Live data from Hacker News

Hackers take over prominent Twitter accounts in simultaneous attack

coindesk.com

911–920 of 1001 posts

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#911

Earlier quoted context omitted.

I can't count the number of times people have asked here "How can Twitter possibly employ 4,000+ employees?". Well, I suppose we've learned 4K isn't even enough for good anti-abuse systems.

Um why not enough and not too much? This alone doesn't say anything in regard to twitter's user count. This means twitter had omni backend tooling that have manual/programmatic admin level access to production database. This is a very bad idea, access to production tables should be through a controlled medium and always challenged.

Any 20 person startup in cyber security-adjacent fields has thought more about this than Twitter? Jeez this is not a good look.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#912

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

Another possibility is that they have already sold the hack, but the relationship with the buyer deteriorated for whatever reason, so they decided to burn the bridge.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#913
post #25

Place your bets, phishing or bug exploit. Some of these targets are too high profile to all fall for it and probably have teams that manage these accounts securely. Edit: 2fa was bypassed, interesting. https://twitter.com/tylerwinklevoss/status/12834920178892595...

Betting on inside / direct database access or admin account.

How many people have admin access to production? That is like a "in case of emergency break glass"-role at best.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#914

Earlier quoted context omitted.

It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.

But then why set up a rather simply scam instead of getting the bug bounty from twitter? That wallet is currently sitting at about 150k USD and these are rather hard to pay out. Why not just go for 100k USD bug bounty, completely legal and with fame?

Reporting that social engineering would allow to take over the admin panel might not lead to any pay out at all.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#915

Earlier quoted context omitted.

I can't count the number of times people have asked here "How can Twitter possibly employ 4,000+ employees?". Well, I suppose we've learned 4K isn't even enough for good anti-abuse systems.

On a serious note, does that 4000+ employees include the content moderators? If yes, then I can see why. If not, then I am not sure what that many employees is for.

For middle management to win their political games.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#918
post #840

Earlier quoted context omitted.

It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.

Occam's razor says this is almost certainly the case. It isn't like the hacker knew that it would generate such little bitcoin being sent their way until after it failed. Especially if the hacker is not from the US it seems much easier to do the bitcoin hack than try to contact a company thousands of miles away that you know one at.

Social engineering could be very easy from within the US, e.g. if you're the neighbour of a Twitter rep working from home and can talk them into handing you their phone for a few minutes. From outside the US it's much harder, esp since an accent could make social engineering via phone less effective.

If Twitter uses the same 2FA internally as they do for customers it'd be pretty easy to take over a support account if you know of the location of an employee.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#919
post #177
post #6

With the way that Elon tweets normally, someone could have done a lot of damage before anyone realized. Luckily markets have closed already.

There are quite a lot of trading bots that base their trades off high impact twitter accounts. I wonder how they would've reacted to this.

That sounds like a... high variance idea.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#920

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

If this is a demonstration to a client I don't want to know what the product is they're selling. There are few more valuable targets than being able to hijack communication of public figures.
Post reply on HN