4 ms·
They social engineered access to a Twitter employees internal account, not the individual end users affected.
by Element_ 6y ago
They social engineered access to a Twitter employees internal account, not the individual end users affected.
- except 6y agoI understand, but that sort of behaviour should have been thwarted quickly by their security team or policies setup against abuse.
- Gigablah 6y agoYep, for one, you shouldn’t be able to just hand over your credentials to other people and they can immediately start doing stuff in your systems. Also, the ability to impersonate people (not just celebrities) should require at least manual approvals. Not sure why this ability even exists. The original speculation (that it was an API vulnerability) is actually easier to stomach.