Live data from Hacker News

Hackers take over prominent Twitter accounts in simultaneous attack

coindesk.com

861–870 of 1001 posts

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#861
post #661

Earlier quoted context omitted.

Or someone making one last use of an exploit on the old API, since ostensibly there is a day to go before the new API is released on the public net.

This makes way more sense than any of the other suggestions in HN. DMs are almost worthless; who uses DMs for anything important? It's for contacting people you kinda know but not really. State secrets aren't transitted over DM, but not because people wouldn't be stupid enough to do it. the people holding them are much older than the demographic that uses Twitter DMs. Worst case with DMs is some new YouTuber drama wo…

a lot of tech support includes PII over DM. Just in my list right now tmobile has enough in a dm thread for someone to call up and take over my line. It's stupid.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#862
post #767

Tweet from TwitterDev team yesterday: https://twitter.com/TwitterDev/status/1283068902331817990 > 2 days to go… #TwitterAPI https://twitter.com/TwitterDev/status/1283433096780677122 > Thank you to all of you who have engaged with us and shared your feedback. Your input has been vital, and we’re committed to continuing these conversations with you. There’s so much more we’re doing to build a better #TwitterAPI… and Ea…

It looks like someone found a 0-day in the new API and wanted to use it before others did. Probably didn't help that the bug bounty for this would have been only 7k. How much does the Twitter employee who implemented this bug get paid? https://twitter.com/LiveOverflow/status/1283511782380908545

Currently their earned BTC balance is $120k+ for comparison. That's a pretty successful scam and 5% of potential revenue will not make anyone go white hat.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#863
I have a question to ask you all. If I wanted to study things to get to the point where internally/externally I could coordinate a hack of this magnitude, what things do I need to study? What are the technical things needed to pull something like this off? What are the social corporate things I needed to know to pull this off? I know that we don't have specifics, but I'm asking as a pure academic exercise how much I'd need to know to pull this off, and how to get away with it too.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#864
post #541

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

I’m guessing DMs were the real loot. The public display with the BTC diversion validates any DMs that were stolen. Otherwise blackmail targets could deny them.

Blackmail targets could still deny them.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#865
post #34

Earlier quoted context omitted.

Sounds like an exploit. The article says that some of the accounts were confirmed to have multi-factor authentication enabled.

> multi-factor authentication enabled It sure seems like multi-factor auth isn't very helpful, when nearly all hacks have nothing to do with breaking credentials.

Actually, that proves that it is helpful.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#866
post #72

Earlier quoted context omitted.

I've seen several live streams on youtube that replay spacex launches and display the same offer. Viewership goes up during actual launches. The one I found had 10k active viewers and the address they linked to had brought in 2btc in under an hour.

I few weeks ago I saw two with 50k each... Google has to step up it's game because their platforms aren't safe anymore.

That's like blaming the post office for chain letters.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#867
post #541

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

I’m guessing DMs were the real loot. The public display with the BTC diversion validates any DMs that were stolen. Otherwise blackmail targets could deny them.

Interesting theory, but then why would they include Apple? Among others in the list, they’re almost guaranteed to be of no value and only increase the risk.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#868

Earlier quoted context omitted.

Nope. They're actually getting away with quite a big loot! The number of unconfirmed transactions has catapulted from ~9k to about ~50k right now, which means there's large amount of activity. It will take a while for the dust to settle. You can watch them here https://www.blockchain.com/btc/unconfirmed-transactions chart https://www.blockchain.com/charts/mempool-count A better graph of the current transactions sitti…

I'm a little unclear, is the following correct?. So basically rando's are sending famous people bitcoin because the famous people tweeted "send us $$ and we'll send you double back"? And somehow the rando's haven't heard of the hack. Is this what's happening? Like are random people seriously sending them bitcoin? Or is it some weird form of money laundering? Although since that's very weird behavior even if there was…

I find myself confused by this as well, surely people who are sufficiently technically sophisticated to own bitcoin won’t fall for “I’ll send you bitcoin if you send me yours first”?

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#869
post #133

Just what kind of an operation is Twitter running here? It seems crazy that they don't have any kind of anti-abuse system in place that could just block tweets with this specific Bitcoin address or possibly tweets matching the regexp of any Bitcoin address. I.e. limit the damage and buy a couple of hours while they try to find the root cause. (Yes, yes, staged rollouts. But anti-abuse systems don't work by those rule…

I can't count the number of times people have asked here "How can Twitter possibly employ 4,000+ employees?". Well, I suppose we've learned 4K isn't even enough for good anti-abuse systems.

On a serious note, does that 4000+ employees include the content moderators? If yes, then I can see why. If not, then I am not sure what that many employees is for.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#870

I have a question to ask you all. If I wanted to study things to get to the point where internally/externally I could coordinate a hack of this magnitude, what things do I need to study? What are the technical things needed to pull something like this off? What are the social corporate things I needed to know to pull this off? I know that we don't have specifics, but I'm asking as a pure academic exercise how much I'…

start here:, and then catch up to whatever the state of the art is. Humans are the weakest link in the security chain. https://theintercept.com/document/2014/03/20/hunt-sys-admins...
Post reply on HN