7 ms·
>none of the eight were Verified accounts. That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celeb
by txcwpalpha 6y ago
>none of the eight were Verified accounts.
That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them picking solely non-verifieds.
- WrtCdEvrydy 6y agoSomeone pointed out that it could be targeted at activists...
- milofeynman 6y agoThat is exactly my worry the moment I saw they were not verified. Nation state could drop a grand per account and get data on 8 activists no problem.
- edoceo 6y agoNot $8k right? $1k per hacked account - which would thousands + the narrow targets?
- milofeynman 6y agoThe NYTb article says they were selling accounts initially for $1-1.5k before trying the Bitcoin scam
- filmgirlcw 6y agoI think the hackers were going after OG accounts that were single, two-character, or common first name usernames. Many OG accounts aren’t verified.
- humaniania 6y agoWhy would anyone care about the DM history of OG accounts? I believe that it is more likely to be politically motivated.
- Nextgrid 6y agoCollecting potential ammo for later blackmail so they can get the OG username?
- DaiPlusPlus 6y agoSeeing if there were any previous offers made to buy an OG handle - to gauge a good selling-price for the name, perhaps?
- ALittleLight 6y agoI could imagine a teenage hacker downloading his friend's or enemy's DMs. People the hacker knows in real life may be more interesting for him.
- dannyr 6y agoWhy do we assume it's a young person doing the hacking?
- TeMPOraL 6y agoBecause it's becoming increasingly hard to explain this hack otherwise. Imagine you walk by the beach, and see that the sea has washed up a pirate treasure chest. You crack it open, and see it full of gold, jewelry, old manuscripts, letters. Would you just throw the chest back into the sea, taking only a single ring, and a nail from the chest to hang a price list on your lemonade stand with? Because that's what happened here. The attackers hit gold, and threw it all away.
- jmkd 6y agoMore like the attackers rifled through the chest to find the map of the real treasure, leaving the meaningless trinkets behind.
- mortenjorck 6y agoThis is by far the most eyebrow-raising part of the update. To take over such a large number of verified accounts and then run a download on only eight non-verified ones seems almost impossible to have been anything other than targeted. The original idea that the bitcoin scam was a diversion starts to look more plausible in this light, but in the absence of any information about the downloaded accounts, there’s really no way to guess what their value may have been and to whom. Alternately, to throw cold water on the above, maybe the process to kick off a download for verified accounts has extra safeguards and the eight non-verified were simply tests to try to determine why the verified downloads weren’t working.
- Bx6667 6y agoThe idea that someone would opt out of downloading Elon masks or Jeff bezos’ DMs is insane. Completely and perfectly insane. Not to mention the other people. Even if just in terms of profit, clearly the dms of the richest man in the world have enough value to just click download. It seems like the probability of this guy passing it up due to lack of interest is very small. Slightly more likely is that he was overwhelmed by the massive implications of having this access and simply didn’t think to do it in the rush to do something before his source chickened out or realized what was going on. And most likely to me is that he simply couldn’t do it because of a higher level of security associated with verified accounts, hence why none of the accounts were verified. He wasn’t able to do anything with trumps twitter so I suspect that for certain high profile accounts, there is a much higher level of security that this guys source couldn’t override.
- LoSboccacc 6y agothe it's even weirder because this looks something that required a certain amount of planning
- kjaftaedi 6y agoI'm not sure what you're thinking, but it's perfectly reasonable. People like you're talking about don't communicate anything of value over twitter. Bezos only follows his ex-wife who doesn't follow him back, barely uses twitter and would be unlikely to have any DMs at all. After the saudi hack, I would be surprised if he has much of anything installed on his phone. The only real reason to hack celebrity accounts in this instance, and which they should have done, would be to deflect attention from the accounts they actually went after.
- usless534 6y agoOne thing is that it might be trying to get data from OG names to easier guess their passwords?
- secfirstmd 6y agoIts absolutely ridiculous that Twitter does not have end to end encryption of DMs yet. To think that they once hired Moxie/Whisper Systems and could have been miles ahead of everyone else on this. It's purely negligence at this stage.
- Dahoon 6y agoWhile I do agree with you I don't see how this would have helped unless it is encrypted with a key Twitter doesn't have (ie. encrypted in the client with something else than the password). I highly doubt we will see that happen.
- deleted 6y ago[deleted]
- twic 6y agoWhat does this even mean? The attackers had the users' credentials, by resetting them. They had all the access the users had. There is no kind of encryption that would prevent them reading the messages in this situation. Twitter is fundamentally a web app. Users can log in from any browser and read their messages, which are stored on the server. This is a very different situation from Signal or WhatsApp, where an account is tied to a device, and messages can be stored there.
- partyboat1586 6y agoWhy has no one considered the possibility that Twitter is lying about this part? The only reason someone wouldn't do this is if they didn't want the heat and if they didn't want the heat they wouldn't have hijacked high profile accounts to begin with.
- rvnx 6y ago"In cases where an account was taken over by the attacker, they may have been able to view additional information" They say it but downplay it very much. Obviously this means the attackers had access to DMs.
- woko 6y agoWhat if the 8 non-verified accounts are alt-accounts used by celebs/VIPs for personal communication? Let us imagine that I am Jeff Bezos, why would I use my official account to DM people? I would rather use one where I look like everybody so that it is less likely to be the target of an attack.
- giarc 6y agoWould having access to the verified account somehow tell you what the alt account name is though?
- in_cahoots 6y agoIt’s definitely possible. Boy detection will use the number of accounts coming from a single source as a signal. High-profile alt accounts are probably whitelisted so they’re not flagged by accident.
- sildur 6y agoVerified accounts probably require a waiting time before downloading the data. I guess the attackers ran a web scraper on the verified accounts.
- Consultant32452 6y agoWhat if powerful people have pseudonymous accounts that are not verified?
- saalweachter 6y agoHmmm, if we want to assume this is still related to high-profile blackmail material, it's possible they were downloading the DMs from accounts messaged by verified accounts. AFAIK, deleting Twitter DMs only deletes the conversation from your end, so if the verified user, worried about this exact situation, periodically deletes their DMs, but the unverified user, not nearly so worried, doesn't...