4 ms·
Watch this turns out to be a JS dependency tree problem from some library that was compromised months ago in some NPM module, used in the twitter web interface.
by VikingCoder 6y ago
Watch this turns out to be a JS dependency tree problem from some library that was compromised months ago in some NPM module, used in the twitter web interface.
- Wingman4l7 6y agoI love this theory, but at the same time, I feel that it's unlikely. Without knowing how their back-end is put together, that'd be like... trying to smuggle in a robot into an office building to break into a safe that's inside without knowing the floor plan, what kind of knobs are on the doors, etc.
- marcinzm 6y agoCould have paid/convinced/threatened an intern/employee to scope it out and then deployed the hack externally to bypass safety measures. Complicated but doable.
- 0x00000000 6y agoOr disgruntled ex-employee
- madeofpalk 6y agoGiven the Twitter web interface is just an client of the Twitter semi-public API, I highly doubt this is it.
- ehsankia 6y agoAs long as the API isn't running on node, right? :)
- VikingCoder 6y agoI'd suspect the web interface has UI that's wrapped around the semi-public API. It's that web interface I'm worried about.
- SahAssar 6y agoBut the twitter web interface has access to post (since you can post via it), so it would be possible.
- madeofpalk 6y agoThe Twitter web interface doesnt - it's just a javascript app that runs in your browser. To post a tweet, it uses the same public API that all third parties use. To posit that it was an npm vunrebility in the frontend caused this hack implies that anyone can just curl their way into someone elses account.
- lukeramsden 6y agoCompromising the web interface would mean you can steal session tokens.
- staycoolboy 6y agoDoubtful: It is well documented that Twitter has re-written many parts of the FE/BE framework, so I think it likely that their NIH attitude might be a benefit.