Live data from Hacker News

Hackers take over prominent Twitter accounts in simultaneous attack

coindesk.com

941–950 of 1001 posts

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#941
post #356

Earlier quoted context omitted.

Even worse? How about POTUS declares war on China thru twitter? OMG, I just realized how dumb that would have been to say back in 2016. But these days?

This hack could absolutely get people killed. There are several tweets I can think of from POTUS that would begin immediate military mobilization from an unfriendly country.

It would with Trump - because we know his diplomacy runs through Twitter. With other presidents like Obama or Bush (did Twitter exist back then?) I would expect the risk is lower.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#942

Initial postmortem: https://twitter.com/TwitterSupport/status/128359184496275046... Seems to be a social-engineering attack on Twitter staff.

Very strange. Why exactly is it possible for any employee to tweet as any user? Unless the person who was targeted was the Database admin himself or something. Even then, how tech illiterate is this employee with such high permissions to fall for a social engineering attack? I would like to know what this employee's role was in the company. Also who did the social engineering?

If I had to guess, the attackers probably didn't even need twitter employees to have direct access to the accounts. If support tools allow Twitter support staff to change a user's email (which would make more sense, but still be extraordinarily unsecure), you basically get full access to the accounts the moment you get control over those tools. It would also explain why all the account emails seem to have been changed.

But even then, that there is no system to detect mass modifications and no delay before the changes take place is incredible. Unless they were able to social engineer their way into multiple employee's accounts to avoid detection, which would be an incredibly bad problem by itself.

Twitter seems to have a shaky history when it comes to limiting employee access to account info.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#943
The BTC address used by the malicious actors has received ~13 BTC so far. That's around $120k in value at the time of me writing this comment.

Not sure if such a massive, simultaneous hacking operation makes sense for ~$120k worth of BTC. As other commenters mentioned, postmortem of this one should be interesting.

https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n...

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#944

Shameless plug: All the companies(Google, Microsoft...) are telling trust us. But, I believe that we should trust us instead of relying on third parties. They always change when businesses interest changes. This is where web3 is coming to play. Technologies like IFFS, safe network are coming. Looking at the scale issue, I guess this web3 takes at least 5 more years. But, this kind p2p technology is possible with smal…

How does that addresses the issue? From the looks of it, this was not a password attack, this was either an inside job or an abuse of an API.

It's not addressing this issue. Looks like inside job. Am saying that we all should change from centralized authority into decentralized world.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#945

Earlier quoted context omitted.

It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.

I remember last year around christmas/new year 2018/2019 a similar hack/leak/doxxing took place, targeting 994 (!!) mostly german politicians, celebrities and influencers. Massive amounts of private information (names, addresses, phone numbers, e-mails, DMs, contacts, online profiles, chat logs, private documents and even intimate details) where leaked. The data was published on a wide spread of public pastebins and…

Ja in South Africa, sim swapping is still one of the biggest attack vectors, especially for bank-account-hacks.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#946

Earlier quoted context omitted.

Very strange. Why exactly is it possible for any employee to tweet as any user? Unless the person who was targeted was the Database admin himself or something. Even then, how tech illiterate is this employee with such high permissions to fall for a social engineering attack? I would like to know what this employee's role was in the company. Also who did the social engineering?

If I had to guess, the attackers probably didn't even need twitter employees to have direct access to the accounts. If support tools allow Twitter support staff to change a user's email (which would make more sense, but still be extraordinarily unsecure), you basically get full access to the accounts the moment you get control over those tools. It would also explain why all the account emails seem to have been change…

"Hello? Twitter support? Yes, I want to change my email address. I'm Elon Musk."

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#948

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

I think this is a state sponsored attack. Wouldn't want to speculate on which state.

based on what?

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#949

Earlier quoted context omitted.

Very strange. Why exactly is it possible for any employee to tweet as any user? Unless the person who was targeted was the Database admin himself or something. Even then, how tech illiterate is this employee with such high permissions to fall for a social engineering attack? I would like to know what this employee's role was in the company. Also who did the social engineering?

If I had to guess, the attackers probably didn't even need twitter employees to have direct access to the accounts. If support tools allow Twitter support staff to change a user's email (which would make more sense, but still be extraordinarily unsecure), you basically get full access to the accounts the moment you get control over those tools. It would also explain why all the account emails seem to have been change…

I am really doubtful they were able to change the email and phone of so many celebrities and powerful people at the same time by phone. Twitter stated "social engineering" but I don't think this was for changing emails and phones of each person one by one.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#950
post #948

Earlier quoted context omitted.

I think this is a state sponsored attack. Wouldn't want to speculate on which state.

based on what?

Perceived motive.

The resources needed to do this. Compromising and paying Twitter staff, the practical, technical know how (and it's cost), and that no real attempt to profit from this has been made?

I don't think that sounds like a financially motivated crime at all. As a crime it has more in common with the proverbial 'horse head on the bed', than a sophisticated heist. I think this was done to shake confidence in the perceived invincibility of Silicon Valley and FANG like companies particularly.

But then any number of well resourced 'political' actors would love to send that message to the large tech companies...

Post reply on HN