Earlier quoted context omitted.
I can't count the number of times people have asked here "How can Twitter possibly employ 4,000+ employees?". Well, I suppose we've learned 4K isn't even enough for good anti-abuse systems.
Um why not enough and not too much? This alone doesn't say anything in regard to twitter's user count. This means twitter had omni backend tooling that have manual/programmatic admin level access to production database. This is a very bad idea, access to production tables should be through a controlled medium and always challenged.
Hackers take over prominent Twitter accounts in simultaneous attack
911–920 of 1001 posts
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#912Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#913Place your bets, phishing or bug exploit. Some of these targets are too high profile to all fall for it and probably have teams that manage these accounts securely. Edit: 2fa was bypassed, interesting. https://twitter.com/tylerwinklevoss/status/12834920178892595...
Betting on inside / direct database access or admin account.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#914Earlier quoted context omitted.
It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.
But then why set up a rather simply scam instead of getting the bug bounty from twitter? That wallet is currently sitting at about 150k USD and these are rather hard to pay out. Why not just go for 100k USD bug bounty, completely legal and with fame?
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#915Earlier quoted context omitted.
I can't count the number of times people have asked here "How can Twitter possibly employ 4,000+ employees?". Well, I suppose we've learned 4K isn't even enough for good anti-abuse systems.
On a serious note, does that 4000+ employees include the content moderators? If yes, then I can see why. If not, then I am not sure what that many employees is for.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#916Re: Hackers take over prominent Twitter accounts in simultaneous attack
#917Re: Hackers take over prominent Twitter accounts in simultaneous attack
#918Earlier quoted context omitted.
It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.
Occam's razor says this is almost certainly the case. It isn't like the hacker knew that it would generate such little bitcoin being sent their way until after it failed. Especially if the hacker is not from the US it seems much easier to do the bitcoin hack than try to contact a company thousands of miles away that you know one at.
If Twitter uses the same 2FA internally as they do for customers it'd be pretty easy to take over a support account if you know of the location of an employee.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#919With the way that Elon tweets normally, someone could have done a lot of damage before anyone realized. Luckily markets have closed already.
There are quite a lot of trading bots that base their trades off high impact twitter accounts. I wonder how they would've reacted to this.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#920Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.