32 ms·
Tweet from TwitterDev team yesterday: https://twitter.com/TwitterDev/status/1283068902331817990 https://twitter.com/TwitterDev/status/1283068902331817990 > 2
by blisseyGo 6y ago
Tweet from TwitterDev team yesterday:
https://twitter.com/TwitterDev/status/1283068902331817990 https://twitter.com/TwitterDev/status/1283068902331817990
> 2 days to go… #TwitterAPI
https://twitter.com/TwitterDev/status/1283433096780677122 https://twitter.com/TwitterDev/status/1283433096780677122
> Thank you to all of you who have engaged with us and shared your feedback. Your input has been vital, and we’re committed to continuing these conversations with you. There’s so much more we’re doing to build a better #TwitterAPI… and Early Access is coming tomorrow!
Were they supposed to launch some new API tomorrow which got hacked?
- dmix 6y agoNice catch, this may be what it was. Edit: looks like an admin panel was the culprit https://news.ycombinator.com/item?id=23853786 https://news.ycombinator.com/item?id=23853786
- ryanisnan 6y agoEarly access wasn't supposed to be enabled until tomorrow. I wouldn't speculate until they give a post-mortem.
- Solvitieg 6y agoI don't understand this angle because typically admin panels only let you manage the account; deactivate, manage email address, etc. As shown in the screenshots. Tweeting on behalf of another user seems like an unnecessary feature to give admins.
- Widdershin 6y agoI've worked on products before that have a feature that lets an admin open the site using the user's session, which is useful for verifying issues that only present when logged in as the user. To be fair though, this was not for a social network, and even if you broke into that account there wasn't much you could do beyond paying the user's bills.
- dlgeek 6y agoCurrent consensus theory is attackers used the admin panel to change email address to an account they owned, then used that to trigger a password reset and gain control.
- shmoogy 6y agoThat's really suspicious timing - probably was an exploit against the new api.
- css 6y agoOr someone making one last use of an exploit on the old API, since ostensibly there is a day to go before the new API is released on the public net.
- Sebb767 6y agoThis might actually explain the simple scam nature. Setting up more complex monetisation, i.e. by shorting a company, takes quite a while, especially if you don't want to be tracked. A bitcoin scam is quick and simple to do. And it's not _too_ illegal (compared to, for example, stock manipulation), so the attacker will probably catch less heat.
- celticninja 6y agoStock trades are easier to trace, but both can be traced with sufficient resources.
- Nextgrid 6y agoThe advantage of cryptocurrencies is that it allows you to commit the scam anonymously easily and defers the laundering of the money for later, giving you time to devise a scheme to launder it. Stock markets or fiat currencies on the other hand require quite a bit of work upfront to set up an account before you can trade.
- alwillis 6y agoBitcoin is not anonymous; it’s pseudonymous. And there are several companies that perform blockchain analysis for tracking transactions. The FBI and other law enforcement is getting pretty good at tracking illicit Bitcoin transactions and money laundering [1]. If these guys are professionals, they’re using mixing services to cover their tracks. Guess we’ll find out if they made any mistakes along the way. [1] “Blueleaks: How the FBI tracks Bitcoin laundering on the dark web”—https://decrypt.co/34740/blueleaks-how-the-fbi-tracks-bitcoin-laundering-on-the-dark-web https://decrypt.co/34740/blueleaks-how-the-fbi-tracks-bitcoi...
- deleted 6y ago[deleted]
- wybiral 6y agoIt seems weird to me that Twitter would have disabled tweets from verified accounts instead of disabling tweets from the API though.
- zelly 6y agoIt looks like someone found a 0-day in the new API and wanted to use it before others did. Probably didn't help that the bug bounty for this would have been only 7k. How much does the Twitter employee who implemented this bug get paid? https://twitter.com/LiveOverflow/status/1283511782380908545 https://twitter.com/LiveOverflow/status/1283511782380908545
- kabacha 6y agoCurrently their earned BTC balance is $120k+ for comparison. That's a pretty successful scam and 5% of potential revenue will not make anyone go white hat.
- metafunctor 6y agoSorry, but $120k is ridiculously low for something like this.
- samstave 6y agoThey could have caused so much more havok... They must have been having an extreme adrenaline rush during this which clouded them from having a more sinister plan.
- aj3 6y agoMany previous ICO hacks (wait for initial coin offering -> change the bitcoin address to your own) have paid millions. Musk's or Buffet's tweets have moved markets multiple times. This sort of access could have been leveraged to gain at least x100 more than what they achieved.
- saberdancer 6y agoMoving the market doesn't do anything if you don't have the stocks. This might have been a temporary hack where the hacker was not sure how much time he has. It could be simple as someone gaining access to an unlocked home PC of a remote Twitter employee.
- jonahbenton 6y agoFinally, a reasonable explanation.