day about a digital signature for limited character tweets. Provided I’m not a cryptography expert and you should explore my ideas with caution, why not even just sign every tweet with an ed25519 signature? It’s on 64 bytes tacked onto the message and easy to verify...
Hackers take over prominent Twitter accounts in simultaneous attack
751–760 of 1001 posts
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#752Twitter should suspend the entire platform until they can credibly fix this and prevent it in the future. An attacker could drop AMZN stock by 10% in minutes with just the wrong tweet from Bezos.
They just disabled tweeting from verified accounts. Right now I have more power than Elon.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#753Looks like hackers got approx 60K. Anybody know how that compares to bug bounties at Twitter?
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#754Tweet from TwitterDev team yesterday: https://twitter.com/TwitterDev/status/1283068902331817990 > 2 days to go… #TwitterAPI https://twitter.com/TwitterDev/status/1283433096780677122 > Thank you to all of you who have engaged with us and shared your feedback. Your input has been vital, and we’re committed to continuing these conversations with you. There’s so much more we’re doing to build a better #TwitterAPI… and Ea…
Nice catch, this may be what it was. Edit: looks like an admin panel was the culprit https://news.ycombinator.com/item?id=23853786
Tweeting on behalf of another user seems like an unnecessary feature to give admins.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#755Earlier quoted context omitted.
They could have inconspicuously joined the numerous TSLA shorters and made 100x that with one tweet
This strategy would require having money to begin with. It's a pretty big assumption that hackers have any money. If they had money, they wouldn't have to be hackers.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#756Re: Hackers take over prominent Twitter accounts in simultaneous attack
#757Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#758Earlier quoted context omitted.
Or someone making one last use of an exploit on the old API, since ostensibly there is a day to go before the new API is released on the public net.
I don't think they were planning to immediately deprecate and remove the old API. Is there any reason to believe this is the case?
https://developer.twitter.com/en/docs/labs/overview/whats-ne...
I don't see any depreciations from today/tomorrow which would be related to what happened.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#759Tweet from TwitterDev team yesterday: https://twitter.com/TwitterDev/status/1283068902331817990 > 2 days to go… #TwitterAPI https://twitter.com/TwitterDev/status/1283433096780677122 > Thank you to all of you who have engaged with us and shared your feedback. Your input has been vital, and we’re committed to continuing these conversations with you. There’s so much more we’re doing to build a better #TwitterAPI… and Ea…
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#760Tweet from TwitterDev team yesterday: https://twitter.com/TwitterDev/status/1283068902331817990 > 2 days to go… #TwitterAPI https://twitter.com/TwitterDev/status/1283433096780677122 > Thank you to all of you who have engaged with us and shared your feedback. Your input has been vital, and we’re committed to continuing these conversations with you. There’s so much more we’re doing to build a better #TwitterAPI… and Ea…
Or someone making one last use of an exploit on the old API, since ostensibly there is a day to go before the new API is released on the public net.
I don't see any depreciations happening which could result in today's hack. Though I could be wrong.