4 ms·
They reposted it on the cash app account but with a different address. The exchanges are going to have a field day monitoring twitter. New address: bc1qwr30ddc
by byteshock 6y ago
They reposted it on the cash app account but with a different address. The exchanges are going to have a field day monitoring twitter.
New address: bc1qwr30ddc04zqp878c0evdrqfx564mmf0dy2w39l
Tweet: https://mobile.twitter.com/CashApp/status/1283522007695597570 https://mobile.twitter.com/CashApp/status/128352200769559757...
- ben174 6y agoSo strange that twitter can't automatically filter these. The message format is pretty consistent. Surely they could write something to at least put tweets matching this pattern in a moderation queue.
- ageitgey 6y agoThey are blocking tweets with that address now. I'm guessing that they still have no idea what the root cause is.
- byteshock 6y agoSomebody is getting fired today... Edit: I was only making a joke, relax. Most likely it’s not a single person’s mistake. It’s just something you say when shit hits the fan.
- floatingatoll 6y agoPromoting, praising, or otherwise endorsing the kind of reaction you state is inexcusable in IT Operations. Your unstated assumptions-by-framing are: 1) A single person is responsible for the flaw. 2) A single person is either already under performance review or committed gross neglect of duties. 3) The above single person will be terminated rather than retrained. If this is how you would speak about your own employees during a security incident, your business deserves to fail. If this is how you expect to be treated by your employer during a security incident, you should seek employment elsewhere.
- VectorLock 6y agoSo saying one person should be fired is not okay, but saying a whole business should be fired is okay?
- kgraves 6y agojeez, they said it's just a joke...
- floatingatoll 6y agoThey used the edit function to walk back their comment as a 'joke' after my post was submitted, and managed to make things worse in the process. Would you joke about firing someone for a mistake during an interview? I would consider that a dealbreaker if I were interviewing someone, as in "this interview is over, go home". Do you consider HN an appropriate forum for pithy one-liner jokes that do not contribute to the discussion? Reconsider.
- secondcoming 6y agoCalm down
- VRay 6y agoThat dude is talking the exact way a lot of execs think. If this is due to one person's screw-up, that person is going to get railroaded out of the company's back door. I saw this happen before. A newish IT guy accidentally deployed a script to a few hundred machines that took down the whole worldwide intranet for a multi-billion dollar juggernaut for an hour or so. He was supposedly forgiven, but ended up on a "performance improvement plan" where he had a bunch of impossible tasks, and every shortcoming was documented to use against him until he was fired. I wish things worked the way you think they do, or if not that way, I wish they'd at least just shitcan the dude on the spot (with a few months' severance) and be done with it.
- dvtrn 6y agoI don’t know what form it would or even should take but these kinds of “Performance Improvement Plans” where the person being coached is set up for failure needs some kind of alternative that incentivizes employers to either responsibly dismiss the person or otherwise be genuine with “performance improvement”. These tactics are hard to prove if someone goes to court over it (probably) but are just as hard to recover emotionally from and can stunt a person all the way to their next job or many.
- ahelwer 6y agoUnlikely. That isn't how hacks or outages are punished in large software service orgs, unless it was intentional or due to negligence like disabling a failing test to get something shipped to prod.
- maaarghk 6y agoApparently all tweets containing seemingly random strings of characters are blocked: https://twitter.com/NepalBlockchain/status/1283537582249218048 https://twitter.com/NepalBlockchain/status/12835375822492180...
- TRcontrarian 6y agoFacebook Messenger is blocking me from sending any string containing the attacker's wallet address bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh. I'm trying to send blockchain explorer URL's to friends and it's failing.
- esperent 6y agoFacebook messenger has extremely sensitive filters. It seems to block most links I try to send. Most recently, I tried to send a GIF of a beautiful city on a river to my girlfriend. Nope, blocked. The link was a GIF sharing site, I don't remember which one, but it's highly unlikely there's any malware on it so it must be a porn filter. And as for sending links to my staging site to a couple of tech friends... forget about it.
- nexuist 6y agoHow would you write a regex that does this? How do you determine whether a string of characters is random?
- Blackthorn 6y agoThe classic way to do it is see how well it compresses, though that requires a certain minimum length.
- Cthulhu_ 6y agoYou can probably calculate the entropy / randomness of a string via a fairly simple algorithm.
- Cthulhu_ 6y agoReminds me of a thing years ago where a virus used a Twitter account's messages as its command & control system. Said twitter account encoded the commands in base64 I believe.
- mc32 6y agoI’d be curious to find out which one of the accounts proved to be the better “sales lead”
- VectorLock 6y agoThey should have used unique wallets for each tweet and A/B tested the gullibility of the victim's audience. Would have made them more difficult to track and shut down as well. More hallmarks that this wasn't probably something they lucked into, rather than some sophisticated attack.
- paulpauper 6y agoexploits like this tend to get patched very fast no time for a/b testing. every second counts.
- VectorLock 6y agoAt the very least it would have provided some interesting post-game analysis.
- Nightshaxx 6y agoSomeone posted in the main thread that twitter was releasing a new API tommorow. It was definitely getting patched soon.