Live data from Hacker News

Hackers take over prominent Twitter accounts in simultaneous attack

coindesk.com

961–970 of 1001 posts

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#961

Watch this turns out to be a JS dependency tree problem from some library that was compromised months ago in some NPM module, used in the twitter web interface.

Given the Twitter web interface is just an client of the Twitter semi-public API, I highly doubt this is it.

But the twitter web interface has access to post (since you can post via it), so it would be possible.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#962

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

"few BTC", for US this is no money, but for a scammer in a 3rd world country 13 BTC more money than most people do in their lives.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#963
post #962

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

"few BTC", for US this is no money, but for a scammer in a 3rd world country 13 BTC more money than most people do in their lives.

"few BTC" is relative to the value of what they had, not the average income of the average person.

If I sold a 7500 sqft home in San Fransisco for $200,000 you could say the same thing.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#964

Earlier quoted context omitted.

What about Donald Trump wanting to shame the company which prevented him to tweet? Is it too far fetched?

Real estate developer by day, elite hacker at night?

>Real estate developer by day, elite hacker at night?

Is there anything this man CAN'T do? Perhaps one day he'll even become president and then "drain the swamp" or something...

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#965

Earlier quoted context omitted.

It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.

But then why set up a rather simply scam instead of getting the bug bounty from twitter? That wallet is currently sitting at about 150k USD and these are rather hard to pay out. Why not just go for 100k USD bug bounty, completely legal and with fame?

> Why not just go for 100k USD bug bounty, completely legal and with fame?

Not everyone believes that the existence of Twitter, in its current state as an amplification medium for the ever increasing polarisation in this world, is actually a force of good.

Helping them out with a security report might be the last thing on their mind.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#966

Earlier quoted context omitted.

Quite possibly this isn't a hack and someone got a Twitter admin's account, then got access to the admin panel and "all" accounts without having to hack much of anything.

If there is such a level of privilege in Twitter's stack, that says a great deal about their technology. Insiders must not be able to act as users except in prescribed ways requiring two-person control, logged and 100% audited. Glass-breaking privilege escalation should set off every pager in the company.

> requiring two-person control, logged and 100% audited

That would be good from a security perspective, but it would cost additional training, require more support staff, increase response time between request and resolve, make the system more complex and possible fragile, and take development resources away from profit centers.

Most companies has likely, at best, the same security at their internal support center as their accounting department, and given how common CEO fraud is, it mean social engineering will likely continue to be a major attack vector for a long time.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#967

Earlier quoted context omitted.

It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.

While possible, this scenario requires such a massive disconnect between the attacker's skill, connections, and luck versus their understanding of economic and geopolitical context that I would consider it among the least likely.

Such as the Max Headroom incident?

It's not uncommon for hackers to have these weird imbalances in skill and understanding.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#968

With so many accounts compromised, the hackers might actually have full access to Twitter's backend. The postmortem would be very interesting. I'll be looking forward to it. Imagine if the hackers timed the intrusion during github outage, and twitter's employees can't deploy a fix for the exploit fast enough because github was down!

It seems like the devs at Twitter are clueless, how this happened.

The hackers could be deep in Twitters systems, eventually even have even someone working at Twitter, or it's a result of a new yet unknown password list or phishing attempt.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#970
post #673

Earlier quoted context omitted.

In time you may come to view this as a bug, not a feature.

This is exactly what I was thinking. This has made me lose a lot of faith in crypto, not that I had a ton of faith to begin with. But I keep hearing people talk about blacklisting addresses and blocking transactions. That's scary stuff. How can people ever feel comfortable storing large amounts of money in crypto if the big players can simply block their address and make it near impossible to liquidize their money? I…

If you’re a fan of crypto for its independence and decentralisation, you aren’t going to be storing your coins on coinbase. You will store them on your own hardware.

Moving coins between wallets is simple, it would not be possible to simply block an address to prevent cashing out.

Post reply on HN