24 ms·
Twitter internal panel linked to account hijackings
- gruez 6y agoAnyone have links to more of these images? Also, if you search for the source for one of the images (mentioned in the article), you can find this tweet: https://twitter.com/UnderTheBreach/status/1283499294541131776 https://twitter.com/UnderTheBreach/status/128349929454113177... which says the recent hacks were done through that tool.
- Fabricio20 6y agoI saw this Imgur album linked in one of the original tool tweets. Not sure if fake or real obv. https://imgur.com/a/2sqjNUo https://imgur.com/a/2sqjNUo
- Solvitieg 6y agoI don't understand this angle because typically admin panels only let you manage the account; deactivate, manage email address, etc. As shown in the screenshots. Tweeting on behalf of another user seems like an unnecessary feature to give admins.
- geerlingguy 6y agoSome suggested the admin panel can initiate a password reset, and that, coupled with email management would allow account takeover, effectively (without allowing 'tweet as user' functionality).
- 542458 6y agoAll the hacked accounts seem to have had the associated email changed. I think the attack goes admin panel -> change email -> reset PW -> tweet bitcoin scams. https://twitter.com/sniko_/status/1283485972286656517 https://twitter.com/sniko_/status/1283485972286656517
- kryogen1c 6y agoif this were true, youd think itd be trivial to review changelog for two affected users and deactivate the in-common admin account. not sure why this would take hours to solve.
- julianlam 6y agoYou're assuming this internal tool was built securely and was feature complete. My experience with internal tooling in general suggests otherwise.
- MAGZine 6y agochanging emails is a common way to keep account owners out of their accounts. might not have anything to do with the mode of entry.
- giarc 6y agoGiven the number of accounts that were taken over, there must have been many people conducting the hack. Also considering that tweets were being deleted then re-tweeted, others must have been monitoring the tweets. Seems somewhat well coordinated.
- Nextgrid 6y agoThe feature wouldn't be tweeting per-se but acting on behalf of the user, which can prove useful for support or debugging. The side-effect is that obviously it also allows tweeting if you wanted to.
- krapp 6y agoI'm starting to think web facing site admin is a bad idea. Assuming that's what this is, I don't know. But I'm surprised it's still a thing.
- klyrs 6y agoIs there a better solution? How do you airgap administration of a web facing service?
- macintux 6y agoIt's painful (although I suppose all airgap solutions are) but remote access protocols like RDP or SSH tunneling to a jump host which has access to the administration portal is one common(?) solution.
- marcinzm 6y agoThat's only safer from attacks that bypass the public admin portal authentication. Any social engineering attack that steals credentials directly won't be impacted.
- macintux 6y agoIt’s another layer of defense. Someone has to not only know your credentials but also know how to use them to get to the jump host, and from the jump host know what to do next (although unless it’s ephemeral, there are probably enough bread crumbs to find the proper url).
- klyrs 6y agoThe point is, that's not an airgap; RDP and ssh tunneling are transititive and we're all logging on from home right now.
- krapp 6y agoI don't know... I've seen a lot of forums that just put a login form in /admin and I just kind of assumed a site like Twitter would use a VPN or ssh or a custom app with its own secret sauce protocol or something... better than I could have whipped up in my PHP monkey days.
- tyingq 6y agoThis tweet is interesting...seems to point at some kind of sms intercept. https://twitter.com/lucky225/status/1283514329187250177 https://twitter.com/lucky225/status/1283514329187250177
- gruez 6y agoThat person later clarified it probably wasn't sms intercept. https://twitter.com/lucky225/status/1283536278856724480 https://twitter.com/lucky225/status/1283536278856724480
- troughway 6y agoIt's an admin panel that shows account information and allows for the staff to change details. What is the big deal?
- mendelmaleh 6y agoI guess it implies that the attack was from the inside?
- gameofcode 6y agoInside attack / insider's admin account credentials compromised / admin panel itself compromised. Would love to see an RCA on this.
- mzs 6y ago>A little over ten years ago: Twitter settled with the FTC as a result of an internal tools breach. Their internal tooling was available directly over the web and accessed through an employee account protected by the password "happiness" https://twitter.com/Magoo/status/1283520203679133696 https://twitter.com/Magoo/status/1283520203679133696
- ycombonator 6y ago“Trends Blacklist” & “Search Blacklist” are interesting buttons. Manipulation much ?
- ycombonator 6y agoTwitter Commie hacks are in full force downvoting
- dang 6y agoPlease stop posting unsubstantive and/or flamebait comments. It's not what this site is for, it destroys what it is for, and we ban account that do it. At least the GP comment contained actual information, however little.
- ycombonator 6y agoThanks for reminding got carried away.
- incrimintal 6y agoThat's for when JewishPrivilege trends
- cameronbrown 6y agoImmoral. Actively overriding what's really trending with what they prefer to trend. Assuming this leak is real.
- deegles 6y agoUmm wouldn't they be writing the 'trending' algorithm in the first place?
- duskwuff 6y agoPractically every "trending" algorithm involves some degree of manual tweaking. Otherwise, they end up prone to identifying uninteresting trends (like the current day of the week, or other time-sensitive trends like "lunch" showing up around local noon), or are easily manipulated by groups of users. Besides, one of the features of Twitter's Trends is a prose description of what the keyword references -- there's no way that could be generated automatically.
- afrcnc 6y agoTwitter is removing those because it's of their own internal backend, not because they're necessarily connected to the hack. Huge leap from Mboard on this
- jeffbee 6y agoWhy would there be screenshots of Twitter's internal tools flying around on Discord, other than they are related to these hacks?
- nexuist 6y agoWhy would a screenshot of their tools warrant a content takedown? People have posted far worse things that have been allowed to stay up. It's not like there's any personal information visible in the screenshots.
- mcphilip 6y agoI’d be surprised if Twitter didn’t have some internal tool like this but I’d expect it to only be accessible over a VPN that few had access to.
- marsrover 6y agoThis was my first thought as well. It must have been an oversight on someone’s part. Maybe infrastructure changes due to the shift to work remotely made it possible to access.
- Nextgrid 6y agoHow would a VPN help in this case though? They social-engineered some employees to gain privileged access to the admin UI. If a VPN was in the way they'd do the same thing to get access to the VPN first.
- xeromal 6y agoI've seen some solutions where the VPN only works on the company machine. In this case, the social engineered employee would at least have to hand over their laptop.
- deleted 6y ago[deleted]
- Nextgrid 6y agoThat's indeed often the case, how it works is that the machine itself has a client certificate it uses to authenticate with the VPN. There's no reason that certificate can't be used directly for the HTTPS connection to the admin UI, providing the same security benefits without actually requiring a VPN. Furthermore depending on how "deep" the social engineering attack goes, a local user with administrator privileges can typically export those certificates unless they are stored on a hardware module (either a smartcard or an internal TPM/secure element).
- EE84M3i 6y agoI don't know about twitter, but a lot of companies are trying to drop VPNs entirely going no-vpn/boyond-corp/"zero trust", so it's not terribly surprising to me.
- zmmmmm 6y ago> Hawley said "please reach out immediately to the Department of Justice and the Federal Bureau of Investigation and take any necessary measures to secure the site before this breach expands It's kind of bizarre when you have the highest levels of government doing their critical communication on a free social media service to the point where they are critically dependent on it, then begging for support when things go wrong. Maybe you shouldn't use a free service that is not under your control or any proper regulatory or quality constraints for your most important messaging to the public then?
- viraptor 6y agoThe next time we swing the other way: "Maybe government should embrace popular communication media instead of spending billions on custom IT infrastructure to post a message on a custom page that everyone screenshots and copies to their timeline anyway." (Also if they don't create an "official account", someone else will do it for them)
- EForEndeavour 6y ago> (Also if they don't create an "official account", someone else will do it for them) What do you mean? How would anyone not affiliated with a given government agency convince human verifiers at Twitter that they're official?
- viraptor 6y agoThey don't have to convince any verifier. They don't have to be verified. If there's no official account and you create an account with a reasonable name, reposting every post from the official feed, you can get significant following. A lot of the followers will not care whether it's official or not and may not question an extra information appearing on the feed one day.
- hyperdimension 6y agoWell, put it this way: why is Donald Trump listed on Twitter as @realDonaldTrump? If you don't snatch up your (organization's) name first, someone will surely do so for you. (Honestly not trying to incite anything by using him as an example; I just hardly use Twitter and he was the first to come to mind.)
- 101008 6y agoAccording to some images, Twitter low level employees can see email address of all accounts (and I guess phone numbers). I know some celebrities have their real email address and phone numbers on those accounts. Isn't that something bad?
- scottmf 6y agoHow do we know they're low-level? Could you show the image?
- 101008 6y agoIn this thread some people shared screenshots of the dashboards. I said low-level because some reports said that the hacker paid 2k to the employee to have access. I dont think a high-level employee would sell the credentials for that amount of money. Although I could be wrong if the reports are wrong too.
- vechagup 6y agoThe management of individual accounts is generally performed by low-level employees at companies like this. It's operational work that is thought to scale poorly and the costs of it are looked upon unfavorably by public market investors. Hence, there is constant pressure to push it to as low of a level as possible. Perhaps a higher tier of user support personnel handles verified accounts (or accounts somehow flagged for extra review in a non-public fashion), but I'd still be surprised if anyone particularly high-level is doing the grunt work of using this tool.
- manquer 6y agoHaving access to some is not the same as having access to all. Rate limiting , or restricting to ones I am managing and approval processes are pretty easy . It does not like Twitter is doing any of that .
- unionpivo 6y agoThey accessed maybe 30 accounts? that's less than 4 per 8hr working shift I imagine a support person does more than in an average day. And while we might have seen all the tweets at the same time, they might have been changing emails and passwords over few hours. Remember twitter has so many users they probably get tens of thousands support requests per day. Even if you have monitoring, I don't think volume was enough to pick it up.
- candiddevmike 6y agoRE: social engineering, as long as a human is involved somewhere, the system can be compromised. IT security is a very depressing field because of this fact. I also hope these incidents remind people of how little control you really have over your online identity. We're all just IDs in a database somewhere, waiting to be impersonated. Decentralization is the only solution for this IMO.
- irjustin 6y agoHonest question, how do I recover a lost identity? The reason why this attack worked is primarily because of a recovery system. I agree this is a significant vector, but I can't see how decentralized solves this? At the moment with blockchain wallets, once you've lost your private key, you're screwed. There is no recovery. So, I'm all for decentralized but if it is truly my identity, I need a way back if I lose it. Not sure how to solve that vector even in a decentralized case. Do I need to upload my identity to specific 'verifiers'?
- dogfoods 6y agoYou need to stop thinking identity singular, and identity as valuable. Have many and treat them as disposable. Of course you can't do this on the 2020 web that consists of four websites filled with screenshots of each other, but that's just one of the many reasons to burn those websites to the ground and resist any attempts to remake them. And it turns out your parents were right about not using your real name on the Internet. Social media and their consequences have been a disaster for the human race.
- irjustin 6y agoBut that's not really identity then right? That just becomes my hnews/reddit username that's unverified. I read @elonmusk because I trust it's him and I'm interested in what he says. Personally, I genuinely like Starship + Starlink updates... I ignore most the other stuff. But still, I want to see those awesome rocket tweets! So, I want to know what he says. He can change his username because it got hacked/whatever... but then I personally have to see what he changed it to... how do I know that he is the one who changed it? how do i know it's not some rando dude impersonating him?
- koolba 6y agoFYI for anyone working at Twitter, the legacy JS disabled mobile site still displays the hacked bitcoin tweets. For example try this with JS disabled vs enabled (404): https://mobile.twitter.com/JoeBiden/status/1283512317846659073 https://mobile.twitter.com/JoeBiden/status/12835123178466590...
- ethanwillis 6y agoAbsolutely amazing. A friend and I just tested this and it's true. It makes me think this is a little more than the "rogue employee" story they're peddling.
- koolba 6y agoI’m not sure. It could be as simple as quick hack to hide the deletions that was not deployed to the legacy site.
- jeffbee 6y agoSeems like a huge liability. They are still disseminating these messages under the identities of major public figures, 8 hours after they became aware of it.
- minxomat 6y agoRepro'd with: curl -fSsL https://mobile.twitter.com/JoeBiden/status/1283512317846659073 | grep -i bitcoin
- jeffbee 6y agoWow. This does the job for me: curl 'https://mobile.twitter.com/JoeBiden/status/1283512317846659073' https://mobile.twitter.com/JoeBiden/status/12835123178466590... -H 'cookie: m5=off;'
- russellbeattie 6y ago4 hours later... Still live. (Wow, that site's quite the blast from the past.) FFS Twitter, get your act together.
- russellbeattie 6y agoHeh. One response I just saw complained about Trump using Twitter, since a hacker could take over his account and say anything. Thankfully, the only good thing about Trump's complete descent into batshit insanity, and our apparent acceptance of it as a country, is that he could tweet literally anything and no one would react. Maybe in his first year as president? But now he could tweet that he was planning on a preemptive nuclear strike against Antifa headquarters in Antarctica and we'd all wait for the White House communications office to issue a correction about what he really meant.
- junar 6y agoTwitter confirmed that the attack used internal tools, and thinks the attacker used social engineering on employees: https://twitter.com/TwitterSupport/status/1283591844962750464 https://twitter.com/TwitterSupport/status/128359184496275046...
- corty 6y agoWhich shows that Twitter probably doesn't properly employ 2FA and two-person-principle when dealing with high-profile accounts. Otherwise, social engineering would have been almost impossible.
- almost_usual 6y agoIf it’s SMS the attacker could have social engineered (big cell service co) to get access to the employee’s phone # and get a SIM. I’m guessing someone re-used a hacked password and SMS 2FA is to blame. Maybe it’s not even that sophisticated.
- mkoryak 6y agoThey should be using things like yubikey though, not phones
- almost_usual 6y agoDefinitely, TOTP at least.
- nemothekid 6y agoThat seems unlikely. The scale of the attack and the profile of the accounts just doesn't seem to me that would be the case. I'd like to think it's a bit harder to intercept a former President's text messages.
- xxs 6y agoI have a little thingie that generates time based codes, similar to wee-calculators banks use but w/o the pin, that's on top of a private key. SMS is fine for end user access but companies can do better, even RSA/Google authenticator are a lot better option than SMS
- deleted 6y ago[deleted]
- throwaway69123 6y agoDidnt @jack testify before congress that twitter didnt blacklist accounts?
- dilandau 6y agoYes. I just posted asking basically the same thing: https://www.washingtonexaminer.com/business/jack-dorseys-personal-message-to-congress-twitter-doesnt-shadowban https://www.washingtonexaminer.com/business/jack-dorseys-per...
- hannasanarion 6y agoWhat does that have to do with this?
- dx87 6y agoIn the screenshots of the admin panel, it looks like they have blacklists of things that shouldn't show up in searches or on trending. It's not clear if it's accounts, or some other criteria that's blacklisted though.
- kevingadd 6y agoThe account tagged with "trends blacklist" and "search blacklist" was also tagged with "compromised", which suggests that the account was known to be hacked by a malicious actor so it was set to not show up in discovery flows to stop attackers from exploiting it for visibility. Does confirm past claims that they shadowban accounts (which does hide them from search, among other things) at the very least, even if the exact criteria are unknown.
- eternalban 6y agoAre those buttons or tags? Those may be buttons to set "compromised" on an account, etc.
- dilandau 6y agoDidn't Twitter say that they don't shadow-ban? [1] From a leaked screenshot of the panel, though, it appears they have a search/trend blacklist. 1: https://www.washingtonexaminer.com/business/jack-dorseys-personal-message-to-congress-twitter-doesnt-shadowban https://www.washingtonexaminer.com/business/jack-dorseys-per... EDIT: thanks for the downvotes, twitter.
- dang 6y ago> EDIT: thanks for the downvotes It's against the site guidelines to do that, so please resist. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- deleted 6y ago[deleted]
- coronadisaster 6y agoI wonder if Twitter will get sued for this...
- siquick 6y agoIsn't the whole point of Terms of Service to protect against being sued in the event of these kind of instances?
- coronadisaster 6y agohopefully not enforceable
- xkcd-sucks 6y agoAnyone dumb enough to give money to a "double your bitcoins" scan deserves what they get, even if it is apparently endorsed by celebrities
- coronadisaster 6y agoDo you also think that any old person that falls for a cash scam deserves it?
- dlgeek 6y agoIf nothing else, they'll get sued for securities fraud by some shareholders, because as Matt Levine likes to say, everything is securities fraud.
- deleted 6y ago[deleted]
- slg 6y ago>We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools. I wonder the size of the population of employees that have access to these internal tools. How many people can independently fire off a Tweet from Jeff Bezos or Elon Musk and erase billions from the stock market? How many people can seize the account of Joe Biden (or presumably Donald Trump) and cause a huge international incident?
- derision 6y agoJudging by Trump was one of the few that wasn't hacked, presumably there are some extra controls in place for that account.
- jc_811 6y agoSo it was a social engineering attack against employees with high level access. This sentence still doesn’t make sense to me: “ Once we became aware of the incident, we immediately locked down the affected accounts and removed Tweets posted by the attackers.” The accounts were posting for hours after it seemed Twitter became aware what was going on.
- minimaxir 6y ago> The accounts were posting for hours after it seemed Twitter became aware what was going on. Oddly, it was just Elon Musk's account that had multiple tweets over a long period of time. The other accounts did just one.
- minxomat 6y agoNo, many accounts, including Kanye continued to post follow-up comments with the same content as other accounts.
- ethanwillis 6y agoThe tweets are still live as of right now with JS disabled. https://news.ycombinator.com/item?id=23855452 https://news.ycombinator.com/item?id=23855452
- oaiey 6y agoAccounts of the employees. There was a statements somewhere else, that this might be close to the token system. Token have a validity which expires in hours. All assumptions on my behalf bit it explains your question.
- minimaxir 6y agoThe Vice article (https://news.ycombinator.com/item?id=23853786 https://news.ycombinator.com/item?id=23853786) was recently updated with a note that the Twitter insider was paid to help take over the accounts, which raises further questions on the nature of "social engineering": > we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take over accounts; not sure on the specifics here at the moment https://twitter.com/jason_koebler/status/1283594885292077056 https://twitter.com/jason_koebler/status/1283594885292077056
- gundmc 6y agoThis makes a lot more sense. I can't imagine Twitter isn't using some sort of phsyical 2FA like yubikeys which are virtually Phish proof if implemented well. That being said, what was the employee's endgame here?
- tossAfterUsing 6y agoavoid some other blackmail
- catalogia 6y ago> That being said, what was the employee's endgame here? General disgruntlement maybe? Maybe they were simply pissed off and looking for a way to hurt the company.
- notwhereyouare 6y agoTo me, it seems a little weird they can tweet on behalf of a user. Especially a user with 2FA on their account. Curious as to what types of changes might come out of this going forward
- harryh 6y agoMore likely a password reset to take over the account. After that an attacker can just tweet from any standard client.
- kbenson 6y agoThere's always someone, usually many people, with abilities like this for any service that's automated enough. Even for banks, as much as they might try to separate portions and mitigate access. The solution is not making it impossible, it's making it easy to find out if it was done and being very careful who you put in those roles. That's just the nature of the world.
- blondin 6y ago> social engineering had that feeling... wonder how much more vulnerable working from home is making us to such things. also scary that targeted employees with such level of access fell for it. must have been really sophisticated.
- except 6y agoI find it hard to believe this was a Social Engineering based attack. Elon Musk’s account was accessed multiple times after their tweets being deleted and it seemed to last forever, account by account being taken over.
- Element_ 6y agoThey social engineered access to a Twitter employees internal account, not the individual end users affected.
- except 6y agoI understand, but that sort of behaviour should have been thwarted quickly by their security team or policies setup against abuse.
- Gigablah 6y agoYep, for one, you shouldn’t be able to just hand over your credentials to other people and they can immediately start doing stuff in your systems. Also, the ability to impersonate people (not just celebrities) should require at least manual approvals. Not sure why this ability even exists. The original speculation (that it was an API vulnerability) is actually easier to stomach.
- agloeregrets 6y agoThe account was fully hijacked, email and password changed, 2FA was disabled. At that point the account basically belonged to someone else. I don’t think they realized the scope and angle of the attack.
- catalogia 6y ago> Once we became aware of the incident, we immediately locked down the affected accounts and removed Tweets posted by the attackers. This must be some new meaning of the word 'immediately' that I wasn't previously aware of. It took them quite a while to get these accounts locked.
- ignoranceprior 6y agoOr maybe it took them quite a while to "become aware of the incident" in the first place, but that's just as bad.
- catalogia 6y agoThey spent an hour or two deleting tweets on Elon Musk's account, with new tweets appearing soon after. So it seemed like they were aware of his account being compromised but did not immediately [successfully] lock his account.
- agloeregrets 6y agoIt’s possible they didn’t understand the scope of the issue for a good amount of time. Elon’s account was the first to drop and was famous in the past for being faked for crypto scams. It’s entirely possible that they assumed it was a single account hijack and avoided notifying the correct people until it was too late. They might not have realized that the account info was changed as well until it was too late.
- dsr12 6y agoIf it’s really a social engineering attack then I think it happened because everyone is working remotely and it is easier to perform social engineering attacks. Maybe this incident will have impact on their long term remote work plans.
- harryh 6y agoI dunno why you're getting downvoted. I think this idea makes some sense. If you're doing something shady to your employer, it seems to me that it would feel a lot safer to do so while working from your home office by yourself then when sitting right in the middle of an office pod with other coworkers.
- deleted 6y ago[deleted]
- minimaxir 6y agoIt might make it harder to stop once it's in progress since you can't physically remove the employee from their workstation.
- Bluecobra 6y agoI agree, also remote employees might not have the same layers of security as they do if they were in the office. For example, there could be a firewall that blocks malicious code at the office or someone is logging into the VPN on their home computer that is infected with malware.
- derwiki 6y agoI don’t work at Twitter, but at my company, Duo restricts us from sensitive web apps while on personal devices.
- un_montagnard 6y agoI wouldn't be too surprised to learn that some people that are working from home are actually working from a coffee shop (in countries where they have re-opened obviously) or other public places with little to none protection against social engineering attack.
- graton 6y agoAnyone else unimpressed with Twitter's U2F/FIDO token support? They support a total of 1 (one) U2F token on an account :( The only other company I know that does that is AWS and one U2F token. Every other site I use allows multiples, usually at least 5 or more. I setup U2F on Twitter but then got rid of it after realizing they only allow one.
- koolba 6y agoAWS has a simple workaround though as you can create as many users as you want, each with its own unique token. Combined with roles it’s straightforward to set up a backup user / device. It makes sense technically to have a single token anyway. Otherwise you either need to include then identifier of the auth token (in addition to the secret) or have the verification step try out all N options.
- graton 6y ago> It makes sense technically to have a single token anyway. Otherwise you either need to include then identifier of the auth token (in addition to the secret) or have the verification step try out all N options. I'm not sure if that is true. Most sites support multiple tokens. Off the top of my head I can think of Google, Facebook, Github, Gitlab, and more that support multiple. So it seems like the normal method is to support multiple. One one site I have over 5 auth tokens configured. And tested with four of them connected to my PC at the same time. I could tap on any one of them to authenticate. This is on a Windows 10 PC.
- koolba 6y agoNone of those sites have a concept of users within an account. For each the user and the account are one in the same.
- blibble 6y agoso how do I do that for the root account, of which there can be only one?
- 6y ago
- ALittleLight 6y agoTo me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisticated attack on multiple employees via social engineering, I have to think the attackers thought about it. And if they thought about it, they weren't just after 150k of BTC.
- almost_usual 6y agoDoesn’t make sense, value of the hack is already toast with Twitter’s credibility
- csunbird 6y agoI think there are three possible explanations here: 1- (Tinfoil hats please) This is a state owned attack, which is a retaliation from US Government to ruin Twitter's credibility and introduce social media regulations. 2- The hackers are gray hat hackers, who know that reporting this vulnerability will not make them any money and they want to get what they think they deserve, so they make it public and get some good amount of cash. 3- The hackers had realized they had a massive vulnerability in their hands by accident and did not know what to do with it. I find second and third option plausible, which also reminds me of the npm hack, where a very, very popular library was compromised and installed on a huge amount of developer machines, but only thing they did was to try to get hold of some bitcoin accounts. I do not condone any type of crime but in both cases, it feels like a huge opportunity was missed by both hackers.
- thakoppno 6y agonothing but pure speculation, but i came to conclusion #1 more or less independently. the obvious qui bono is not twitter. and twitters biggest opponent at the moment is? the pound of salt for that is just that once clandestine motives are introduced theres no bottom to the subversion one would introduce to make attribution difficult.
- ciarannolan 6y agoIf the details about how these accounts were taken over are true, that an employee changed email addresses of these accounts to email accounts controlled by the attackers, this is going to turn out to be a massive breach. I'm thinking specifically of direct messages that could have been scooped up before they went public and started tweeting on these accounts.
- gundmc 6y agoBased on what we know, it does sound like the attackers had full access to the accounts. That's a really interesting point about direct messages. It makes it all the more interesting that Obama and Biden and were both targets with the upcoming election. Wonder if those will start showing up on WikiLeaks again.
- s5300 6y agoDoes anybody on Hacker news seriously believe that the account of Biden or Obama actually send messages privately on Twitter? They most certainly don't. I have no idea why that fact is not obvious to some. Trump had two liked tweets for all of time back from like, 2012. Around 2017 or so a group realized this and bought or otherwise messed with the site the liked tweets linked to and made them have pictures making jokes about trump. It took more than a year for anybody to give a shit enough to take down. They don't use the site for anything more than direct statements/retweets.
- gundmc 6y agoAgreed. I don't think it would turn up any skeletons, more of the implication if this breach was in any way politically motivated given our recent election meddling.
- ciarannolan 6y agoI definitely don't think Obama/Biden/others would DM. But Elon? Some of these bitcoin exchanges? Maybe. How about accounts that were accessed (if any) that never blasted out the bitcoin tweet, but had their messages harvested?
- dsr12 6y agoWith the info we have it looks like hackers changed the email id of the accounts and then used forgot password to reset the password. What’s concerning is that they were able to do it for accounts with 2FA enabled. I think disabling 2FA should be extremely privileged actions and should not accessible to most employees.
- minxomat 6y agoThey apparently have another level of auth, used for at least Trump's account. And probably the CEO's considering past events.
- flywheel 6y agoDidn't Twitter buy "Moxie Marlinspike"'s company specifically to get him to fix their security? I guess they didn't really get much out of that. Now I'm starting to get nervous about the security of Signal.
- agloeregrets 6y agoYep. After the one employee deleted Trumps account. This is why I thought it might have been an internal tool; why wouldn’t they hack “THE” account?
- deleted 6y ago[deleted]
- mcphilip 6y agoI suspected some sort of internal tool was used to target prominent users but I’m still curious why there were thousands of unverified accounts tweeting the same scam. Searching for that bitcoin address pulled up tons of accounts tweeting it shortly before that term was blocked. Are there really that many trolls out there, or was a very large set of accounts hacked?
- huy-nguyen 6y agoI’m sure a lot of mere twitter mortals were enjoying a sweet schadenfreude moment.
- ignoranceprior 6y agoCould some of those just be ordinary people who fell for the scam, or bots that retweet top accounts?
- jtchang 6y agoThis is why the concept of a blast radius exists. It is so important to critically examine and limit the blast radius of administrative actions. This is both from a vulnerability perspective as well as honest human mistakes. For certain actions like taking over an account and impersonation there should be rate limits all around. Overriding them requires a break glass process where multiple people may have to approve (or even just acknowledge that it is happening). Social engineering happens. It can happen to the best of us who hold the keys to the kingdom. The goal is that no one individual can completely break all the barriers. They need a bit of help, time, or both.
- iKevinShah 6y agoReally Qualitty suggestion. Do you have any recommended document / link where one could study how to do this? (blast radius in production). Would be really glad.
- vsareto 6y agoTwitter can probably afford to have all account actions to verified accounts be behind break-glass procedures and hire dedicated people to do nothing but watch and audit that.
- CamelCaseName 6y agoI wish they had used unique addresses for each tweet they sent out. It would have been fascinating to see which which account had the best conversion rate.
- RotANobot 6y agoThis has intensely piqued my curiosity.
- gkoberger 6y agoOh wow that would have bee interesting. My guess would be Elon (or Kanye). I know one person who actually sent money to Elon – "it seemed like something he'd do". Seems likely Elon's followers have the highest rate of people who understand crypto, combined with the fact that he's more likely to do something like this than, say, Joe Biden.
- mercer 6y ago> Seems likely Elon's followers have the highest rate of people who understand crypto Even worse, I'd say his followers probably have enough understanding of crypto to be able to send him money, but not enough understanding or skepticism to realize it's a scam.
- iKevinShah 6y agoI didnt even know I wanted to know this. My guess is between Jeff and Bill. They're the leading ones who can afford giving twice the money back ;)
- ladberg 6y agoElon Musk can afford it and is the only one known to tweet crazy stuff.
- kerng 6y agoI'd assume one closer to crypto, probably Elon Musk or Coinbase. Because the audience needs to know how to quickly send BTC. In addition, it's a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his. So, maybe some thought today Musk is having it and finally doing it for real! If there is a person to run such a campaign for real, it would be him - so it could even be plausible.
- deleted 6y ago[deleted]
- tzs 6y agoWait a second...they were hacked in a way that makes it so we can't trust any tweets. Does it make sense, then, for them to use tweets to report their progress on addressing this?
- tastroder 6y agoWhy not? They're not updating HN with those but media and shareholders.
- manquer 6y agoBecause for all we know , it is not them posting this tweet and is the attackers . How can you trust it is them when the attack clearly showed any account can be manipulated. This kind of compromised messaging is not unknown while being attacked , when browserstack got hacked few years back, the attackers send official email to all customers whose emails they got in the leak saying the company was shutting down.
- deleted 6y ago[deleted]
- renewiltord 6y agoThey have easy access to out-of-band signalling. Jack Dorsey can literally call up a news channel and say "They've got everything. Don't believe anything from Twitter.com" and you'd know it in fifteen minutes because it would be pushed out to everything after a Twitter SRE pulled the Red Lever that reactivates the failwhale. Because Jack Dorsey is a real human and a powerful real human and he hasn't done that, we don't have to envision the cyberpunk PURDAH identity scenario for proof from him and we don't have to think this is a secondary Moab run. At least now that it's been up for a few minutes.
- bluedino 6y agoCould Twitter implement something like signed messages?
- cavisne 6y agoIts pretty amazing that realdonaldtrump@ was not a part of this. I guess the controls on that account are at an even higher level than elon musk/obama.
- enraged_camel 6y agoIt might also be that impersonating a government official is a serious crime. Sure, the hackers here have committed a crime, but this was more of an embarrassment for Twitter than anything else. If they had posted from Trump's account though...
- manquer 6y agoIt is also that many people will not think it is a hack . Trump does post all sorts of things . There is no tweet from his acc will surprise me that he actually posted it
- eschulz 6y agoSo if people are less likely to think it is a hack, then they're more likely to send bitcoin in response to a tweet from his account. They'd hack Trump's twitter first if they could.
- manquer 6y agoIf they actually wanted bitcoin yeah, if they wanted to show that twitter is vulnerable not so much
- huy-nguyen 6y agoNYT article says that Trump's account is under special "lock and key" protection.
- jaywalk 6y agoAnd that came about because a rogue low-level employee suspended his account.
- cantrevealname 6y ago> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no technical countermeasures. I'd like to see a system where it is physically impossible for a customer service rep to discover any info about me until I authenticate and authorize it. Or to at least offer me the option to lock my account such that I need to authenticate and authorize before any access is given to the customer service rep. Does anyone know of customer service panels at big companies or government departments where this is the case? I.e., it is literally impossible for a rep to browse random customer information even if they are willing to break the rules? If it's been done somewhere, it would be interesting to hear how it was implemented.
- salemh 6y agoHow does a single rep coordinate the mass amount of posts across verified (and non verified?) accounts? That is an insane amount of access for 'a rep'. They can just copy and paste the same message across that level of accounts?
- kevingadd 6y agoThe rep can perform a password reset and/or change the sms/email pair and then attackers can do the rest and make the posts themselves.
- miguelmota 6y agoDid the attackers have direct access to the database, or why does their internal admin dashboard allow employees to tweet on behalf of any account?
- KingOfCoders 6y agoWhy have employees have the ability to do anything with accounts except closing them?
- zelly 6y agoApparently admins could post only on behalf of bluechecks. I still can't think of a reason why they would need to create posts. Edit maybe, but create? Why? Of course with access to the database anything at all can be done, but this was apparently an explicit feature of the admin dashboard.
- KingOfCoders 6y agoWhen I was working for a company with SOX compliancy, direct DB access was highly regulated and audited.
- dbbk 6y agoSource? This is the first I've heard of the dashboard allowing for post creation.
- rurban 6y agoCan someone post the content within that walled garden called Twitter? I cannot see that content without being logged in on mobile.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- shrimpx 6y agoI wonder if this is related to Twitter easing some security restrictions to enable wfh for Covid. As in for example get rid of an IP whitelist which would have been too cumbersome to maintain with everyone wfh.
- y04nn 6y agoIf this is the true story. Is it a standard practice on social networks to give to an administrator the right to post anything in your name without any distinguishable marker? There is a enormous trust issue here. I expect an administrator to be able to moderate a post or disable an account, not to impersonate it from a admin dashboard.
- thepangolino 6y agoAdmins have direct access to the database. A similar controversy happened on Reddit a while back.
- manquer 6y agoNot the same , he modified SQL dB directly and he was the CTO and one of primary architects of the system. This is admin UI given to operations staff , far more trivial to have writes protected ,I cannot imagine anyone need to write to customer data that often in this kind of app.
- deleted 6y ago[deleted]
- y04nn 6y agoFrom reading HN comments, it is more likely that the attacker changed the account email from the admin panel and took over the account (even accounts with 2FA enabled), which seem more likely to me. To prevent this kind of mess, Twitter should add more restrictions do disable 2FA on an account (multiple admin authorizations, email notification, add delay before the action is performed) and also change the account state to unverified and add to the feed a "email changed" or "identity changed" status. I also think that changing the email should not be immediate and that the old email should be notified of the change.
- benlumen 6y agoIt doesn’t make sense that they could tweet from people’s accounts and get away with it for hours from a moderation panel like that. I don’t buy it.
- eternalban 6y agoWas thinking about that. So one scenario, that depends on an API end-point for the internal tool, would immediately and quietly takeover and change account passwords for targetted accounts. After that, start messages from individual accounts. While security is chasing around individual incidents it would take them a while to realize the breach is more systemic. That's probably when they threw the kill switch for verified accounts.
- gadders 6y agoInteresting to see all the gaslighting tools Twitter has on their admin dashboard - "trends blacklist", "search blacklist" etc
- bryan_w 6y agoThis is what you get when you allow permanent WFH. People you're never met in person with the keys to your kingdom
- tomtompl 6y agoSo twitter uses 'blacklist' word in their internal panels? It's chilling.
- H8crilA 6y agoIs nobody bothered by the shadow-banning? "Trends blacklist" and "Search blacklist"? Talk about transparency...
- thepangolino 6y agoIt's been pretty much standard practice on many social media for years. My problem with it is how it's not acknowledged.
- throwaway6e8f 6y agoShouldn’t that be “Trends Denylist”?
- shultays 6y agoWhy would an admin panel be able to post tweets from other users? I can't think a valid reason
- creativeCak3 6y agoThis is starting to sound too elaborate for it to be a “hacker” under a basement showing off.
- caymanjim 6y agoElaborate? This is as trivial as it gets. Convincing a Twitter employee to change a few email addresses is not elaborate. It's not hard to find employees disgruntled enough to take a bribe, or with a political axe to grind.
- fortran77 6y agoThey had access to DMs, too. This is even more worrisome. Might there be extortion attempts next?
- sonicggg 6y agoThe fact that everyone accepts the level of centralization for a platform like Twitter is crazy. It should be a decentralised platform, and nobody else, besides the owner of the account, should hold the keys to it.
- sumon5660 6y agoowo
- uwu 6y agouwu
- bsev 6y agoInterestingly, similar access was used in 2009: https://www.ftc.gov/news-events/press-releases/2010/06/twitter-settles-charges-it-failed-protect-consumers-personal https://www.ftc.gov/news-events/press-releases/2010/06/twitt... I wonder if this attack was facilitated by some security measures being relaxed to allow work from home.