40 ms·
Hackers take over prominent Twitter accounts in simultaneous attack
- rudolph9 6y agoI was thinking the other day about a digital signature for limited character tweets. Provided I’m not a cryptography expert and you should explore my ideas with caution, why not even just sign every tweet with an ed25519 signature? It’s on 64 bytes tacked onto the message and easy to verify...
- andy_ppp 6y agoOr put the tweets onto a blockchain...
- rudolph9 6y agoI mean you could but seems unnecessary. Putting tweets on a blockchain would make it very difficult to delete them or edit them but offer no more certainty than a regular tweet that includes a signature verifiable with a known public key of mine. I just don’t don’t want someone impersonating me on any one of the many random website I have a profile where anyone with access to the db can write whatever they want under my name.
- acid__ 6y agoHow do you plan on managing the signing keys?
- rudolph9 6y agoHardware security module
- acid__ 6y agoSeems like it would be a nice feature for security-minded folks, and would probably be pretty difficult to roll out to regular consumers. Does Mastodon have something like this? Sounds like something their userbase would appreciate.
- rudolph9 6y agoYou could literally dump the signature in at the end of the utf-8 tweet. A tweet can contain about 500 bytes, the signature is 64 bytes; encode it using utf8 characters and you got plenty of room room for a message and a signature I’m honestly surprised this isn’t common already in the crypto space and kinda wonder if I’m missing something
- acid__ 6y agoFor sure, the hard part isn't building it, it's getting people to actually use it. The amount of effort involved of actually acquiring and transporting a hardware security key is well beyond what most "normal" people are willing to do. Plus, reading your example in a different comment, it's completely jarring to someone who isn't used to reading things in that format.
- rudolph9 6y agoI get why everyday users don’t use it but why doesn’t an org like coinbase? Yes the quick and dirty poc I built in 5 minutes is a bit jarring but it could easily be adjusted so the beginning of the tweet reads like it normally would and the end is the cryptographic signature nearly separated from the main message.
- rudolph9 6y ago-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 hi hacker news -----BEGIN PGP SIGNATURE----- iIIEARYKACoWIQSiJQKEVJeJondn78BXE/NAGxPd0QUCXw/JqwwcZm9vQGJhci5j b20ACgkQVxPzQBsT3dGf1gEAwMzbCxEaEJzRjJwFe90TRrXZiIe4KD9cZ64CHZEz eKEA/3W0ZIx6TOASPrzuTLytBK8OsL9FFAVWMUGTyLJSSh8O =ORB6 -----END PGP SIGNATURE-----
- rudolph9 6y agopubkey: https://gist.github.com/rudolph9/bd672dc6d50a51a7d3f5352a918ae021 https://gist.github.com/rudolph9/bd672dc6d50a51a7d3f5352a918... A little more cumbersome than I imagined but proves that the contents of a tweet can contain a message and a digital signature.
- rudolph9 6y agoI think I may have just re-invented keybase.io haha.
- monokh 6y agoThis must be a twitter exploit. Just too many high profile accounts have been pushing out scams at the same time.
- retox 6y agoYou'd think a 0day like that would be worth much more than the BTC they're going to receive.
- bayesianbot 6y agoLots and lots of crypto accounts hacked. Either Twitter is hacked or some automated tweeting system has a 0day.
- Nextgrid 6y agoMy bet is on some kind of client/marketing platform that all these accounts gave write permission to. Edit: I stand corrected, many other comments mention that the offending tweets appear to be posted from the web app, so this suggests an issue within Twitter itself.
- captn3m0 6y agoSome of these are really high profile hacks (Biden/Obama for eg). I'm wondering if its a silly twitter authentication bypass.
- deleted 6y ago[deleted]
- nickysielicki 6y agoI find it fascinating that they didn't target @POTUS/@realDonaldTrump. I wonder if there are specific mechanisms in place to protect accounts that could, y'know, start WW3, that aren't rolled out to other blue checkmark accounts.
- rumori 6y agoAll type of accounts are posting the same message. Out of curiosity I just deactivated mine, let's see what happens.
- abigger87 6y agohttps://gifyu.com/image/QrnS https://gifyu.com/image/QrnS
- codesternews 6y agoThis raises so much questions about Tech giants security. If they could do this manipulating elections or so much power with one system. "Security is Myth."
- megadeth 6y agoTop crypto currency accounts compromised
- a-wu 6y agoWith the way that Elon tweets normally, someone could have done a lot of damage before anyone realized. Luckily markets have closed already.
- iamben 6y agoElon Musk as well. Tweets still up, saying "Feeling greatful, doubling all payments sent to my BTC address! You send $1,000, I send back $2,000! Only doing this for the next 30 minutes." As of now, 121 people have sent cash totally more than 2.5BTC. Edit: Just seen @BillGates compromised as well, same bitcoin account. Edit 2: Elon's tweet seems to be getting removed, and then reposted again shortly after. About $40k sent so far. Edit 3: Interesting to watch - on both accounts, tweets seem to be deleted and then reappear as pinned a few mins later.
- ISL 6y agoTweet is down now, but still in Google's cache.
- ISL 6y agoBillGates tweet is now down, within the last minute.
- pinewurst 6y agoI still see it as a "pinned tweet" https://twitter.com/BillGates/status/1283503731682811907 https://twitter.com/BillGates/status/1283503731682811907 (Now gone @ 3:32p Pacific)
- nathancahill 6y agoIt's also getting reposted.
- rvz 6y agoThey are reposting the same message on the hacked accounts again. This is a coordinated Twitter hack.
- blablablub 6y agoOne thing we know now is that Twitter can take tweets down really quickly if they want.
- dvaun 6y agoThere's a Web Archive link[0] for anyone curious. It looks like this was pretty successful for the hacker. At the time of writing they received ~3.1 BTC, or ~$29k in USD[1]. Edit: Replaced [1] with a site that appeared to have less trackers according to Privacy Badger. [0]: https://web.archive.org/web/20200715202030/https://twitter.com/elonmusk/status/1283495825998520320 https://web.archive.org/web/20200715202030/https://twitter.c... [1]: https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n...
- etaioinshrdlu 6y agoPartial list of hacked accounts here, https://twitter.com/Justin12393LEE/status/1283498445886586883 https://twitter.com/Justin12393LEE/status/128349844588658688... Mentions: - Bitcoin - Coinbase - BINANCE - CZ_Binance - Gemini - Kucoin - Gate .io - Coindesk - Tron - Justin Sun - Charlee Lee
- leephillips 6y agoI feel left out.
- jcims 6y agoJust tweet it yourself. Who will know?
- shmoogy 6y agoThose are some big names. I got notified about Elon and bill gates, figured there was some large scale hack. Crazy times
- ISL 6y agoThis must be a shot over someone's bow. Edit: Or a trading play? That would have taken place while the markets were open, though. TWTR after-hours trading is off 3% on the news.
- pcbro141 6y agoSome pics of the tweets: https://twitter.com/TheHackersNews/status/1283502081265950720 https://twitter.com/TheHackersNews/status/128350208126595072...
- Reason077 6y agoSo many accounts are affected, this seems to be a system-level hack rather than a compromise of individual accounts. Someone has found a way to post a tweet from any account they like?
- actuator 6y agoSome folks are saying some of these accounts had 2FA, so can be the case but I guess if it was a system thing, we might have seen tweets from more prominent accounts.
- a3r0 6y agoYou would think they would do something with Trump if it was arbitrary accounts. But maybe his has additional protections
- nathancahill 6y agoI believe I read something (trying to find it) about Twitter internally having additional protections on Trump's account. Only a handful of people within Twitter can touch it.
- Firebrand 6y agoIt was likely after this incident: http://www.bbc.com/news/world-us-canada-41854482 http://www.bbc.com/news/world-us-canada-41854482
- marcinzm 6y agoThey're clearly trying to avoid the risk of being tracked. For example, they could have done stock manipulation and made more money. Trump is someone with the power and craziness to spend a hundred million tracking you down and literally dropping bombs on your head. So it'd be poor risk management to go after his account.
- Covzire 6y agoI agree, but only until the bombings, I mean he's the most anti-war president in living memory.
- whoisjuan 6y agoWhoever hacked Twitter today definitely got major access to their backend: https://twitter.com/whoisjuan/status/1283502962103455744?s=20 https://twitter.com/whoisjuan/status/1283502962103455744?s=2...
- css 6y ago> Whoever hacked @Twitter today definitely got major access to their backend Is there any proof Twitter was hacked and not just these two accounts?
- whoisjuan 6y ago- Uber - Apple - Bill Gates - Elon Musk - Jeff Bezos - Joe Biden - Barack Obama - Michael Bloomberg - Kanye West - Wiz Khalifa - Bitcoin - Ripple - Coinbase - BINANCE - CZ_Binance - Gemini - Kucoin - Gate .io - Coindesk - Tron - Justin Sun - Charlee Lee That seems like someone got full access to the backend, not the accounts per se. Also worth mentioning that the tweets get deleted but then they get added and pinned again.
- css 6y agoWhere is the proof someone got access to the backend and not those specific accounts? Seems more likely an API client got hacked, possibly one that high profile people might use like a tweet scheduler, but not Twitter, given their threat profile and resources. That would explain why 2FA accounts were affected.
- viraptor 6y agoThere's no proof since there's no official incident writeup yet. For now there's just Occam's razor since majority/all of those accounts will be 2fa protected.
- mlinsey 6y agoYes. Also, we're about an hour in now, and Musk's account just sent out another tweet after the message had been posted and deleted several times. At this point, if it was just an account compromise, someone would have reset it by now
- pcbro141 6y agoPics of tweets: https://twitter.com/TheHackersNews/status/1283502081265950720 https://twitter.com/TheHackersNews/status/128350208126595072...
- deleted 6y ago[deleted]
- danso 6y ago> At least some of the compromised accounts have multi-factor authentication enabled, including CoinDesk's. Interesting. I wonder if it was a SMS hack, and if not, then a new kind of vulnerability?
- 2arrs2ells 6y agoIs there a way to pin a tweet via SMS? I don't think so... and these tweets are getting pinned.
- SwiftyBug 6y agoI believe OP meant that the attackers got access to the account by hacking SMS, thus getting the verification code and legitimately logging in the accounts.
- duskwuff 6y agoTwitter dropped support for SMS posting earlier this year: https://www.theverge.com/2020/4/27/21238131/twitter-sms-notifications-disabled-jack-dorsey-hack https://www.theverge.com/2020/4/27/21238131/twitter-sms-noti...
- danso 6y agoI meant in the sense of SIM-swap hacks, though SMS-posting would also make sense as a vector (had Twitter not recently ended it) https://info.phishlabs.com/blog/sim-swap-attacks-two-factor-authentication-obsolete https://info.phishlabs.com/blog/sim-swap-attacks-two-factor-...
- mikewhy 6y agoHeadline seems pretty editorialized.
- forsaken 6y agoNo Trump?
- fareesh 6y agoI like to imagine that it would trigger some kind of alarm at the CIA/NSA/FBI and have drones surrounding the person's house within a few hours?
- wisemanwillhear 6y agoPerhaps Twitter has additional security around his account? An IP whitelist? Perhaps the President has a special version of the twitter client that includes additional authentication? Twitter is no fan of the current president, but it seems plausible for national security reasons.
- shiado 6y agoPlace your bets, phishing or bug exploit. Some of these targets are too high profile to all fall for it and probably have teams that manage these accounts securely. Edit: 2fa was bypassed, interesting. https://twitter.com/tylerwinklevoss/status/1283492017889259523 https://twitter.com/tylerwinklevoss/status/12834920178892595...
- dx87 6y agoSounds like an exploit. The article says that some of the accounts were confirmed to have multi-factor authentication enabled.
- justinmeiners 6y ago> multi-factor authentication enabled It sure seems like multi-factor auth isn't very helpful, when nearly all hacks have nothing to do with breaking credentials.
- Latty 6y ago> when nearly all hacks have nothing to do with breaking credentials. This seems like a big claim to make. My understanding is that by far the most common reason accounts are compromised is password reuse combined with another site being compromised.
- justinmeiners 6y agoSure, I guess that is a wrong assumption on my part. Perhaps a better way to word it, is: two factor auth only seems to protect you if all the other parts of site authentication are solid, which rarely seems to be true.
- nrmitchi 6y agoWell of course if you exclude all of the attacks that didn't happen because 2fa was enabled, then ya, 2fa won't protect you against the ones that still happen. Lets compare this to.... car safety. Ya, if you get hit head on by an 18-wheeler on the highway, your seatbelt is only going to help you as much as the rest of the safety of the car. But in pretty much every other situation, I would be glad to be wearing my seatbelt. It's uncharitable to focus on the small slice of situations that something doesn't work in order to deem it useless.
- downshun 6y agoA clear use case of Blockchain for the cryptocurrency detractors \s
- ve55 6y agoThis is looking really bad, I wonder what they used to get access to all these high-profile accounts? It's worth noting these types of blackhat crypto scammers make millions a year from this already, but this is definitely making it a lot worse. EDIT: Still going on after 30+ minutes, seeing people like Bill Gates tweet crypto scams still. Amazed they got all the crypto exchange too. And it's not just Bitcoin, they got RIpple too and posted XRP addresses.
- deleted 6y ago[deleted]
- lostmsu 6y agoThis is going to be a hilarious postmortem. If we ever see it.
- monokh 6y agoSome reports that this was related to compromised OAuth tokens. How would someone know and what is the source of the compromise? A third party app that all of these accounts use?
- jacquesm 6y agoStill going on. https://twitter.com/BillGates/status/1283503731682811907 https://twitter.com/BillGates/status/1283503731682811907 What a disaster this stuff. Wonder how it was done.
- ben174 6y agoSeems they’re cashing in. According to one tweet, $7.8m transferred to their address so far.
- Latty 6y agoThe responses to that tweet say it is fake and the real number is only 6BTC (~$50k).
- mendelmaleh 6y agohttps://www.blockchain.com/it/btc/address/bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh https://www.blockchain.com/it/btc/address/bc1qxy2kgdygjrsqtz... According to this, 6.1 BTC, which is around 56k USD
- kawfey 6y agoIt's amusing that the tweets keep coming, get deleted, reappear, get deleted... I can't help but imagine how any account on twitter would be safe if the Bill Gates', Elon Musk's, and top crypto site's Twitters are compromised.
- jacquesm 6y agoPretty safe to assume they are all compromised until there is proof to the contrary.
- kbenson 6y agoPartially because it's twitter, I'm completely unable to determine if the responses are hacked accounts, joking, or actual people that sent money. I suspect the actual numbers and percentages of the whole of each would be surprising...
- challenge 6y agoalso all @apple tweets have been deleted lol the hacker already got 6 BTC! this is crazy.
- ydnaclementine 6y agoThe wallet that the hacker who got Elon posted has been given 5.7 BTC and counting: https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n...
- adjkant 6y agoWow, up to 11 now
- ydnaclementine 6y agoParent wallet (the one posted on twitter) now transfering funds to this wallet: https://www.blockchain.com/btc/address/1Ai52Uw6usjhpcDrwSmkUvjuqLpcznUuyF https://www.blockchain.com/btc/address/1Ai52Uw6usjhpcDrwSmkU...
- deleted 6y ago[deleted]
- Miner49er 6y agoThe scammer's address: https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh?page=1 https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n...
- ilikehurdles 6y ago$110k received so far in btc.
- 10xPerson 6y agoI refuse to believe there are people who can be aware of BTC enough to go out of their way to even obtain some, and then fall for a scam like this...
- SwiftyBug 6y agoThe attacker already made over 5 BTC: https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n...
- smnrchrds 6y agoI am not familiar with BTC markets. How would they be able to collect? Wouldn't everyone be watching that wallet like hawk, making it impossible to withdraw without revealing their identity?
- SwiftyBug 6y agoThere are services that are able to obfuscate a transfer of BTC, which really only makes it very laborious to trace the money.
- lawn 6y agoThere are many exchanges and services where you can sell BTC for XMR (Monero) without revealing your identity. And with Monero you cannot trace addresses or transactions.
- stjo 6y agoI believe no sane service would accept BTC from that address. It is now "stained" and every other address it touches will be too. There are systems that automatically monitor for such scams so it is quite hard to launder $100k.
- lawn 6y agoThere have been much larger amounts people have laundered this way.
- claudeganon 6y agoI’m sure they’ll hold onto them, considering they ran a scam on one of the world’s richest people who made the NSA’s favorite operating system.
- hoschicz 6y agoReally surprised by this. I suspect a system-level 2FA hack or a bug exploit, all these people woudln't fall for phishing
- s5300 6y agoStill going on as of this post time. Elon's just went off again. Over 30ish minutes now. Holy shit, it's going to be fun to see the outcome of this.
- vsareto 6y agoAll of Apple's tweets are gone https://twitter.com/Apple https://twitter.com/Apple
- dawnerd 6y agothey just posted the scam there...
- duskwuff 6y agoThat's not new. AFAIK, Apple promotes all of their tweets, so they don't show up on their profile.
- WatchDog 6y agoFor someone that doesn't understand twitter, what does that mean?
- duskwuff 6y agoTwitter allows users (typically companies) to "promote" tweets, causing them to be seen by users who are not following the account, and hence would not typically see the tweet. When a user promotes a tweet, they are given the option to hide it, so that it won't show up to users who are following the account directly, or who are looking at the account's profile. This is so that (for example) a company that posts a dozen different variants of an advertisement for different markets won't have all twelve of those show up on their profile page, or on the timeline of any user who's following them. Apple, for whatever reason, seems to set the "hide this" option for every tweet they post and promote. Why? Beats me.
- artursapek 6y agoI think they do it for brand reasons. Having an empty Twitter page makes it seem like they're "above it all".
- vimy 6y agoIt means they use paid tweets (ads) to ‘tweet’.
- deleted 6y ago[deleted]
- epa 6y agoArchive of Elon's tweet https://web.archive.org/web/20200715203559/https://twitter.com/elonmusk https://web.archive.org/web/20200715203559/https://twitter.c...
- caiobegotti 6y agoThat's really light in details, TC has more juice about the situation IMHO: https://techcrunch.com/2020/07/15/twitter-accounts-hacked-crypto-scam/ https://techcrunch.com/2020/07/15/twitter-accounts-hacked-cr...
- rvz 6y agoUber has been hacked as well. At this point, they can get any high profile Twitter user. EDIT: You know this is a coordinated Twitter hack when they have Apple's account hacked [0]. https://twitter.com/Apple/status/1283506278707408900 https://twitter.com/Apple/status/1283506278707408900
- paxys 6y agoI feel like we already knew this when Jack Dorsey's Twitter account was hacked.
- gundmc 6y agoI thought that vulnerability was due to the now-deprecated Tweet by Phone integration and SIM swaps?
- ISL 6y agoThey haven't yet gone after the most prominent Twitter user.
- ceejayoz 6y agoThat's one of the few accounts that might get you drone striked for messing with. It may stay safe.
- tomp 6y agoWould be too obvious. Noone believes what that account tweets anyway.
- joshstrange 6y ago40-some% of Americans do according to polling at least :/
- gruez 6y agoWhat can you tweet to trump supporters for maximum monetization? Crypto scam? Doubt many of them own crypto or know what it is. Get them to send western union/itunes gift cards? Too obvious, will probably get clawed back.
- deweller 6y agoThese are already removed. Does anyone have a screenshot or other archive?
- challenge 6y agorumors say the hacker got access to an internal (used by employees) admin panel...
- mindfreeze 6y agoAll Apple Tweets are now deleted https://twitter.com/apple https://twitter.com/apple and now one scam alone https://twitter.com/Apple/status/1283506278707408900 https://twitter.com/Apple/status/1283506278707408900
- tandav 6y agoApple never tweeted anything (only promotional ad tweets)
- pier25 6y agoApple too: https://imgur.com/ZvPshMX.jpg https://imgur.com/ZvPshMX.jpg
- nathancahill 6y agoApple and Kanye West too.
- PatrolX 6y agoI posted this here and it got flagged. https://twitter.com/asculthorpe/status/1283501026281127937 https://twitter.com/asculthorpe/status/1283501026281127937 Try to warn people and you get slammed for it. Ugh.
- mindfreeze 6y agoGuess this a attack from the TikTok world /s
- PatrolX 6y agoSo far people have sent: Transactions 253 Total Received $101,539.14 Link to address: https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n...
- jackschultz 6y agoAn incredibly number of people in the entire world who have seen these tweets, and currently, 5:16 eastern, shows 271 transactions. Not like everyone who sees these tweets has bitcoin accounts, but less than 300 falling for the fake tweets is such a small number in terms of populations.
- qgadrian 6y agoDid the hackers remove all tweets from Apple? Wtf
- SwiftyBug 6y agoIt seems like they did.
- blocked_again 6y agoApple didn't have any normal tweets before the incident as well. Apple only post sponsored tweets.
- danso 6y agoThis is the earliest non-deleted tweet I've found referencing the bitcoin address (or rather, noticing that an account got hacked). It was sent at 12:23PM Pacific time (more than 1.5 hours ago): https://twitter.com/lawmaster/status/1283481418518208513 https://twitter.com/lawmaster/status/1283481418518208513
- pastrami_panda 6y agoIt's astonishing that they can't seem to at least shut the platform down. Have they lost control completely or do they think it's preferable to let the scammers go on than to close shop?
- Nextgrid 6y agoCryptocurrency scams with fake accounts impersonating verified ones have been around for years despite being detectable with a simple regex. There's no reason to believe this disgraceful company actually cares, although after this incident hopefully they will change their mind.
- Silly_Spray 6y agoThe scammer has got $100k and counting in less than 30mins. WOW 2020.
- trollied 6y agoLoads of accounts still tweeting it in realtime. Follow it live: https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh&src=typed_query&f=live https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...
- bentcorner 6y agohttps://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh%20filter%3Averified&src=typed_query&f=live https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8... Added "filter:verified" to query Edit: Add @JoeBiden to the list.
- jonny_eh 6y agoWow, it's not just big accounts, it's like anyone or everyone.
- 1-6 6y agoHow do we know that it's not the actual OP trying to pose like a big account target?
- lgats 6y ago
- AgentK20 6y agoJeff Bezos just got hit as well: https://twitter.com/JeffBezos/status/1283508547897171969 https://twitter.com/JeffBezos/status/1283508547897171969
- tass 6y agoBezos now, too! https://twitter.com/JeffBezos/status/1283508547897171969 https://twitter.com/JeffBezos/status/1283508547897171969
- tass 6y agoSearching for the bitcoin address in twitter gives an absolute ton of results. Are all these accounts hacked, or are people now posting just to joke around?
- stefan_ 6y agoLove how they don't just ban the bitcoin address. Firehose big data my ass. No one at home at Twitter.
- actuator 6y agoWouldn't they just change the address, it ain't like creating an address has a cost
- jazzyjackson 6y agonpm i bitcoin-regex
- stickfigure 6y agoTemporarily block anything that matches the format of a bitcoin address?
- Ajedi32 6y agoThen they'll just start obscuring addresses by interspersing them with spaces or posting links to third-party sites containing the address. It's an unending game of cat and mouse. IMO Twitter's efforts at this point are much better spent on finding out how the hack occurred and cutting it off at the source.
- 6y ago
- WarOnPrivacy 6y agoThe domain associated with first round of tweets wasn't anonymized. Could be a setup https://twitter.com/jfbsbnix/status/1283487977591767041 https://twitter.com/jfbsbnix/status/1283487977591767041 Or maybe a dodge https://twitter.com/verretor/status/1283506654521094146 https://twitter.com/verretor/status/1283506654521094146
- tschwimmer 6y agoI couldn’t imagine this being anything other than misdirection. All major registrars do anonymization for free as an opt out. You can manage to fully compromise a giant company but are stupid enough to untick aN important box? Not likely.
- throw_m239339 6y agoShould Twitter start supporting cryptographically signed messages? In any case, I wonder about the legal ramifications of this kind of event, for Twitter and for the individuals that have been hacked.
- rnhmjoj 6y agoThere is no loosing in doing so: just put a padlock on verified mesages and show the signing key. If the message sounds fishy and it's not verified then you should start worrying. We've had the technology to avoid these sort of issues for decades and it's a shame it's still largely unused. Yeah, I know the argument PGP usability is really bad but it doesn't mean Twitter or other network used as official channels can't provide their own friendly interface and start signing/verifying messages, they certainly have the resources.
- ISL 6y agoOh wow, now they're doing multiple tweets/minute: https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh&src=typed_query&f=live https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8... It might make sense for Twitter to redirect all non-retweets of that address to /dev/null (or a sandbox) for a little while.
- adjkant 6y ago"Something something blockchain bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh"
- kartayyar 6y agoJeff Bezos too. https://imgur.com/a/Zd668ao https://imgur.com/a/Zd668ao
- pwdisswordfish2 6y agoPoll: Will this affect your trust in Twitter as a source of information? If no, why not?
- jsnell 6y agoJust what kind of an operation is Twitter running here? It seems crazy that they don't have any kind of anti-abuse system in place that could just block tweets with this specific Bitcoin address or possibly tweets matching the regexp of any Bitcoin address. I.e. limit the damage and buy a couple of hours while they try to find the root cause. (Yes, yes, staged rollouts. But anti-abuse systems don't work by those rules, at least in emergencies.)
- actuator 6y agoYeah, I would have guessed a platform like Twitter would have anti-abuse systems with at least term filters.
- Barrin92 6y agoAt this point I'd advocate for a huge red button or a gong that someone can smash and it just halts the platform
- jsnell 6y agoKill-switches are dangerous, since they get built and never get used. I work on an anti-abuse system. It caused two user-visible outages in the last couple of years, one of which was an accidentally triggered kill-switch that had not been used in years and had some unexpected side-effects. So I can see why they wouldn't have one of those pre-built for setting the entire site to a read-only mode. It's not at all obvious whether the risks are larger with or without that capability built in. But a spam filter with configs you can push quickly seems like table stakes, and should be a system that gets excercised weekly if not daily.
- catalogia 6y ago> Kill-switches are dangerous, since they get built and never get used. What about the circuit breakers at their data centers? Serious question..
- MattGaiser 6y ago
- pfarnsworth 6y agoHow did they possibly steal Elon Musk's Twitter account? We need a post-mortem on this because if he can be phished, then we need to know how, and if it was some internal hack then I also need to know how. That's extremely scary!
- stockholm 6y agoTwitter should just ban all Btc address posting momentarily until this is solved
- adjkant 6y agoListing some out that I've seen: @Apple @Uber @elonmusk @kanye @MikeBloomberg @JoeBiden @WarrenBuffet @wizkhalifa @BarackObama @JeffBezos @MrBeastYT @FloydMayweather @LuckyovLegends @xxxtentacion
- neurostimulant 6y agoWith so many accounts compromised, the hackers might actually have full access to Twitter's backend. The postmortem would be very interesting. I'll be looking forward to it. Imagine if the hackers timed the intrusion during github outage, and twitter's employees can't deploy a fix for the exploit fast enough because github was down!
- kyleee 6y agoboy I sure hope we get a juicy post mortem, this is quite a scam
- whoisjuan 6y agoAnd it seems that it's still compromised. Tweets get deleted and then they re-appear.
- slezyr 6y ago> All Bitcoin sent to my address below will be sent back doubled. If you send $1,000, I will send back $2,000! > Only doing this for the next 30 minutes! Enjoy. No, it's hacker's doing, they need to keep timestamps updated
- Narretz 6y ago30 minutes later and it still happens, just after "Elon" posted a normal message. Hopefully most users have caught on to the scam by now.
- except 6y agoThe attacker must have added some high level access, for it to be still ongoing.
- d--b 6y agoWhy isn't twitter taking its infrastructure down?
- retox 6y agoIt would be cheaper for twitter to refund every person 10x what they sent than to shut down the entire site.
- Nextgrid 6y ago[citation needed] Their reputation and the post-mortem/cleanup effort of this hack already wiped out a significant chunk of their advertising profit. Taking down the platform for one day would be a drop in the bucket in comparison. They are causing extreme damage to lots of high-profile people's reputation every second the platform is kept active. I wouldn't be surprised if lawsuits appear as a result of this. Taking down the entire platform would be safer and would at least stop the damage.
- _____-___ 6y agoNo. No it wouldn't. Trust is priceless and they're losing it by the minute.
- chki 6y agoWouldn't it be possible to block this attack by flagging all tweets containing the Bitcoin address in question? I would've assumed that Twitter could do something like this, maybe even already set up an automated system.
- RandomBK 6y agoTreating the symptom and not the cause. The scam itself is (arguably) less damaging than whatever the hacker(s) can do with the access they've obtained. Block bitcoin addresses, and they'll move on to different types of messages.
- deleted 6y ago[deleted]
- leeoniya 6y agohard to feel sorry for anyone who falls for this.
- davidlee1435 6y agoKudos to Coinbase- I tried sending a small amount to the account after seeing Elon Musk's tweet, and Coinbase prevented the transaction from occurring.
- celticninja 6y agoWhy would you do that?
- benjohnson 6y agocuriosity value > fractional bitcoin value
- celticninja 6y agoIt's also validates the scam for other users. When they see BTC being sent they are more likely to think it is genuine. I can see sending dust to track the coins but other than that it's a damn foolish idea.
- MattGaiser 6y agoYou can't stop stupid.
- epanchin 6y agoI imagine there’s only a small overlap between users that know how to track transactions, and those that would fall for this.
- SkyBelow 6y agoI'm actually kind of interested in exactly what sort of overlap that would be.
- deleted 6y ago[deleted]
- 6y ago
- deleted 6y ago[deleted]
- WarOnPrivacy 6y agoJoe Biden's turn https://twitter.com/JoeBiden/status/1283512317846659073 https://twitter.com/JoeBiden/status/1283512317846659073
- creaghpatr 6y agoDoes that make it election interference?
- WarOnPrivacy 6y agoWINterference !
- rsanheim 6y agoWTF. I'm baffled. How have they not either * thrown the site in read only mode OR * taken the entire site down Until they can fix the security vulnerabilities. That would be better than what is happening now.
- caiobegotti 6y agoI'm honestly surprised that Twitter doesn't have some sort of circuit breaking for such gigantic attack towards major accounts. It's a PR nightmare that a circuit breaker would help a bit with, no?
- puranjay 6y agoConsidering that Twitter has taken a decade and not managed to create a functional web media player, something like a circuit breaker is probably low on their priority list.
- perryizgr8 6y agoI still haven't figured out the correct way to watch a video on twitter. I always have to mess around with the mute button, seek back to start of video, etc.
- puranjay 6y agoOn Chrome, it won't even load up most of the time. Press play and it shows a "failed to load media" error message. I have to refresh the page to get it to work. I've completely stopped playing any media on Twitter. Twitter and Reddit's tech incompetence absolutely baffles me. How are billion dollar companies not able to make functional video players?
- teknopurge 6y agoExchanges should[can] blacklist the address.
- saagarjha 6y agoExchanges are blacklisting the address.
- VikingCoder 6y agoWatch this turns out to be a JS dependency tree problem from some library that was compromised months ago in some NPM module, used in the twitter web interface.
- Wingman4l7 6y agoI love this theory, but at the same time, I feel that it's unlikely. Without knowing how their back-end is put together, that'd be like... trying to smuggle in a robot into an office building to break into a safe that's inside without knowing the floor plan, what kind of knobs are on the doors, etc.
- marcinzm 6y agoCould have paid/convinced/threatened an intern/employee to scope it out and then deployed the hack externally to bypass safety measures. Complicated but doable.
- 0x00000000 6y agoOr disgruntled ex-employee
- madeofpalk 6y agoGiven the Twitter web interface is just an client of the Twitter semi-public API, I highly doubt this is it.
- ehsankia 6y agoAs long as the API isn't running on node, right? :)
- VikingCoder 6y agoI'd suspect the web interface has UI that's wrapped around the semi-public API. It's that web interface I'm worried about.
- 6y ago
- vmception 6y agoMy bet is on one of those social media managers like Hootsuite/Social Blade/Buffer getting hacked.
- blocked_again 6y agoProbably not. A lot of accounts with hardly any followers are also tweeting the scam. Search the bitcoin address to see the tweets in real time.
- bfm 6y agoLooks like Hootsuite Twitter integration has been having issues for 50 mins now https://status.hootsuite.com/post/623750375373160449/twitter-publishing-issues https://status.hootsuite.com/post/623750375373160449/twitter....
- vmception 6y agoI’m currently leaning towards Twitter tried a bunch of things to stop this and hootsuite got caught in the fray Or maybe it was a multipronged attack that included social media management software and OAuth but the hilarious most visible solution is that Twitter now disabled all verified accounts and they should keep it that way
- bfm 6y agoYou're probably right. After reading through https://twitter.com/TwitterSupport/ https://twitter.com/TwitterSupport/ it looks like Twitter has been disabling some features. And according to https://twitter.com/louanben/status/1283518716118958080/photo/1 https://twitter.com/louanben/status/1283518716118958080/phot... the @TwitterSupport account was also affected. I doubt they use a system like HootSuite for that account.
- miguelmota 6y agoHackers still actively tweeting out from everyone's accounts https://twitter.com/search?q=All%20Bitcoin%20sent%20to%20the%20address%20below%20will%20be%20sent%20back%20doubled&src=typed_query&f=live https://twitter.com/search?q=All%20Bitcoin%20sent%20to%20the...
- admn2 6y agois it just me or are they now mass altering users' names? https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh&src=typed_query&f=live https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...
- Macha 6y agoNot sure if the hackers are doing that or people are just trying to get attention from the search results e.g. tweets like this look like people are consciously looking for attention: https://twitter.com/Statist_Sam/status/1283533522536411136 https://twitter.com/Statist_Sam/status/1283533522536411136
- miguelmota 6y agoAt this point people are only doing it for trolling reasons
- deleted 6y ago[deleted]
- rsecora 6y agoThey are posting to almost every other account, high profile or not. Its a massive spam, too much users to be a password steal. About the client, they are post from accounts that have only used "Twitter for Web" or only used "Twitter for Mac" or only used "Twitter for iPhone"... in the past Updated accounts with the spam. https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh%20filter%3Averified&src=typed_query&f=live https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...
- nonbirithm 6y agoIt's amusing that this is so successful only because of all the people posting their triumphant screenshots of success in losing all their money. All it takes is 100 gullible people to net $100k, and there's a lot more than 100 gullible people on Twitter. And it all happened in the span of 20 minutes. Can we expect any better response in the hopes of preventing this next time assuming all the accounts are hacked already? Or does the nature of realtime media and hundreds of bored eyes sitting on wads of cryptocurrency getting to it first mean it's just game over? I remember the golden days of messing up people's lives over digital terminals, where the most they'd do was wipe your harddisk or warn the user of something vaguely ominous on the third Tuesday of April like "the Reaper's gonna get you" or play an 80's Top Ten number rendered through the PC speaker all of the sudden scaring you to death. From here on out it's always going to be about money, and to me that's just boring and sad.
- s5300 6y agoYou're going to regret this post when a world leaders twitter says: "Nukes Incoming, hide yo kids, hide yo wives" one day...
- rsa25519 6y agoObama https://twitter.com/BarackObama/status/1283515490653147139 https://twitter.com/BarackObama/status/1283515490653147139 Also: - Musk - Bill Gates - Apple - Uber - Jeff Bezos - Joe Biden - MrBeast
- Nextgrid 6y agoWhen it comes to MrBeast I think this is where the most damage/payout could be achieved because MrBeast is popular for literally giving money away.
- WarOnPrivacy 6y agoand Obama https://twitter.com/BarackObama/status/1283515490653147139 https://twitter.com/BarackObama/status/1283515490653147139
- pier25 6y agoBarack Obama too: https://imgur.com/a/KGTEQNt https://imgur.com/a/KGTEQNt
- break_the_bank 6y agoObama just tweeted out the same thing. It seems all of twitter has been hacked. The post mortem will sure be interesting. Also interested in how TWTR gets affected.
- MattGaiser 6y agoObama too: https://twitter.com/BarackObama/status/1283515490653147139 https://twitter.com/BarackObama/status/1283515490653147139
- zone411 6y agoI wonder what the automated trading bots tracking these accounts did. Will Twitter get sued by the people who fell for this scam? By the people who got hacked?
- babuloseo 6y agoGet the popcorn!
- throw_m239339 6y agoYour site is getting hacked, you don't know how the hackers are doing it, what do you do ops wise? Take the whole site down for a few hours? Because the entire platform is compromised, how do you handle that?
- rsanheim 6y agoYes, of course. Take the site down if you don't have a read only mode or something. You are losing millions in trust every minute this hack goes on.
- cryptoz 6y agoIndeed, already billions in trust lost so far, guessing by the ~4+% after-hours TWTR drop.
- throwaway43234 6y agoTo be fair, it's still higher than yesterday's low. It's not like TWTR is known to increase over time anyways.
- eternalban 6y agoThis is possibly a blessing in disguise. Obama and Biden's accounts have been hacked as well so this basically just burned Twitter as an international political platform. Following that thought, it is entirely possible the whole point of the hack is to discredit Twitter and the bitcoin bit is just smoke.
- jcims 6y agoThey just disabled posts from verified users.
- mlindner 6y agoYes, but it took them nearly 2 hours to do that, in the middle of the work day no less.
- anigbrowl 6y agoI've seen the groundwork for this over the last 6-8 weeks, with 'people' (questionable-looking accounts) retweeting screenshots of similar-looking tweets purporting to be from Elon Musk, and other similarly fishy accounts going 'wow it really works' or the like. I noticed them showing up consistently in replies to Trump tweets, probably just because they get tons of engagement.
- Nextgrid 6y agoThose have been going on for years. They clearly demonstrate Twitter's incompetence (which seems to have culminated today) since they were very easy to filter out with a simple regex, but I doubt they are related to this attack.
- DevX101 6y agoI could imagine a faked tweet attributed to Trump that could immediately begin mobilization in other countries to prepare for war. There are several fake tweets from the Bezon/Musk I could imagine that could credibly send the stock price of AMZN down by 10%, TSLA down by 50% in a matter of minutes. Attacker(s) could profit immensely if they had leveraged short positions cleverly placed. Users losing a few hundred thousand is getting off light considering the severity of this attack and how much worse it could have been.
- PatrolX 6y agoTwitter is seriously out of control. They should have pulled the plug an hour ago, and that plug pulling should have been automated. If this were something even more sinister a whole country could have plummeted into chaos, death, destruction.
- Covzire 6y agoSeriously, this hack should inspire the most terrifying Black Mirror episode yet.
- PatrolX 6y agoImagine what "could have been" done. Simultaneous compromise leading to tens or hundreds of millions of people receiving the same / similar messages for over an hour from the people they trust the most. Death and destruction waiting to happen.
- lgl 6y agoWhich really puts into perspective the amount of power we have placed on social media. I wonder if this will spark a #deletetwitter movement?
- xxr 6y agoImagine something of this magnitude combined with well-voiced (or silent and subtitled) high-effort deepfakes.
- noobmax 6y agoI believe someone twitter admin users account was hacked who maybe has access to tweet anything from anyone's account. Twitter passwords/system is safe IMO.
- jf- 6y agoThis is nuts, Twitter is totally compromised and they haven’t pulled the plug. Not confidence inspiring.
- jaxxstorm 6y agoI'm flabbergasted they haven't just hit the panic button and shut everything down. Unless, perhaps, they can't.
- jonny_eh 6y agoYou mean shutdown Twitter? I think that's a bit extreme in this case.
- jasoncartwright 6y agoIs it? They don't appear to know what will be hit next or how to stop it.
- kristofferR 6y agoThe hackers are changing the login information of the hacked accounts too, gonna require a massive amount of cleanup.
- dvt 6y agoIt's not too hyperbolic to say that WW3 could be started on a platform like Twitter. Having a "shutdown" button doesn't seem that extreme when essentially the entire site seems to be compromised. I'd bet my bottom dollar that Congressional hearings are going to happen.
- dvt 6y agoWhat blows my mind is how does Twitter not have a "maintenance" mode -- where no new tweets can be posted and the site is essentially read-only?
- one2know 6y agoCorporations don't do anything unless there is a executive sponsor and business need/attached revenue. Probably they have never needed a maintenance mode, aka self imposed downtime. The only thing worse that unexpected downtime is some manager causing the need to turn on maintenance mode. They would lose their job.
- adrr 6y agoWe had maintenance mode at MySpace. We could shutdown any part of the site with feature flags that can be turned on for ranges of users. Very useful for bringing back the site after an outage and allow the caches to fill without overloading the underlying dbs. I am sure twitter has the same, they had scalability issues at the beginning . I guarantee they have a mode to disable posts and mode to disable authentication so they can recover the underlying systems .
- jayflux 6y agoMaybe they do and they haven’t needed to resort to that yet?
- raldi 6y agoWhat makes you think they don’t? We had one on Reddit in 2008.
- fortran77 6y agoThis doesn't make me feel any better about Bitcoin as a platform/product.
- BiteCode_dev 6y agoGiven how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.
- quonn 6y agoIt can‘t really be the first three, because Twitter will fix this problem soon. So it would be wasting the exploit. It‘s either incompetence or your fourth option.
- epanchin 6y agoI read about this in the news before I saw it in my Twitter feed. My trust in Twitter has dropped severely. Why weren’t these tweets deleted immediately and a note pinned to every users feed?
- CamperBob2 6y agoArguably it was irresponsible of Twitter not to pull the plug on the servers at the first hint of an exploit at this scale. When you literally have no idea what's going on, job #1 is to keep it from getting worse.
- jonny_eh 6y agoOr a distraction while a bigger hack is going on?
- woeirua 6y agoBingo, they're probably walking away with all of Twitter's internal data as we speak...
- 6y ago
- aliabd 6y agoDo we think scammers also have access to the hacked account’s DMs?
- aqme28 6y agoAbout $110k in the address. Honestly not that impressive for a hack of this scale. I wonder what they could have gotten if they reported this for a bug bounty instead. Or as Matt Levine said, "if I got Elon Musk's twitter password I'd wait until market hours to use it."
- jonny_eh 6y agoTwitter right now: https://twitter.com/i/status/1283517347894980610 https://twitter.com/i/status/1283517347894980610
- justicz 6y agoJust imagine if Trump’s account were hacked to indicate that the US is launching a missile towards North Korea. Or maybe a message to encourage some kind of armed uprising in the US. Hacking the right Twitter account could easily have massive life-and-death consequences. Isn’t that terrifying?
- awake 6y agoLooks like hackers got approx 60K. Anybody know how that compares to bug bounties at Twitter?
- 6nf 6y agoUp to 7 million dollars now
- zelly 6y agoWork from home wouldn't backfire, they said.
- WarOnPrivacy 6y agoI love the internet so much right now.
- deft 6y agoThe attack is ongoing. Why haven't they 1) shut down api endpoints 2) locked down all verified accounts 3) blocked any tweets with the btc address in them 4) make a statement if they really can't stop it?
- codesternews 6y agoSecurity is myth
- Me1000 6y agoIt would be incredibly irresponsible if there isn't a team at Twitter right now working to bring the whole site down. It's one thing going after a couple celebrities and CEOs, but they've now hit a former US President and a current Presidential candidate.
- qeternity 6y agoA lot of people (rightly) pointing out that the actual exploit payload here is a horribly inefficient way to monetize such awesome power. Some of the replies that influencing regulated markets would be traceable...sure, but trillions of dollars flow through these markets each and every day. A decently large options position accumulated over days wouldn't raise any red flags, and one tweet about the Fed raising rates on the back of strong employment + vaccine hope would have sent markets into a tailspin. The reality is that it would be much more difficult to identify bad actors than it is with public crypto addresses. And your money is clean at that point, part of the US financial system (or other tier 1 banking system).
- lazyjones 6y agoSo... What if this is just massive distraction for a Twitter content manipulation of some sort, like making some tweets disappear or incriminating some people with malicious content?
- techaddict009 6y agoHas Twitter's forever WFH policy resulted in this Zero Day Vector or Whatever it is! Which has resulted in Hacking of So many big Accounts and Bitcoin Scam?
- Acrobatic_Road 6y agoWhat could have been the best prank of 2020 wasted on a bitcoin scam. If it were me, I'd try to start a war or two as the ayatollah, or maybe make some unplanned celebrity trump endorsements. Wasted potential.
- fortran77 6y agoI can't imaging some of those hacked people not having extremely good security habits. 2FA, long unique ramdom-generated passwords not used anywhere else, and secured phones that would be hard to do a SIM swap on. Which leads me to believe someone has really hacked twitter in a bad way or there's someone on the inside helping them.
- deleted 6y ago[deleted]
- DevX101 6y agoTwitter should suspend the entire platform until they can credibly fix this and prevent it in the future. An attacker could drop AMZN stock by 10% in minutes with just the wrong tweet from Bezos.
- PatrolX 6y agoIf they don't do that soon then expect POTUS to seize control of it.
- baxtr 6y agoEven worse? How about POTUS declares war on China thru twitter? OMG, I just realized how dumb that would have been to say back in 2016. But these days?
- hn3333 6y agoThat's assuming Tweets actually serve an actual diplomatic function and are not merely marketing/propaganda for voters. (Also POTUS is not authorized to declare any wars btw.)
- saagarjha 6y agoOk, mass panic then?
- mattigames 6y ago> That's assuming Tweets actually serve an actual diplomatic function and are not merely marketing/propaganda for voters. He has fired people over twitter [0] so I'm not sure the scope of one can do there is limited to "marketing/propaganda" > (Also POTUS is not authorized to declare any wars btw.) Other nations are not going to read the US law first before deciding if the declaration was or not real. [0] https://www.theverge.com/2018/3/13/17113950/trump-state-department-rex-tillerson-fired-tweet-twitter https://www.theverge.com/2018/3/13/17113950/trump-state-depa...
- Alupis 6y ago
- staycoolboy 6y agoI really HOPE the details of this hack become public, because this is huge. (I can already hear celebs who say dubious things trying to claim they were hacked.)
- mekkkkkk 6y agoIs it just me, or does this seem suspiciously poorly thought out? Perhaps there is a second stage involving stock plays. The BTC thing might be a diversion. Or we are incredibly lucky and the exploit was found by people with really bad foresight and imagination.
- Scoundreller 6y agoOr it's been exploited for months/years to read people's DMs and private accounts and they decided to burn it now mostly for lolz?
- mekkkkkk 6y agoThat would be so incredibly stupid. Burning a money machine of that magnitude for lulz? I don't think anyone would do that.
- Scoundreller 6y agoSometimes relationships fall apart and things get ugly.
- vanshg 6y agoPurely speculation, but the exploit could be tied to the APIs that they are deprecating today. It's possible that this is simply a last hurrah
- cwkoss 6y agoInteresting thought. I was thinking that an access token was about to expire, but I like your theory better.
- XCSme 6y agoIt was mentioned in another comment that something like a new Twitter API is released tomorrow, so maybe one of the last chances to use the exploit?
- 6y ago
- thatwasunusual 6y ago> With so many accounts compromised, the hackers might actually have full access to Twitter's backend. This.
- 1-6 6y agoDid someone gain access to the Twitter building in SF while everyone was away?
- lpellis 6y agoDoes this mean they can also login to any account connected with OATH. Many sites allow Twitter auth.
- techaddict009 6y agoSeems like the hacker has got 100% access to Twitter's backend and is just not able to decide whom to attack next! One after another big handles getting hacked! Collection till now has crossed 12 BTC (https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n...)
- clarkmoody 6y agoThere is definitely a big red button at Twitter that somebody should have pressed an hour ago.
- blisseyGo 6y agoStrange coincidence tweet by Jack Dorsey from last evening: https://twitter.com/jack/status/1283169859233214465 https://twitter.com/jack/status/1283169859233214465 > #bitcoin @BubbaWallace
- AzzieElbab 6y agoCan't help imagining twitter engineers holding the last line of defense between the hackers and trumps account.
- the_svd_doctor 6y agoAre very high profile accounts (like Trump) more secure than a usual password + 2FA, somehow ? EDIT: Not that it would matter here. Just curious.
- admn2 6y agoSomeone on here said Twitter set up some special security for just his account
- dsr12 6y agoHackers still posting using Elon's account: https://twitter.com/elonmusk/status/1283520825782566912 https://twitter.com/elonmusk/status/1283520825782566912
- pagade 6y agoElon Musk again - https://twitter.com/elonmusk/status/1283520825782566912 https://twitter.com/elonmusk/status/1283520825782566912
- dsr12 6y agoTwitter support tweeted: "We are aware of a security incident impacting accounts on Twitter. We are investigating and taking steps to fix it. We will update everyone shortly."
- totony 6y agoAll in all that looks like a poorly thought out attack. So much more could've been done than cryptoscam. Considering execution, it may be that this is some API 0day which does not show (or make it hard to guess) which account messages are being posted from. How else would you explain neutral messages for all account when you could've personalised it per account to maximize efficiency.
- cookie_monsta 6y agoDoes this mean that Twitter is now not to be trusted?
- Laforet 6y agoI have a couple of services that run on twitter API and they have all been suspended in the last half hour. They are definitely in damage control mode.
- riffic 6y agoThis is what happens when you put all of your communication eggs into a single basket. Twitter needed to be taken down a couple of pegs. I think accounts of a high enough profile may want to closely examine the ActivityPub ecosystem.
- qrbLPHiKpiux 6y agoUs politicians using twitter to communicate en masse is irresponsible in of itself. So unprofessional
- tehwebguy 6y agoYes, they should make the constituents come to them! What?
- eternalban 6y agoIt's called a website. Office holder communicates via his office's offical website. Constituents have email addresses he can email. S/he can setup a slack/zoom/irc channel and have a constituent "town hall". Tweeting is actually effectively reducing the available bandwidth of communication, and quality of content.
- tehwebguy 6y agoThey do all of the things you mentioned, but some of the people are on social media.
- delfinom 6y agoOn the other hand, the average person doesn't have the bandwidth to track and follow 50 separate websites for the politicians that affect them.... Like in my case, there's the local village council made of 5 members, theres the town council the village is part of, the county has its own board/council, and then theres the state house and state senate and then theres the US house and US senate, and the finall president.
- justinzollars 6y agoInstead of putting so much engineering time into pushing a political agenda, twitter should focus on security and identity improvements.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- justinzollars 6y agohttps://twitter.com/NorthmanTrader/status/1283516339768918017 https://twitter.com/NorthmanTrader/status/128351633976891801...
- webXL 6y ago$113k scammed and counting.... Why is twitter still in write mode??
- elwell 6y agoAll @apple tweets removed? @Apple hasn’t Tweeted When they do, their Tweets will show up here. https://twitter.com/Apple https://twitter.com/Apple
- blocked_again 6y agoApple don't post regular tweets. They only use sponsored tweets.
- zacwebb 6y agoThey never had Tweets
- firloop 6y agoYep, Apple only used that account to run ads on.
- ipython 6y agoHow is this different from the persistent “Elon Musk” btc giveaway posts that find their way onto every one of Trump’s tweets?
- Nextgrid 6y agoThose were using fake accounts attempting impersonate the real ones. This is the real accounts tweeting the scam.
- shaabanban 6y agoImagine for a moment that this ends up being something state-sponsored or that twitters entire DB gets dumped, private accounts and all. This could have a profound impact on governments who want to target dissidents if somebody for example, only felt comfortable criticizing their government from a protected account...
- byteshock 6y agoSeems like they reposted it on the cash app account. This time it’s a different address. New Address: bc1qwr30ddc04zqp878c0evdrqfx564mmf0dy2w9l https://mobile.twitter.com/CashApp/status/128352200769559757.. https://mobile.twitter.com/CashApp/status/128352200769559757....
- PatrolX 6y agoExpect POTUS to go to DEFCON 1 and seize control of Twitter any second now.
- break_the_bank 6y agoWhy is twitter optimizing uptime instead of trust? Trying to figure out why would they let such a massive hack play out for over an hour instead of pulling the kill switch.
- lesderid 6y agohttps://twitter.com/TwitterDev/status/1283068902331817990 https://twitter.com/TwitterDev/status/1283068902331817990 Hmm.
- chki 6y agoYep, that won't be a coincidence. Also a bit relieving because this means that probably there was no access to DMs etc. before the rollout of this feature.
- NegatioN 6y agoIf this is the case, the simple bitcoin scam might make sense as a quick way to cash in before an obvious exploit is patched? Compared to the speculation of hidden agendas at least. I feel like a bug report might make more sense in that case though...
- epanchin 6y agoThis would be sweeter if TwitterDev was now compromised.
- deleted 6y ago[deleted]
- WarDores 6y agoMultiple folks on Twitter saying all verified accounts have been locked.
- retzkek 6y ago> “I am giving back to my fans. All Bitcoin sent to my address below will be sent back doubled.” So Twitter is the real-life Jita local chat? Does this also mean BTC is as meaningless as ISK, that people are willing to gamble it on a doubling scam?
- ericmay 6y agoI also got an email verification request for an old Reddit account I didn’t even remember having. Take a look there too. It happened at the same time.
- p0rkbelly 6y agoI definitely think this is China shooting a shooting a warning shot across our bow. Would be sabre-rattling after yesterdays EO against china. "You have no idea how compromised you are. You're lucky we did not go after POTUS account."
- ericmay 6y agoDon’t buy it. No advantage to revealing your capabilities.
- jacquesm 6y agoWhoever did this is going to have a serious price on their heads. I doubt the pay off is worth it unless they are a state actor flexing their muscle.
- Firebrand 6y agoIt appears Twitter has now prevented verified accounts from posting. Us schlubs can now run the asylum for a while.
- sleepyshift 6y agoIn an attempt to mitigate the damage, Twitter appears to have blocked verified accounts from sending tweets.
- PatrolX 6y agoVerified Twitter accounts can no longer Tweet while incident is being dealt with.
- WarOnPrivacy 6y agoPosts stopped for the other btc address (bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh) Here's a tweet from KimKardashian, for a different BTC address (bc1qwr30ddc04zqp878c0evdrqfx564mmf0dy2w39l) https://twitter.com/KimKardashian/status/1283523054874877953 https://twitter.com/KimKardashian/status/1283523054874877953
- xiphias2 6y agoHow can it be still up after so much time? The response time from the SREs is extremely bad.
- WarOnPrivacy 6y agoIKR? We expected so much more from anything Kardashian
- _____-___ 6y agoWell, another post said they changed the emails of accounts affected. So they probably can't personally do anything about it.
- blablablub 6y agoSo Twitter's killswitch is that verified accounts cant tweet any more... Vive la plebs!
- benlumen 6y agohttps://twitter.com/brandontwall/status/1283525485440503811 https://twitter.com/brandontwall/status/1283525485440503811 Hours in, seems the vulnerability was not yet patched but simply blue-checks had posting rights pulled. Only non-verified accounts have been posting the wallet key for a while now (search new to find them). I know it's easy to judge from afar but I can't believe they're leaving the site up during this.
- withinrafael 6y agoVerified Twitter user here: Locks [1] are in place, attempting to tweet throws an error: Something went wrong, but don't fret -- let's give it another shot. At the bottom of the page, a notification appears: This request looks like it might be automated. To protect our users from spam and other malicious activity, we can't complete this action right now. Please try again later. [1] https://twitter.com/TwitterSupport/status/1283526400146837511 https://twitter.com/TwitterSupport/status/128352640014683751... Direct Messaging is still functional as of 523PM PDT.
- withinrafael 6y agoUpdate: Can tweet again, locks have been removed [1]. [1] https://twitter.com/TwitterSupport/status/1283562446196596737 https://twitter.com/TwitterSupport/status/128356244619659673...
- chadlavi 6y agoI'm an unverified nobody and the same thing happened to me, was unable to tweet up until about 8pm EDT.
- scrose 6y agoI wonder what a bug bounty for something like this would have paid out.
- sleepyshift 6y agoI wonder whether this is just write-only, or if they've been able to read private data (like DMs) too.
- techaddict009 6y agoFinally Twitter wakes up and Twitter support tweets: "You may be unable to Tweet or reset your password while we review and address this incident." Not clear who is You here, all accounts are just verified or selected accounts.
- londons_explore 6y agoNotable that Trump is not impacted. If you had backdoor access to any Twitter account, why on earth wouldn't you tweet as Trump?
- Nextgrid 6y agoI have heard that Trump's account has extra protections around it that presumably prevent even staff from accessing it, in which case if this was a staff account compromise it would make sense that they can't touch Trump's account. Another possibility is that they are indeed just after the money and compromising Trump's account would prompt a faster response from Twitter (possibly taking down the entire account or platform) and reduce the effectiveness of the scam.
- burfog 6y agoTrump's account might have been the final one targeted, locking the attacker out from messing with any additional accounts. If a Twitter employee is messing with famous accounts in an unauthorized way, automatically stopping the employee would be reasonable. I've heard of this feature existing with the software used by phone companies and hospitals. Employees who poke around looking at famous people soon get locked out of the system.
- dang 6y agoAll: don't miss that there are multiple pages of comments. The top few subthreads have become so large that they fill out the first page entirely. You have to click 'More' at the bottom to see the rest, including a lot of the newest posts. Or use these links: https://news.ycombinator.com/item?id=23851275&p=2 https://news.ycombinator.com/item?id=23851275&p=2 https://news.ycombinator.com/item?id=23851275&p=3 https://news.ycombinator.com/item?id=23851275&p=3 https://news.ycombinator.com/item?id=23851275&p=4 https://news.ycombinator.com/item?id=23851275&p=4 Edit: also, there's a related thread tracking the BTC transactions here: https://news.ycombinator.com/item?id=23851542 https://news.ycombinator.com/item?id=23851542. In general, look for More links at the bottom of big threads. This is a performance workaround that we're hoping to drop before long, but in the meantime there's a limit of 250 or so comments per page.
- Scoundreller 6y agoInteresting how @Apple currently displays zero tweets at all. https://twitter.com/Apple https://twitter.com/Apple
- satkin 6y agoLooks like verified users can tweet again: https://twitter.com/TaylorLorenz/status/1283531947877294082 https://twitter.com/TaylorLorenz/status/1283531947877294082
- dluan 6y agofor 15 minutes society was perfect, i felt invigorated and had the ability to dream new dreams, and we were all loving friends. and then the blue checks came back.
- vbsteven 6y agoSounds like the outro for Bonjour Tristesse - The end of the world.
- deleted 6y ago[deleted]
- gfrangakis 6y agoEveryone say a prayer for Twitter engineers trying to fix this tonight
- caretak3r 6y agoIt's so easy for a Twitter user to use a a later compromised 3rd party app, only having to press a button to authorize the entire oauth chain. Look at hosted packages or artifacts in dockerhub, GitHub, ruby, pypi, etc. Malicious things like this are everywhere, dormant on systems until the right group can leverage against end users. Imagine if tweekdeck was compromised.
- blisseyGo 6y agoTweet from TwitterDev team yesterday: https://twitter.com/TwitterDev/status/1283068902331817990 https://twitter.com/TwitterDev/status/1283068902331817990 > 2 days to go… #TwitterAPI https://twitter.com/TwitterDev/status/1283433096780677122 https://twitter.com/TwitterDev/status/1283433096780677122 > Thank you to all of you who have engaged with us and shared your feedback. Your input has been vital, and we’re committed to continuing these conversations with you. There’s so much more we’re doing to build a better #TwitterAPI… and Early Access is coming tomorrow! Were they supposed to launch some new API tomorrow which got hacked?
- dmix 6y agoNice catch, this may be what it was. Edit: looks like an admin panel was the culprit https://news.ycombinator.com/item?id=23853786 https://news.ycombinator.com/item?id=23853786
- ryanisnan 6y agoEarly access wasn't supposed to be enabled until tomorrow. I wouldn't speculate until they give a post-mortem.
- Solvitieg 6y agoI don't understand this angle because typically admin panels only let you manage the account; deactivate, manage email address, etc. As shown in the screenshots. Tweeting on behalf of another user seems like an unnecessary feature to give admins.
- embit 6y agoI am sorry but either from the article or discussion here, I am not exactly clear what has happened. Can someone explain ? Meaning did the user accounts on Twitter got hacked or the actual company websites ? Or both ?
- arp242 6y agoAt this point, no one really knows much other than that they've managed to get several prominent Twitter accounts to post scam messages. There were also replies posted and tweets pinned and recovery emails reset, so the attack seems deeper than just "ability to post a new tweet". Some accounts were protected with 2FA, so it probably is some exploit in the API which affects many accounts (possibly all?), some intrusion in the Twitter infrastructure, or some exploit which allows people to hijack accounts. But that's really just an educated guess. Considering it doesn't seem fixed yet, I'm not even sure the Twitter people have a complete understanding of what's going on yet.
- jacquesm 6y agoThe title is inaccurate. The Twitter accounts hacked are far more important than just a couple of prominent cryptocurrency accounts. Obama is in there, Jeff Bezos, Bill Gates and many other prominents that have nothing to do with crypto.
- paul_f 6y agoThis entire thread and not one mention of 4Chan. Why isn't this simply an insider with a few friends doing this for fun?
- aeyes 6y agoIs the attack now changing usernames to the BTC address or are these people just trolling? https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh&src=typed_query&f=live https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...
- brunoluiz 6y agoJust imagine if they have to shutdown twitter momentarily —- it has been a long time since the last big fail whale
- gmngmn22 6y agoI guess an employee screwing up thing is easier to imagine now with everybody wfh
- blablafd 6y agoThanks BTC which make it true! BTC is the only thing that is totally useless and harmful!
- genidoi 6y agoChilling to imagine a tweet from Trump declaring a nuclear strike has been launched against China.
- woliveirajr 6y agoWorldwide verified accounts are now disable (can favorite and retweet but not post messages), and I imagine that soon we'll see unverified accounts also being targeted.
- korethr 6y agoSo, has twitter deleted all the bogus tweets at this point? I have clicked on multiple links just to see a bunch of context-less replies.
- VWWHFSfQ 6y agoThe hackers made more profit in 5 minutes than Twitter has in 10 years
- caretak3r 6y agoPeople who don't want scrutiny from their old tweets want an easy way to delete/wipe their tweets. There are a load of software out there that claim to do this. They all relatively take over the oAuth chain, and do the needful. But one of them does it as if you were in your browser. As to not give away information about the user's phone/type/version.
- Nextgrid 6y agoHow is this relevant to the unfolding disaster?
- caretak3r 6y agoHahah looks like it's getting closer: OAuth account takeover? https://twitter.com/LiveOverflow/status/1283511782380908545 https://twitter.com/LiveOverflow/status/1283511782380908545
- hosainnet 6y agoThis reminds me of Colin. Back in 2013 when I was working at Sky News, the person responsible for the social media accounts (with millions of followers in total) stormed into a meeting: "Our Twitter account has been hacked". This was at a time when many high-profile news Twitter accounts were hacked by so-called "electronic armies" who published damaging tweets. However in our case it was a single obscure "Colin was here" tweet. We had recently built an internal endpoint in one of the backend apps that takes a string and publishes it straight to the main breaking news Twitter account. This was integrated with a custom UI tool that the news desk people used to quickly break a story across TV, Twitter, the website etc with one click. I had a suspicion that this endpoint was how that tweet was published, but could not prove it. Many thoughts were going through my head.. “is this an internal job, or did someone hack our backend system and somehow figured this out etc.. “ We quickly returned to our desks, and straight away I greped our logs for "tweeting" as I developed that feature and was sure we logged that when the endpoint is called, but in the heat of the moment forgot that to “-i” as it the log message actually contained "Tweeting" (which cost us a few minutes). In the meantime there was panic around the business, people were putting out PR statements just in case it was a real hack, the tweet was deleted etc. Finally, with help from colleagues, we tracked down a "Tweeting" log message around the same time the tweet was published along with the HTTP request source IP, and traced it (just like in movies) to our secondary news studio in Central London. This is when one of the managers shouted "I know a Colin who works there, he's a testing team manager!". We gave Colin a ring to understand what was going on, he had no idea about any of this but said he was doing some DR testing earlier of all tools that editors use, and wasn’t really aware this would go out. As you can imagine, it could have been much worse. The entertaining bit was the 30 minutes of fame this mysterious Colin enjoyed on the internet, where many people were worried about the welfare of "Colin", and it was picked up by various [1] news [2] websites. [1] https://www.buzzfeed.com/lukelewis/an-important-history-of-the-colin-was-here-meme-that-changed https://www.buzzfeed.com/lukelewis/an-important-history-of-t... [2] https://www.buzzfeed.com/lukelewis/an-important-history-of-the-colin-was-here-meme-that-changed https://www.buzzfeed.com/lukelewis/an-important-history-of-t...
- solinent 6y agoEveryone here is suggesting a monetary motive. Maybe there's a political motive--someone who really hates Twitter or serves to benefit if Twitter suffers.
- wesammikhail 6y agoAnd this is how you make that happen? I can think of at least 400 ways off the top of my head of doing that without involving BTC or $$.
- jkhdigital 6y agoOr it’s just a good samaritan doing all of us a favor
- solinent 6y agoI agree, I'm not a fan of twitter.
- XCSme 6y agoMaybe it's Dr DisRespect's revenge.
- ycombonator 6y agoRelated https://news.ycombinator.com/item?id=23853786 https://news.ycombinator.com/item?id=23853786
- zetazzed 6y agoMy wild, unfounded conjecture: the attacker discovered this recently and had only a short, fixed time window in which to run a scam. Maybe the time before some maintenance update? So none of the more sophisticated approaches (like selling to the highest bidder or manipulating some stocks) were practical before the vulnerability would be repaired. If you imagine short notice and a couple-hour window when US markets were closed, are alternative hacks really that much more lucrative?
- meaydinli 6y agoPlease be kind to the people that are working on this problem, right now, at Twitter and the countless hours that will need to go into remedying it. Hopefully, an eventual post-mortem is gonna be juicy and then we can critique all we want.
- koolba 6y agoDid they send one out from Trump as well? Imagine the mayhem if they send out a notice that he’s resigning or that he is launching nukes.
- tedk-42 6y agoBtc address in the explorer to see how much was deposited https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n...
- swalsh 6y agoOh finally, some real news about hackers.
- totaldude87 6y agoHow many DM’s would have been read ... could it be for black mailing? Anyways would love to see a postmortem ( if Twitter shares such)
- chippy 6y agoeven the existence of a widely accessed internal admin tool that has the ability to read "private" DMs would shake things up
- ExcavateGrandMa 6y agoEPIC!
- surround 6y agoInstead of taking a screenshot, archive Tweets with https://archive.is/ https://archive.is/ before they disappear. (The Wayback machine doesn’t work with Twitter due to robots.txt)
- Keverw 6y agoWonder if this could have been done by a rogue employee at Twitter? Since they are working from home during COVID, wonder what internal controls they have? I know some wondered if they used serveral high profile accounts, why not the presidents then? Well Twitter put extra protections on his account after an employee on their last day decided to suspend his account for 11 minutes. So if this isn't an hack and done internally that might be a clue. I was surprised Apple especially got their account hacked, since they are big on security as a company. I know with Facebook a page can have multiple person accounts managing it, but I don't believe Twitter ever had such a thing unless more recently... So if you want multiple people to manage an account you'd use a special tool or just share the login info between your social media team. I kinda feel like if you have to commute to an office, maybe more accountability as I'd feel someone might be looking more over your shoulder but I'd depend if someone gets private offices or a more open office design.
- odomojuli 6y agoI do not think it is hyperbolic at all that I immediately just felt the hand move a full minute towards midnight. This is suspiciously underwhelming use of an exploit.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- caetris1 6y agoMy original comment was deleted, so I'll try this again. I've read the comments here and quite surprisingly there are a lot of folks saying that the value of this hack isn't worth more than roughly one year's salary at Twitter (as an intern). I appreciate the pragmatism, but unlikely. Anyone with this kind of exploit could have sold it, moved to Russia, and received immunity from extradition. Secondly, people should be scrutinizing any moron willing to give away thousands of dollars to billionaires for a promise of a 2x return. Especially in these times. So, reason can only allow us to arrive at a most likely cause. That this was indeed an inside job. It was not about money. It was not a security flaw. But rather, it was simply a group of employees that were unhappy with Twitter allowing the federal government to investigate bad actors on the platform behind closed doors. And here is why: https://www.scribd.com/document/467148777/DHS-Social-Media-Letter https://www.scribd.com/document/467148777/DHS-Social-Media-L...
- dang 6y agoYour comment was deleted because you yourself deleted it.
- malikNF 6y agoThis "send me btc to send you more btc"scam has been happening for the past few months and Charles Hoskinson (https://twitter.com/IOHK_Charles https://twitter.com/IOHK_Charles), founder of the Cardano blockchain was warning about this issue for a while, he mentioned his team was trying to get in touch with twitter and youtube to stop this and these companies have let this slide for a while. [edit] some are wondering if this is some type of money laundering scheme https://twitter.com/nktpnd/status/1283521742602940420 https://twitter.com/nktpnd/status/1283521742602940420
- trophycase 6y agoPast few years, actually.
- Hongwei 6y agoThis may be the last straw that tips politicians over into considering Twitter & co utilities - stuff that the gov has a say in running because failure is unacceptable to the public. Not that I think the gov could do a better job, but that doesn't stop them elsewhere.
- caetris1 6y agoI've never heard of Hacker News censoring comments that do not abuse the site guidelines, with rational opinions. This comment thread is being heavily censored. This fundamentally abuses the trust that users have put into this site.
- dang 6y agoYour comment was deleted because you yourself deleted it. "Hacker News" hasn't been censoring anything. Is it possible that you thought your comment was removed because in fact it was on one of the later pages of comments? That is simple pagination. I tried to tell people about this by pinning https://news.ycombinator.com/item?id=23853229 https://news.ycombinator.com/item?id=23853229 to the top of the first page.
- jliptzin 6y agoSeems to me twitter should hire some humans to sit there and manually approve every tweet by all VIP accounts before they go live. How hard could that be? If that’s all they do you’re adding maybe a 30 second delay to every VIP tweet and you’re pretty much guaranteeing that this doesn’t happen again. Unless of course the hackers somehow inserted the tweet directly to the database and bypassing any such measures.
- whitenoice 6y agoThat will not help, as the imposter could post a sane tweet impersonating the VIP. The person checking would not be able to identify if it's the VIP or the imposter.
- jliptzin 6y agoThe point is to screen outrageously out of character or dangerous tweets, for instance Hillary Clinton giving away bitcoin, or a politician declaring war on another country. Something timid or benign slipping through is not that big of a deal.
- coronadisaster 6y agodang, if you would collapse all threads by default and only show/load top level comments, you probably would not even need this performance workaround. On the first page of your performance workaround, there was only 4 top-level comments... probably less than 100 total, I would guess (for most posts).
- drummer 6y agoThese hackers are clearly amateurs. If you're going to post crypto scams on hijacked Twitter accounts you can't NOT include John McAfee's account. Seriously.
- borplk 6y agoThis is likely due to third-party social media account management software getting hacked. And they probably used compromised API tokens.
- Nextgrid 6y agoInitial postmortem: https://twitter.com/TwitterSupport/status/1283591844962750464 https://twitter.com/TwitterSupport/status/128359184496275046... Seems to be a social-engineering attack on Twitter staff.
- blisseyGo 6y agoVery strange. Why exactly is it possible for any employee to tweet as any user? Unless the person who was targeted was the Database admin himself or something. Even then, how tech illiterate is this employee with such high permissions to fall for a social engineering attack? I would like to know what this employee's role was in the company. Also who did the social engineering?
- tjomk 6y agoWell, it's actually not that hard to fall for social engineering even if you're well educated about the topic. Have a listen to an interview Christopher Hadnagy gave on Darknet Diaries.
- swimfar 6y agoHere's the episode: https://darknetdiaries.com/episode/69/ https://darknetdiaries.com/episode/69/
- blisseyGo 6y agoFair point. I still want to know how it happened and how the employee who's got to have very high level permissions managed to give access to the entire system including change user email and phone numbers.
- mardifoufs 6y agoIf I had to guess, the attackers probably didn't even need twitter employees to have direct access to the accounts. If support tools allow Twitter support staff to change a user's email (which would make more sense, but still be extraordinarily unsecure), you basically get full access to the accounts the moment you get control over those tools. It would also explain why all the account emails seem to have been changed. But even then, that there is no system to detect mass modifications and no delay before the changes take place is incredible. Unless they were able to social engineer their way into multiple employee's accounts to avoid detection, which would be an incredibly bad problem by itself. Twitter seems to have a shaky history when it comes to limiting employee access to account info.
- porjo 6y agoRecent update: "We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools." https://twitter.com/TwitterSupport/status/1283591846464233474 https://twitter.com/TwitterSupport/status/128359184646423347...
- abvdasker 6y agoI don't think anyone appreciates how scary this is. A simple BTC scam or even market manipulation is one thing. Can you imagine the mass panic if there were one sombre tweet from Trump's account about a nuclear strike?
- abvdasker 6y agoOkay here is my mostly baseless conspiracy theory: As many others have noted, access to the compromised accounts is worth several orders of magnitude more money than the hackers were able to extract using this naive bitcoin scam. Whether it's used to manipulate markets or just resold, the hack is probably worth millions or tens of millions. Is it plausible that hackers who could coordinate and execute this kind of a breach would not know how to maximize the value of the hack and would instead opt for a really naive and not especially lucrative BTC scam? It is also pretty common knowledge that the activist investor hedge fund Elliott Management has wanted Jack Dorsey removed as Twitter's CEO for quite some time. What if the BTC scam is a cover for corporate espionage? What if the purpose of the hack was actually to make Dorsey look incompetent in the most public way possible, and possibly turn many influential public figures against Twitter? Elliott Management has the resources to finance a breach like this as well as the motive. An alternate theory would be that this actually was a form of market manipulation -- manipulation of Twitter's share price.
- kabacha 6y agoI think you underestimate the value of this hack — it's really safe. BTC is transparent but pretty safe and easy to launder compared to messing with stocks which would draw so much heat that it's very likely you'd get caught.
- abvdasker 6y agoIf their goal was to get BTC, why would they copy/paste the exact same message with the same Bitcoin address for every compromised account? Nobody who could pull this off would be that dumb.
- enchiridion 6y agoIs it really that much harder to track 1 address vs 10k? It seems like it would be additional work for no marginal benefit.
- known 6y agoAccording to Blockchain.com, more than $100,000 was received at that address about an hour after the first hack, which appears to have tricked more than 350 users. https://archive.vn/QOp4M https://archive.vn/QOp4M
- IMAYousaf 6y agoI have a question to ask you all. If I wanted to study things to get to the point where internally/externally I could coordinate a hack of this magnitude, what things do I need to study? What are the technical things needed to pull something like this off? What are the social corporate things I needed to know to pull this off? I know that we don't have specifics, but I'm asking as a pure academic exercise how much I'd need to know to pull this off, and how to get away with it too.
- mixologic 6y agostart here:, and then catch up to whatever the state of the art is. Humans are the weakest link in the security chain. https://theintercept.com/document/2014/03/20/hunt-sys-admins/ https://theintercept.com/document/2014/03/20/hunt-sys-admins...
- kabacha 6y agoUnfortunately majority of big breaches like this are a result of social hacking rather than some computer science magic. However to answer your question of how much you'd actually need to know? Decent networking and system understanding as well as how to apply this knowledge in reverse engineering. Finally you need loads of luck. Most of penetration testing is just throwing existing things at the system and generally looking around for flaws and if you're lucky you might just stumble on something valuable.
- IMAYousaf 6y agoWell that's what I'm asking about. What social hacking principles possibly were used here? What is the understanding that the attacker has about the people inside the company and how security is at companies like this to pull off a breach like this?
- blisseyGo 6y agoThis reminds me of 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23/syrian-hackers-claim-ap-hack-that-tipped-stock-market-by-136-billion-is-it-terrorism/ https://www.washingtonpost.com/news/worldviews/wp/2013/04/23...
- blisseyGo 6y agoCould this be related to the Executive Order POTUS signed yesterday on Hong Kong Normalization? https://www.whitehouse.gov/presidential-actions/presidents-executive-order-hong-kong-normalization/ https://www.whitehouse.gov/presidential-actions/presidents-e...
- young_unixer 6y agoIf they made a movie about how these guys did it, I would totally watch it.
- magma17 6y agoCuriously, Elon's btc address is different from the others. Nice try, elon.
- bishalb 6y agoSo which ones of you did this? ;)
- arberavdullahu 6y agoI am wondering if the hackers had access to the private messages of these accounts?
- alvis 6y agoIt's a very very loud attack, no doubt. But how sophisticated it's? Probably not as much as many think. As early reports suggest the attack was done via a stolen employee's token, it suggests the attacker has access to the employee's web browser. Potentially some malware extension that silently sniffs traffic to twitter?
- lanevorockz 6y agoIt's really strange to claim it was "simultaneous" account hacking instead of Twitter being hacked. I guess all journalism today has 50% opinion in the middle.
- Inversechi 6y agoTwitter support thread: https://twitter.com/TwitterSupport/status/1283591844962750464 https://twitter.com/TwitterSupport/status/128359184496275046...
- stevefan1999 6y ago#cancelTwitter
- sch00lb0y 6y agoShameless plug: All the companies(Google, Microsoft...) are telling trust us. But, I believe that we should trust us instead of relying on third parties. They always change when businesses interest changes. This is where web3 is coming to play. Technologies like IFFS, safe network are coming. Looking at the scale issue, I guess this web3 takes at least 5 more years. But, this kind p2p technology is possible with small-scaled mesh. Mesh networks within our devices or families. From the beginning, I hate the idea of storing passwords in the third-party password manager. Later, I fell into the same trap because a managing lot of passwords is difficult. So, I building an open-source p2p password manger. Replicates the passwords within your devices, instead of storing everything at the vendor's cloud. It's half-way for the closed beta release. I would like to hear everyone's feedback on this idea. Thanks
- HenryBemis 6y agoHow does that addresses the issue? From the looks of it, this was not a password attack, this was either an inside job or an abuse of an API.
- sch00lb0y 6y agoIt's not addressing this issue. Looks like inside job. Am saying that we all should change from centralized authority into decentralized world.
- yazinsai 6y agoImagine buying puts on TSLA and tweeting this from @elonmusk: > Stepping down from TSLA effectively immediately. Focusing 100% on SpaceX. Life's short. This could easily be worth $100m's
- freakynit 6y agoThis seems more and more like a diversion for something else.
- abhiminator 6y agoThe BTC address used by the malicious actors has received ~13 BTC so far. That's around $120k in value at the time of me writing this comment. Not sure if such a massive, simultaneous hacking operation makes sense for ~$120k worth of BTC. As other commenters mentioned, postmortem of this one should be interesting. https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n...
- dynamite-ready 6y agoWait... So the hackers were able to target Joe Biden's account, Barrack Obama's, but not Trump's? That is very odd.
- GrumpyNl 6y agoIs this the beginning of the end for twitter? Tweets can not be trusted anymore.
- watson 6y agoHere's an official update from Twitter: https://twitter.com/TwitterSupport/status/1283591844962750464 https://twitter.com/TwitterSupport/status/128359184496275046...
- deleted 6y ago[deleted]
- beezischillin 6y agoThe screenshots seem to show accounts shadow-banned, something Twitter denied doing for years... I am referring to those labels showing banned from search, etc. Seems interesting.
- e79 6y agoA lot of people are asking “why a bitcoin scam?” From what we know right now, targeted accounts had their emails and 2FA reset via an admin tool. These attacks were noisy, so the window of opportunity for the attacker was small. The attack was launched after hours, likely to limit the chance that the compromised Twitter employee would be around. So market manipulation wasn’t really a great option. This was basically a “smash and grab” style attack, which makes sense given the noisy nature of the access. I wouldn’t be surprised if Twitter’s admin tool purposely doesn’t allow employees to silently access accounts.
- hacker_newz 6y agoAfter hours for who?
- ryanisnan 6y agoYeah, that's just wrong. It was mid-day PDT, right around Twitter's core hours, and many of the targets are also west coasters.
- e79 6y agoYep you’re right. My bad. Hmmm... I still think my point makes sense. The “smash and grab” style attack fits given how noisy it was. People were wondering why they didn’t do something far more insidious like covertly gather everybody’s DMs and such. That’s not really feasible when you know your attack is going to get noticed fairly quickly.
- ryanisnan 6y agoTrue. Also there would have probably been some time pressure to act given twitter employees would have likely noticed logins from strange devices/locations, and raised some flags.
- pluc 6y agoThey didn't hack anything, the access was given to them by an insider.
- abetteramerica 6y agoSo, does no one think this was China doing a 'we can do what we want when we want' as a response to Trump's executive order the day before this happened? And if it is, would they be honest about the cause since that would require a response and likely an escalation?
- blauditore 6y agoFunnily enough, the Tweet made me immediately think whoever wrote it speaks French natively. In French grammar, there needs to be space before any punctuation with exactly two parts (e.g. ":", "!", or "?"), and it's a common error for French-natives to do the same in English.
- willfiveash 6y agoI'm guessing use of 2FA internally could have prevented this intrusion but that's a hassle so...
- amai 6y agoIsn't it obvious? All the hacked accounts were fake accounts from the start managed by twitter employees who fill them with content every day to simulate an active social network. The hack just revealed that Twitter in fact rules the world and all these other companies, billionaires and celebrities simply don't exist.
- partisan 6y agoOne possibility is that a twitter employee was blackmailed with some personal information and forced to do this.
- vs4vijay 6y agoIf you take a look at some of the transactions, you will see some interesting addresses like: 1JustReadALL1111111111111114ptkoK 1TransactionoutputsAsTexta13AtQyk 1YouTakeRiskWhenUseBitcoin11cGozM 1BitcoinisTraceabLe1111111ZvyqNWW 1WhyNotMonero777777777777a14A99D8 1forYourTwitterGame111111112XNLpa Link: https://www.blockchain.com/btc/tx/67b814526ae6ee78a16059bfcfc06ed7768c92c58f3409367cb180627631ddbe https://www.blockchain.com/btc/tx/67b814526ae6ee78a16059bfcf...