9 ms·
Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update-on-our-security-incident.html https://blog.twitter.com/en_us/topics/com
by 0xUser 6y ago
Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update-on-our-security-incident.html https://blog.twitter.com/en_us/topics/company/2020/an-update...
> The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all of the employees that were initially targeted had permissions to use account management tools, but the attackers used their credentials to access our internal systems and gain information about our processes. This knowledge then enabled them to target additional employees who did have access to our account support tools. Using the credentials of employees with access to these tools, the attackers targeted 130 Twitter accounts, ultimately Tweeting from 45, accessing the DM inbox of 36, and downloading the Twitter Data of 7.
- nodesocket 6y agoWhy are internal employee tools publically accessible? Minimum they should require VPN access, but really go further with Zero Trust.
- bawolff 6y agoThe blog post is vauge but definitely implies that a vpn was in place.
- whoisjuan 6y agoAFIK, in a Zero Trust Architecture a VPN is considered a perimeter and therefore it becomes a vector of attack to access systems of authoritative decision. Many security researchers have already established that the benefits of a VPN especially in the modern distributed world are marginal at best. Basically, yes a VPN makes you a tiny bit safer but it also adds a lot of networking complexity and adds more friction to the job of your employees. It also becomes an attack vector for malicious parties, since once they get VPN access they can theoretically access at least the first layer of protected resources. So in layman's terms an attacker just needs to phish for VPN credentials, maybe steal an OTP token and they will have access to a non-trivial amount of network protected resources. On the other hand if every service you use has its own authentication then the attacker needs to target each service and to know what services to attack they need knowledge that is possibly contained in another system that also requires authentication and is definitely not guaranteed for the attacker that all the systems will have the same password and/or have 2FA disabled. Honestly, in my opinion VPNs are just an excuse to monitor traffic. This is a bit of cynical take, but I'm convinced that companies that use VPNs are more interested in seeing what goes in and out their network than in protecting their resources.
- jcims 6y agoDepends on what you're defending. If your enterprise is a global network with millions of nodes operating a blend of modern and legacy systems accumulated through hundreds of acquisitions in 100+ countries over the course of the last 50 years, a VPN with hardware tokens isn't a bad additional layer. It isn't even mutually exclusive with zero trust, it's just another layer of auth and access. Twitter? Largely a different story and commando zero trust might be a viable option. As observed many other places, this sounds like a poor authentication model and probably poor governance for highly privileged access. Presumably they will take a look at their authentication, which sounds like it's making some bad assumptions, and improve.
- AnonC 6y ago> On the other hand if every service you use has its own authentication... This would be a nightmare for the people managing any nontrivial system. There are good reasons to use something like Active Directory and tie systems and applications to it for easier policy enforcement and management. There are good reasons to avoid this centralization for certain things too. Either extreme would be an exercise in frustration.
- whoisjuan 6y agoCertainly. That’s why things like Okta make sense. It allows people to use it as a Password Manager while keeping certain level of sanity in managing resources but without giving up individual authentication against services. I’m not so sure that it works that well once it becomes the actual authentication middleware. But as a single sign on directory it definitely reduces the complexity for the employees and for IT departments. Either way I think more than systems, people need training. I know there are sophisticated phishing attacks but someone who has been trained to understand and acknowledge these situations should be able to detect when someone is trying to steal information. I think Twitter’s failure was to not properly train their employees especially when they are such a visible and juicy target for bad actors.
- gsich 6y ago>Many security researchers have already established that the benefits of a VPN especially in the modern distributed world are marginal at best. Yes, with the (wrong) assumption that after you have connected to a VPN, all other services are free for the taking, without any further authentication.
- Thorrez 6y agoWhat if the attackers phish the VPN credentials too? Does Zero Trust imply phishing-resistant credentials? What Twitter needed was phishing-resistant credentials (security keys, aka U2F).
- staticassertion 6y agoZero Trust != VPN. Zero Trust means that the network is not what determines trust. Consider this: * You go to your office, connect to the network * Now you have access to internal services, by virtue of being on the network In a Zero Trust network it does not matter what network you are on. Trust is handed out individually, based on the identity/ role of the user and the context of their session (is their os patched? running security tools?).
- Thorrez 6y agoHow does the site know the user's OS is patched? The User Agent? How about whether security tools are running? The attacker can surely use a patched OS. Are the security tools secret? If not, then the attacker can run the security tools too.
- staticassertion 6y ago> How does the site know the user's OS is patched? The User Agent? User agent is a great place for a version 0, sure. 99% of your assets aren't compromised, so worrying about a bypass isn't important to most of them. For a v0 just knowing that most of your boxes are patched is a huge win. Of course you'll want client certificates on devices, or some sort of TPM, which is how Chromebooks work. The attacker having a box is not enough - identity is a key principal of zero trust networks.
- ThA0x2 6y agoAnother instance where zero-trust networking has utterly failed. Security comes in layers. That first layer of requiring a VPN can stop many types of attacks from happening. Next layer is requiring MFA for VPN access. Then for admin access, require MFA only from approved devices on the domain. Large banks and the DoD have been doing this for years. The "fail often and fail fast" crew are always reinventing the wheel after bad experiences. I honestly feel sorry for them.
- dcow 6y ago? This definitely wasn’t a zero trust failure.
- ehsankia 6y agoWere the spear fishing attacked also used to get 2FA, or did these accounts not have 2FA? Would hardware based 2FA not have stopped this?
- deleted 6y ago[deleted]
- zamalek 6y agoI haven't seen a form of phishing that hardware 2FA doesn't stop. Yes, it would have.
- fareesh 6y agoThe way it is worded can also mean that there were XSS vulnerabilities in the internal tool since they are saying "gained information about how our processes work". I feel like that's a strange and vague thing to say. The right kind of xss vulnerability would enable them to bypass 2fa too, maybe steal backup codes even.
- berkes 6y agoI understood that line as 'saw names, contact detail, positions and permissions of employees'
- Thorrez 6y agoIf there's an XSS attack I don't consider that phishing.
- fareesh 6y agoIsn't it both? Phish first user, post to internal tool and xss attack second user.
- Thorrez 6y agoYeah I guess you're right, it could be like an exploit chain where 1 link in the chain is phishing to gain access to something and xss is the next link for lateral movement. But I don't know what "The right kind of xss vulnerability would enable them to bypass 2fa too" means. If the attacker doesn't have 2FA I would think the attacker can't log in, thus meaning the first link of the chain has no purpose. But I also think XSS in this case is not very likely. From interviews with the attackers it sounds like they're social engineering experts who hang out on social engineering forums, not XSS experts[1][2][3]. [1] https://krebsonsecurity.com/2020/07/whos-behind-wednesdays-epic-twitter-hack/ https://krebsonsecurity.com/2020/07/whos-behind-wednesdays-e... [2] https://www.nytimes.com/2020/07/17/technology/twitter-hackers-interview.html https://www.nytimes.com/2020/07/17/technology/twitter-hacker... [3] https://krebsonsecurity.com/2020/07/twitter-hacking-for-profit-and-the-lols/ https://krebsonsecurity.com/2020/07/twitter-hacking-for-prof...
- andrew_ 6y agoI'd like to know more about these tools. That there's at least one which can bypass a user's 2FA settings without notification suggests that there are additional tools in the same vein.
- spullara 6y agoEvery network has to have tools to do that. How else will they enforce the laws they are required to enforce?
- cmelbye 6y agoThose legal requests aren’t serviced with a password reset in order to log into the account. It seems more likely that there’s an internal tool to help people who have lost their second factor, but that’s just a guess.
- deleted 6y ago[deleted]
- ma2rten 6y agoGoogle requires its employees to use a security key for access to all internal systems including admin tools, source code and email. Every since google started enforcing this policy the number of successful phishing attacks has gone down to basically zero.
- Thorrez 6y agoDid you reply to the right comment?
- londons_explore 6y agoI believe the Twitter attack involved tricking a user into installing proxy software on their machine (to be in twitter's internal network). If that is the case, that same proxy software could proxy the security key requests too.
- 6y ago
- dang 6y agoOk, we'll change to that from https://www.reuters.com/article/us-twitter-cyber/twitter-says-spear-phishing-attack-on-employees-led-to-breach-idUSKCN24W089 https://www.reuters.com/article/us-twitter-cyber/twitter-say.... Thanks!
- harikb 6y ago> ultimately Tweeting from 45 for a moment I thought it read `tweeting from 45's`
- DoofusOfDeath 6y agoNah, you're thinking of putting a 33 RPM disc on the phonograph, then setting the playback speed to 45 RPM. Hands down the easiest way to make Shaun Cassidy sound like one of the Chipmunks.
- dpweb 6y agoNo disrespect to those challenged with protecting such a huge target, but why do admin tools even have these capabilities? I could see needing to disable a user account or change some attributes, but why would an admin ever need to tweet from it? There shouldn't be tools with God privileges even for admins. Not surprising human error was involved in a breach this huge. So, how many people had access to this tool? Is there a killswitch for the tool itself available to very few, really very few, persons? edit: I dont know if the tool can tweet but surprised 2FA can be stripped without a human being confirming (ie.. the acct owner's social media person), especially for famous people.
- yipbub 6y agoThey probably had permissions to change/reset the access credentials which can be used to gain access as a the user.
- Thorrez 6y agoI doubt the admin tweeted from the tool. The admin changed the email on the account, then did a password reset, then logged in as the account then tweeted.
- dlkmp 6y agoDid they tweet directly from the admin tools? My impression was that they used the admin tools to reset the password and then take over the account, ultimately tweeting like any normal user would do.
- erk__ 6y agoIt is my understanding that they used the tools to update the email of the account, then reset the password to log into and make a new password such they could log in and tweet. Do you have any source that says that they could use the support tools to tweet directly from?
- wraithy 6y agoDo we know for sure that the admin tools can do all this? My understanding was that the tools enabled password resets, which allowed the attackers to tweet from the accounts themselves. > For 45 of those accounts, the attackers were able to initiate a password reset, login to the account, and send Tweets.