Earlier quoted context omitted.
Even worse? How about POTUS declares war on China thru twitter? OMG, I just realized how dumb that would have been to say back in 2016. But these days?
This hack could absolutely get people killed. There are several tweets I can think of from POTUS that would begin immediate military mobilization from an unfriendly country.
Hackers take over prominent Twitter accounts in simultaneous attack
941–950 of 1001 posts
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#942Initial postmortem: https://twitter.com/TwitterSupport/status/128359184496275046... Seems to be a social-engineering attack on Twitter staff.
Very strange. Why exactly is it possible for any employee to tweet as any user? Unless the person who was targeted was the Database admin himself or something. Even then, how tech illiterate is this employee with such high permissions to fall for a social engineering attack? I would like to know what this employee's role was in the company. Also who did the social engineering?
But even then, that there is no system to detect mass modifications and no delay before the changes take place is incredible. Unless they were able to social engineer their way into multiple employee's accounts to avoid detection, which would be an incredibly bad problem by itself.
Twitter seems to have a shaky history when it comes to limiting employee access to account info.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#943Not sure if such a massive, simultaneous hacking operation makes sense for ~$120k worth of BTC. As other commenters mentioned, postmortem of this one should be interesting.
https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n...
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#944Shameless plug: All the companies(Google, Microsoft...) are telling trust us. But, I believe that we should trust us instead of relying on third parties. They always change when businesses interest changes. This is where web3 is coming to play. Technologies like IFFS, safe network are coming. Looking at the scale issue, I guess this web3 takes at least 5 more years. But, this kind p2p technology is possible with smal…
How does that addresses the issue? From the looks of it, this was not a password attack, this was either an inside job or an abuse of an API.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#945Earlier quoted context omitted.
It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.
I remember last year around christmas/new year 2018/2019 a similar hack/leak/doxxing took place, targeting 994 (!!) mostly german politicians, celebrities and influencers. Massive amounts of private information (names, addresses, phone numbers, e-mails, DMs, contacts, online profiles, chat logs, private documents and even intimate details) where leaked. The data was published on a wide spread of public pastebins and…
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#946Earlier quoted context omitted.
Very strange. Why exactly is it possible for any employee to tweet as any user? Unless the person who was targeted was the Database admin himself or something. Even then, how tech illiterate is this employee with such high permissions to fall for a social engineering attack? I would like to know what this employee's role was in the company. Also who did the social engineering?
If I had to guess, the attackers probably didn't even need twitter employees to have direct access to the accounts. If support tools allow Twitter support staff to change a user's email (which would make more sense, but still be extraordinarily unsecure), you basically get full access to the accounts the moment you get control over those tools. It would also explain why all the account emails seem to have been change…
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#947That is very odd.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#948Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.
I think this is a state sponsored attack. Wouldn't want to speculate on which state.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#949Earlier quoted context omitted.
Very strange. Why exactly is it possible for any employee to tweet as any user? Unless the person who was targeted was the Database admin himself or something. Even then, how tech illiterate is this employee with such high permissions to fall for a social engineering attack? I would like to know what this employee's role was in the company. Also who did the social engineering?
If I had to guess, the attackers probably didn't even need twitter employees to have direct access to the accounts. If support tools allow Twitter support staff to change a user's email (which would make more sense, but still be extraordinarily unsecure), you basically get full access to the accounts the moment you get control over those tools. It would also explain why all the account emails seem to have been change…
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#950Earlier quoted context omitted.
I think this is a state sponsored attack. Wouldn't want to speculate on which state.
based on what?
The resources needed to do this. Compromising and paying Twitter staff, the practical, technical know how (and it's cost), and that no real attempt to profit from this has been made?
I don't think that sounds like a financially motivated crime at all. As a crime it has more in common with the proverbial 'horse head on the bed', than a sophisticated heist. I think this was done to shake confidence in the perceived invincibility of Silicon Valley and FANG like companies particularly.
But then any number of well resourced 'political' actors would love to send that message to the large tech companies...