Live data from Hacker News

Hackers take over prominent Twitter accounts in simultaneous attack

coindesk.com

931–940 of 1001 posts

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#931

With so many accounts compromised, the hackers might actually have full access to Twitter's backend. The postmortem would be very interesting. I'll be looking forward to it. Imagine if the hackers timed the intrusion during github outage, and twitter's employees can't deploy a fix for the exploit fast enough because github was down!

Why can twitter staff tweet under people's accounts? How does that make sense?

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#932

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

Nope. They're actually getting away with quite a big loot! The number of unconfirmed transactions has catapulted from ~9k to about ~50k right now, which means there's large amount of activity. It will take a while for the dust to settle. You can watch them here https://www.blockchain.com/btc/unconfirmed-transactions chart https://www.blockchain.com/charts/mempool-count A better graph of the current transactions sitti…

Zoom out and you see that this is normal every ~14 days.

Also number of transactions is in no way related to amount of money being transferred.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#933
post #883
post #767

Earlier quoted context omitted.

It looks like someone found a 0-day in the new API and wanted to use it before others did. Probably didn't help that the bug bounty for this would have been only 7k. How much does the Twitter employee who implemented this bug get paid? https://twitter.com/LiveOverflow/status/1283511782380908545

We now know it wasn't a 0 day. It was socially engineered access to internal tools. That's still a tricky one to lockdown.

It's tricky to fully prevent (considering conspiracies of multiple people) but not that tricky to ensure the responsible internal parties will be identified and brought to justice.

Working from home of course always leaves open the question if a person was willingly participating in a crime or was forced at gunpoint.

However, in this case, looks like Twitter's internal tools simply give too much access to people to control access to Twitter accounts. Probably no gunpoint required, just a single compromised employee. It remains to be seen how willingly they have participated.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#935

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

I think this is a state sponsored attack. Wouldn't want to speculate on which state.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#936
post #767

Earlier quoted context omitted.

It looks like someone found a 0-day in the new API and wanted to use it before others did. Probably didn't help that the bug bounty for this would have been only 7k. How much does the Twitter employee who implemented this bug get paid? https://twitter.com/LiveOverflow/status/1283511782380908545

Currently their earned BTC balance is $120k+ for comparison. That's a pretty successful scam and 5% of potential revenue will not make anyone go white hat.

Sorry, but $120k is ridiculously low for something like this.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#937
Shameless plug: All the companies(Google, Microsoft...) are telling trust us. But, I believe that we should trust us instead of relying on third parties. They always change when businesses interest changes. This is where web3 is coming to play. Technologies like IFFS, safe network are coming. Looking at the scale issue, I guess this web3 takes at least 5 more years. But, this kind p2p technology is possible with small-scaled mesh. Mesh networks within our devices or families. From the beginning, I hate the idea of storing passwords in the third-party password manager. Later, I fell into the same trap because a managing lot of passwords is difficult. So, I building an open-source p2p password manger. Replicates the passwords within your devices, instead of storing everything at the vendor's cloud. It's half-way for the closed beta release. I would like to hear everyone's feedback on this idea.

Thanks

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#939

Shameless plug: All the companies(Google, Microsoft...) are telling trust us. But, I believe that we should trust us instead of relying on third parties. They always change when businesses interest changes. This is where web3 is coming to play. Technologies like IFFS, safe network are coming. Looking at the scale issue, I guess this web3 takes at least 5 more years. But, this kind p2p technology is possible with smal…

How does that addresses the issue? From the looks of it, this was not a password attack, this was either an inside job or an abuse of an API.
Post reply on HN