5 ms·
Twitter confirmed that the attack used internal tools, and thinks the attacker used social engineering on employees: https://twitter.com/TwitterSupport/status/
by junar 6y ago
Twitter confirmed that the attack used internal tools, and thinks the attacker used social engineering on employees:
https://twitter.com/TwitterSupport/status/1283591844962750464 https://twitter.com/TwitterSupport/status/128359184496275046...
- corty 6y agoWhich shows that Twitter probably doesn't properly employ 2FA and two-person-principle when dealing with high-profile accounts. Otherwise, social engineering would have been almost impossible.
- almost_usual 6y agoIf it’s SMS the attacker could have social engineered (big cell service co) to get access to the employee’s phone # and get a SIM. I’m guessing someone re-used a hacked password and SMS 2FA is to blame. Maybe it’s not even that sophisticated.
- mkoryak 6y agoThey should be using things like yubikey though, not phones
- almost_usual 6y agoDefinitely, TOTP at least.
- nemothekid 6y agoThat seems unlikely. The scale of the attack and the profile of the accounts just doesn't seem to me that would be the case. I'd like to think it's a bit harder to intercept a former President's text messages.
- xxs 6y agoI have a little thingie that generates time based codes, similar to wee-calculators banks use but w/o the pin, that's on top of a private key. SMS is fine for end user access but companies can do better, even RSA/Google authenticator are a lot better option than SMS
- manquer 6y agoMost tech companies like google and Facebook use hardware keys like Yubikey. TOTP and definitely sms are not as secure as hardware keys
- raxxorrax 6y agoThe mechanism isn't relevant because the admin tool has a reset function. It is needed of course, because people loose their phones, keys and whatnot. No security mechanism is safe against an administrative reset for services like Twatter. SMS is seen as less safe because the transport layer is not encrypted. But there isn't much difference in the practical security of the average user.
- corty 6y ago> SMS is seen as less safe because the transport layer is not encrypted. Lack of encryption is only part of the problem. Lack of proper authentication is more important. Mobile networks are vulnerable to SS7 redirects, SIM-Jacking and plain old social engineering. The 2FA reset function is also a part of doing 2FA properly. Your reset needs to be at least as secure as the regular 2FA flow. Meaning that "just phoning support" isn't an option. Yes, resets will be cumbersome and might involve stuff like physical presence, showing a government ID and maybe being vouched for by a third party. Most companies fail badly at this.
- raxxorrax 6y agoThat and many users wouldn't do that for online accounts. Blue checkmarks are the exception while ignoring conventional internet wisdom... which came at a steep price. Edit to the topic: As I said, the transport layer of SMS isn't safe, but I don't think it has practical merit. How often were SMS redirected or spied upon? In high profile cases? Even that would be difficult to determine, but the occurrence is probably very low. And for a twitter account? Seriously? Depends on the account but assessment of threats is the first step of an honest security review. My reddit pwd has been 'reddit' for years. That wouldn't fly if I were Madonna and if I had any attachment to it.
- deleted 6y ago[deleted]
- mzs 6y agoarticle has been updated as well to include: >"We used a rep that literally done all the work for us," one of the sources told Motherboard. The second source added they paid the Twitter insider. …