3 ms·
I find it hard to believe this was a Social Engineering based attack. Elon Musk’s account was accessed multiple times after their tweets being deleted and it se
by except 6y ago
I find it hard to believe this was a Social Engineering based attack. Elon Musk’s account was accessed multiple times after their tweets being deleted and it seemed to last forever, account by account being taken over.
- Element_ 6y agoThey social engineered access to a Twitter employees internal account, not the individual end users affected.
- except 6y agoI understand, but that sort of behaviour should have been thwarted quickly by their security team or policies setup against abuse.
- Gigablah 6y agoYep, for one, you shouldn’t be able to just hand over your credentials to other people and they can immediately start doing stuff in your systems. Also, the ability to impersonate people (not just celebrities) should require at least manual approvals. Not sure why this ability even exists. The original speculation (that it was an API vulnerability) is actually easier to stomach.
- agloeregrets 6y agoThe account was fully hijacked, email and password changed, 2FA was disabled. At that point the account basically belonged to someone else. I don’t think they realized the scope and angle of the attack.