Live data from Hacker News

Hackers take over prominent Twitter accounts in simultaneous attack

coindesk.com

761–770 of 1001 posts

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#762
post #647

Earlier quoted context omitted.

Nice catch, this may be what it was. Edit: looks like an admin panel was the culprit https://news.ycombinator.com/item?id=23853786

Early access wasn't supposed to be enabled until tomorrow. I wouldn't speculate until they give a post-mortem.

What timezone is "tomorrow"? Did this happen at midnight for some timezone?

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#763
post #496

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

How about the possibility of a Bitcoin marketing campaign?

I like your thinking. This is a novel idea.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#764
Wonder if this could have been done by a rogue employee at Twitter? Since they are working from home during COVID, wonder what internal controls they have? I know some wondered if they used serveral high profile accounts, why not the presidents then? Well Twitter put extra protections on his account after an employee on their last day decided to suspend his account for 11 minutes. So if this isn't an hack and done internally that might be a clue.

I was surprised Apple especially got their account hacked, since they are big on security as a company. I know with Facebook a page can have multiple person accounts managing it, but I don't believe Twitter ever had such a thing unless more recently... So if you want multiple people to manage an account you'd use a special tool or just share the login info between your social media team.

I kinda feel like if you have to commute to an office, maybe more accountability as I'd feel someone might be looking more over your shoulder but I'd depend if someone gets private offices or a more open office design.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#765
post #647

Earlier quoted context omitted.

Nice catch, this may be what it was. Edit: looks like an admin panel was the culprit https://news.ycombinator.com/item?id=23853786

I don't understand this angle because typically admin panels only let you manage the account; deactivate, manage email address, etc. As shown in the screenshots. Tweeting on behalf of another user seems like an unnecessary feature to give admins.

I've worked on products before that have a feature that lets an admin open the site using the user's session, which is useful for verifying issues that only present when logged in as the user.

To be fair though, this was not for a social network, and even if you broke into that account there wasn't much you could do beyond paying the user's bills.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#766
post #595

Earlier quoted context omitted.

What was done was a guaranteed method of getting the method/exploit fixed in record time. If the perpetrator wanted to demonstrate, they would have targeted someone inconsequential that would not have put the problem on twitters radar. They blew their whole wad, likely on purpose, and there is nothing else planned.

Yeah, the idea that this is an initial step in something bigger doesn't make sense. If they wanted to exfiltrate data, they already did that previously. They very loudly burned their access, this seems a lot more like someone trying to monetize their access quickly before their access token expires - squeezing out the last few drops before they can no longer get into the system.

And by burning their access they could make sure nobody else is able to use that exploit to exfiltrate data

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#767

Tweet from TwitterDev team yesterday: https://twitter.com/TwitterDev/status/1283068902331817990 > 2 days to go… #TwitterAPI https://twitter.com/TwitterDev/status/1283433096780677122 > Thank you to all of you who have engaged with us and shared your feedback. Your input has been vital, and we’re committed to continuing these conversations with you. There’s so much more we’re doing to build a better #TwitterAPI… and Ea…

It looks like someone found a 0-day in the new API and wanted to use it before others did. Probably didn't help that the bug bounty for this would have been only 7k. How much does the Twitter employee who implemented this bug get paid?

https://twitter.com/LiveOverflow/status/1283511782380908545

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#770
post #466

Earlier quoted context omitted.

If they had full access to Twitter’s backend, they probably would be tweeting from accounts like @POTUS or @jack. But this seems like they have access to limited accounts. Most likely gained access to a third party service that allows you to manage your tweets? Edit: they tweeted from the twitter support account. Just wow. They might have actually gotten into Twitter’s systems. Edit 2: To expand on my edit above, I s…

Donald Trump was Tweeting in Farsi earlier, I was seriously on the fence about whether that was a genuine tweet.

[deleted]
Post reply on HN