23 ms·
Twitch is hacked, and its source code leaked
- han_solo 5y agohasanyone looked at the code? what language is it in?
- luis8 5y agoI wonder how often these "hacks" are just an engineer leaking the info.
- nemothekid 5y agoThis is a pretty thorough and high profile hack on a major tech company - this isn't something I'd expect from an Amazon owned property. The hack (allegedly, I haven't downloaded it) includes * Entire git histories * Internal/Private AWS SDKs * Encrypted Password dumps and payout reports It's so comprehensive I'm very curious into how an attacker got that level of access. I can't think of another, large, corporate web 2.0 startup who's gotten owned in a similar fashion. Could the same attack work on Amazon? YouTube? It's also strange that someone who has this level of access to what is presumably a multi-billion dollar company decided to just leak the data? Maybe they did try to ransom it, but I'd imagine someone with this kind of access inside Twitch must have had some creative way of making money.
- skilled 5y agoI'm hoping we will get to see a transparent report (from hacker or Twitch) on how this happened. I think anyone would be excited to hack Twitch as the site alone - or any big platform for that matter - but this is quite literally someone just downloading the entire Twitch ecosystem and publishing it online.
- ergerger 5y agoTwitch has not been known to be transparent about anything.
- Hokusai 5y ago> this isn't something I'd expect from an Amazon owned property Because you expect Amazon to put security priority over new features and profit? We have very different understandings of what Amazon stands for.
- adrusi 5y agoEC2, Amazon's cash cow, competes with nearly identical offerings from Microsoft and Google, and is not a place where additional features are often all that valuable to customers. Any sort of breach like this on EC2 would seriously hurt Amazon's bottom line and they know it.
- nemothekid 5y ago>Because you expect Amazon to put security priority over new features and profit? I don't know what you think Amazon stands for, but Amazon runs the largest cloud hosting service in the world - AWS, which not only runs a large number of other large companies but governments as well. I know, first hand, that their datacenter security protocols are state of the art. Amazon has a much larger surface attack area so if they were playing fast and loose with security, chances are we would know already.
- Hokusai 5y ago> Amazon has a much larger surface attack area so if they were playing fast and loose with security, chances are we would know already. I get your point and I am no taking about AWS but about Twitch. Each part of the company has its own incentives. Amazon is well know for not caring about quality nor its employees. In my experience with corporations there is little to no technical sharing between different parts of the company. AWS could have the best SecOps in the world and Twitch could have no security at all. Is your experience different?
- vineyardmike 5y ago> In my experience with corporations there is little to no technical sharing between different parts of the company. Amazon is all about sharing efforts with the company. That's the whole point of AWS - its a monetization of this efforts. Most older AWS services started out as internal services that someone realized was generally useful.
- FormerBandmate 5y agoI mean, it did work on Amazon (a division with poorer security probably, but still). 4chan is a truly special place
- leros 5y agoIt something I would expect security hardware to have automatically stopped. Even an employee shouldn't be able to download 125GB of stuff without flipping a safety switch somewhere.
- com2kid 5y ago> Even an employee shouldn't be able to download 125GB of stuff without flipping a safety switch somewhere. I am trying to recall, but I am pretty sure when I worked in Microsoft Office that a build would pull down many tens of gigabytes of data. 125GB in one day from the build system wouldn't be uncommon!
- Raidion 5y agoThat's ingress though. Companies should be monitoring and worrying about egress. Edit: This won't help against a thumbdrive, but that type of thing should be also tracked.
- AustinDev 5y agoI'm working on a project and just had to repull my workspace after some local corruption. I pulled 1.2TB out of the office and never got an email. I think it's pretty common for places not to monitor egress that closely.
- yawaworht1978 5y agoIndeed , how could this happen, really curious. So let's say someone with access to all GitHub repos gave the password to someone else, maybe then it was downloaded from another machine? Or someone stole the credentials and downloaded from another machine? Or someone got access to such a machine? It's it not possible to prevent these cases? How long does such a download take?
- stefan_ 5y agoCue monorepo discussion
- koolba 5y agoHow much of this is a holdover of lax security practices from before they were acquired? I can’t imagine AWS being managed in a way where local network access gives you keys to the kingdom. Then again, EC2 instance profiles do let you do quite a bit.
- lamontcg 5y agoConflating AWS security with twitch security is probably the wrong way to think about it. Within Amazon those are almost going to be two entirely separate companies, with very different security focuses. The idea that Amazon is monolithic and uniform wasn't true when I left there in 2006, and I'm certain it is less so now. And that isn't just that its related to the merger, but that fundamentally its different business orgs with different focus.
- vineyardmike 5y agoBut does twitch not share the same Amazon wide git service? Could most of Amzn code be leaked or compromised? Seems like all of amazon internals that shares security measures is at risk...
- cheeze 5y agoI've heard (but don't have any actual evidence more than hearsay) that Twitch generally operates independently of Amazon/AWS. I'm sure that they share some things, but I wouldn't be surprised if their source was separate from the "main repo"
- bleepblooop 5y agoRemember that Amazon runs one of the biggest multi-tenant service platforms in the industry! A separate business unit like Twitch is likely to be set up a lot like any other random AWS customer, and you wouldn't expect that compromising servers used by one AWS customer to automatically compromise the underlying infrastructure. (I would also expect that the Amazon retail systems are in most senses "just another tenant" on AWS, albeit with much more liberal quotas!)
- 5y ago
- ArlenBales 5y agoThere are so many indiscreet USB pentesting devices easily purchasable by anyone today, I'm actually surprised this sort of thing doesn't happen more often.
- SketchySeaBeast 5y agoShouldn't that be discreet devices? Or do they make a really high pitched whine with a big flashing light when they start transferring data?
- angst_ridden 5y ago"Hey, Jeff, what's that weird thumb-drive over there that keeps texting me `I'm in your datacenter downloading your datas'?"
- 63 5y ago> It's also strange that someone who has this level of access to what is presumably a multi-billion dollar company decided to just leak the data? Maybe they did try to ransom it, but I'd imagine someone with this kind of access inside Twitch must have had some creative way of making money. Notably, the initial leak didn't actually include the password data which the leaker claims to have, just source code and payment data which has been verified by several affected streamers. It's possible that this first leak was just to establish trust so they can random or auction password hashes later.
- zinekeller 5y agoMaybe that Twitch is competent in the password department so they decided against it? But thinking about it, although it's unclear if two-factor secrets are included in the leak, but maybe the two-factor secrets may be usable to someone who has already the password of a victim. Unless it's the dongle-type one (WebAuthn/FIDO), the secret is common to both the server and the user, so two-factor bypass is almost certain in this case.
- nemothekid 5y ago>It's possible that this first leak was just to establish trust so they can random or auction password hashes later. Password hashes are relatively useless though? Once the leak is announced I imagine most of the big targets will rotate their credentials. Then the next thing you need to do is spend possibly thousands in CPU time bruteforcing bcrypt hashes. Then I'm not sure what you can even do with those. I'm not criminally creative but I imagine you could make more by abusing trust with payment processors or fraudulent invoices.
- j_walter 5y agoRelatively useless...but if even a few percent of people recycle passwords used for banking or crypto platforms it could be a profitable cache of data.
- tyingq 5y ago>Then I'm not sure what you can even do with those Assume some end users used the same passwords on other, non-twitch accounts. That's what makes hacked passwords valuable, no matter where they came from.
- yupper32 5y agoDoes anyone know if Twitch employees have two factor auth? Having access to an employee's account would be the easiest way to pull this off. It'd be strange if they don't have two factor auth, of course, but it's just as strange to have this large of a hack. I think if it is a simple case of an employee account takeover, then the attack would "work" to some extent at any company. Larger companies typically have strict data access requirements, though. Good luck finding the few employees who have raw access to Google password hashes, for example. And even more luck knowing how to get that data if you do.
- some_furry 5y ago> Does anyone know if Twitch employees have two factor auth? Yes, IIRC everyone at Amazon has a hardware security key (which is more secure than the standard mobile app TOTP most of us use everywhere online).
- ramesh31 5y ago>(which is more secure than the standard mobile app TOTP most of us use everywhere online). Is it though? The "wrench theory" applies here. It's not unthinkable that an employee was stalked on social media and had their key stolen.
- bawolff 5y agoIts still more secure. Rubber hose cryptanalysis applies to both equally, but that doesn't mean there aren't other attacks that apply to totp which don't to yubikeys. More secure != perfectly secure.
- xmprt 5y agoWith a phone you need my passcode to accept to 2FA request (assuming lock screen notifications are disabled). I think yubikeys can work without a passcode as long you plug it in right?
- pizzazzaro 5y agoConsidering who owns it? There's conversations with government agencies asking "are we okay?" To the world's richest man.
- kordlessagain 5y agoFrom an ethical standpoint, any code that amplifies and profits from radical speech should be fair game for release. If employees or hackers feel the need to release info in that regard, so be it. This is the risk defined in such models and should be mitigated accordingly.
- heurisko 5y agoWho decides what speech is radical enough to compromise the privacy of users? And if speech is "radical" meaning to the point of illegality, shouldn't the legal system decide, rather than the court of public opinion?
- kordlessagain 5y agoRadical as in pushed to the extremes, not radical in thought to the general population. See https://www.youtube.com/watch?v=rE3j_RHkqJc&t=1s https://www.youtube.com/watch?v=rE3j_RHkqJc&t=1s That I've been DONT MENTION ARROWS ON HN on this post is a good indication we're not close to solving this by a long shot.
- madrox 5y agoThere were no encrypted password dumps. No production secrets were leaked (according to the article). What's here is no more than what your average Twitch engineer has access to. Yes, that included payout data. Anyone with "staff" access to the site (which any employee can have) has access to any streamer's dashboard, which includes payout data. I don't think this was an attack. Based on the data so far I think it was a disgruntled engineer. Obviously if more gets leaked later I may revise that opinion.
- twistedpair 5y agoSo much for information compartmentalization. Does the typical engineer need access to payment details for their daily work?
- deleted 5y ago[deleted]
- ABeeSea 5y agoPart of the appeal is working at a place like Amazon is having a voice in decision making in the product you’re building. Hard to make informed decisions or opinions without the data. Engineers in Amazon retail definitely have broad access to sales data.
- oconnor663 5y agoThe tradeoffs for any individual piece of data are different from the tradeoffs of a company-wide policy. Siloing off one little thing (e.g. credit card info) usually doesn't inconvenience very many people, but at the same time it only provides marginal security. No front page headline has ever read "At Least The Credit Card Info Was Safe". On the other hand, a company-wide policy of siloing everything can have more of a security impact, but it also inconveniences everyone frequently. That's the tradeoff that many tech companies don't want to make.
- zerkten 5y agoI don't see how this precludes just-in-time access. Even if people can re-up on their own, you can still observe the data access patterns and manage the risk. Further, when you see someone is getting blocked a lot you can improve the experience for them so they are unblocked, or have more efficient access to the data. This is just mature data and security management. Quality of life and developer experience are important topics in many ways, but should they really trump security consistently? It's always going to be dependent on people's risk assessment and comfort, but frequently it skews the wrong way because the people making the decisions know that they'll be gone.
- gorgoiler 5y agoFacebook [2011] was pretty bad… https://www.theguardian.com/technology/2012/feb/17/facebook-hacker-glenn-mangham-jailed https://www.theguardian.com/technology/2012/feb/17/facebook-... …except Mangham didn’t ever get to release his spoils to The Internet?
- dilyevsky 5y ago> I can't think of another, large, corporate web 2.0 startup who's gotten owned in a similar fashion Linkedin, Microsoft, Yahoo, Google
- slightwinder 5y ago> It's also strange that someone who has this level of access to what is presumably a multi-billion dollar company decided to just leak the data? From what I heard about Twitch-interns over the years, it seems the company is more a third-rate-s**hole that grew too big too fast and accumulated a huge amount of technical debt and fatal security flaws. Making billions doesn't mean anything if you don't invest them back into the important corners of the company. It's considered a miracle that the platform is still working that well in that state. And what comes from the leaks so far supports this view. Though, said that, it seems they did start to improve one or two years ago, just too late to prevent this critical hit. But considering this was also a strike that avoided the deadly parts (yet), maybe there is a different aim here and the company can grow from this? It will be interesting to see how Amazon will react to this.
- superfrank 5y ago> From what I heard about Twitch-interns over the years, it seems the company is more a third-rate-s*hole that grew too big too fast and accumulated a huge amount of technical debt and fatal security flaws. I mean this as a genuine question, but is there any company that didn't end up like this after an exponential growth phase? I'm not saying it's okay, but this feels par for the course. I've now been at two start ups during that hockey stick growth time and both went through this as well. I'd be curious if anyone here has worked at a large, fast growing tech company where they didn't accumulate a ton of technical debt during growth. If so, what did the company do to prevent that?
- slightwinder 5y agoGenerally yes, but Twitch is not your average startup. It's now 10 years old, and 7 of those years it was owned by Amazon, which should have enough competence and manpower for bringing it onto a good course. But from what I heard, Amazon did neglect Twitch for a long time and focused too much on making it a profitable business by all costs. Because of which they had all those scandals and problems in the last years. It's a business-platform, where technology is just an afterthought.
- aahortwwy 5y agoITT: people shocked that something like this could happen at a company the size and profile of Twitch. Running security at scale in a hypergrowth B2C company is very difficult. It's also completely different from running security at a startup, in a B2B company, or a slower-growth situation. _Every_ security executive and manager I've met has given up in frustration after 12-24 months and gone to take a cushy FAANG job instead. I'm not surprised at all. My experience in security at a larger SV unicorn was that changes only happened in the immediate aftermath of a security crisis. Otherwise, there was incredible inertia and you just wouldn't be able to get the institutional support you needed to make progress.
- _qbjt 5y agoMore discussion here: https://news.ycombinator.com/item?id=28770590 https://news.ycombinator.com/item?id=28770590
- ChrisArchitect 5y agolots of discussion and speculation from a few hours ago here: https://news.ycombinator.com/item?id=28770590 https://news.ycombinator.com/item?id=28770590
- dolores_ab 5y agoSomeone actually started streaming going through the code ... on twitch. https://www.twitch.tv/deepfrieddev https://www.twitch.tv/deepfrieddev
- jedberg 5y agoHah. This is like when reddit does something people don't like and there is a huge thread about it ... on reddit.
- mawaldne 5y agoThis no longer works. Guy got banned I think.
- echelon 5y agoIt just got disconnected. The chat had a few Amazon insiders, which was interesting to read their perspectives.
- treesknees 5y agoAny bits you recall from the chat?
- Avery3R 5y agogot banned
- Orphis 5y agoAnd banned
- onnnon 5y agoChannel is gone, banned?
- jeffalo 5y agoYep, we saw it happen live.
- Nickoladze 5y ago
- runawaybottle 5y agoDoes it take a genius to figure out how to build twitch? It’s a modern crud app with video streaming.
- decebalus1 5y agoThis reminds me of the Albertsons guy on Blind who inadvertently created a meme when he said that Facebook could be rewritten with a small cluster of Oracle dbs. The meme is that Albertsons people are so elite, they work and think in a higher level of existence, way above the scalability bs us commoners are accustomed to.
- lwansbrough 5y agoJust stream the video, it’s easy!
- kinghajj 5y agoNetflix & Youtube in shambles.
- lapetitejort 5y agoI found out how to destroy reddit. Just fork their repos! https://github.com/reddit https://github.com/reddit
- duskwuff 5y agoSadly, Reddit stopped updating the public repo for their main application in 2017: https://github.com/reddit-archive/reddit https://github.com/reddit-archive/reddit
- BitwiseFool 5y agoIt's for the best. New reddit is awful.
- asddubs 5y ago
- DavidPeiffer 5y agoI'd be interested if someone could get their own instance of Twitch up and running from this leak. Someone mentioned internal API's, which would have to be reworked to avoid detection, but it'd be interesting to host it on AWS just to see how long it takes to get shut down. How would current AWS policies hold up? Obviously the code would be illegally acquired, but do they have detection mechanisms in place?
- manquer 5y agoEven with source code it is hard to run a service if not impossible. You would need well written documentation that explains various options and error codes you could potentially get. Many times there is some magic command only one guy knows and he will share with you on slack. Rubbing a service of any complexity takes years of institutional knowledge.
- BugWatch 5y agoPlease don't rub the services, it causes unnecessary friction, and wear & tear.
- ijcd 5y ago100s of services and databases to work out and sort through. Good luck building a global real-time video CDN too. You could build your own faster. Microservice architectures mirror the org that built them. You wouldn’t do it the same way for yourself.
- marto1 5y agoWe're just walking into a future where these kind of leaks happen every other day, aren't we ?
- shapefrog 5y agoWe are already there it seems
- cblconfederate 5y agodoes it matter? social networks arent some obscure technology, but making them successful is
- mastermojo 5y agoThere's something about this sentence that I find hilarious: The download was posted to 4chan today, described by its unidentified source as “part one” of “an extremely poggers leak,”
- jallen_dot_dev 5y agoThis hack was not very xqcL of them.
- wchar_t 5y agoI find it extremely ironic that they whine about Twitch being a "disgusting cesspool"... on 4chan. > Calling Twitch a “disgusting toxic cesspool,”
- noncoml 5y agoAnybody took a peek? What language, and framework if they use one, do they use?
- dolores_ab 5y agoA mix of Go, Ruby, Python, Elixer from what I saw.
- blain 5y agoHere are a few screenshots of go and php: https://sizeof.cat/post/twitch-leaks/ https://sizeof.cat/post/twitch-leaks/. WARNING: do not click the link, copy it and paste it in new tab.
- whimsicalism 5y ago?
- kreitje 5y agoThey check the referrer, see it's from HN and redirect to an image instead. So by copy + paste into a new tab, it will lose the HN referrer.
- rcfaj7obqrkayhn 5y agoon firefox, disabling referrer means you won't see the image network.http.sendRefererHeader = 0
- deleted 5y ago[deleted]
- holler 5y agoI know the original frontend used ember.js but then they switched to react... that's about all I know :D (twitch used to sponsor and attend local ember.js meetups)
- 5y ago
- frays 5y agoAs an avid Twitch streamer, what do I need to do to protect myself?
- INTPenis 5y agoChange your password obviously, maybe even reset your 2FA if those codes are in the leak. And if you want to be perfectly safe, don't visit twitch. Because if that source code has any vulnerabilities they might be exploited against twitch visitors as we speak.
- notsureaboutpg 5y agoIf the literal source code is leaked, you should: Change your password (and if you used this password at any other site, change it there too). You might want to put a hold on the credit card you stored info of with Twitch (for any followers). If the source code is compromised, other attacks are possible. Depending on how the code works, it may be possible for attackers to successfully charge your followers while you stream. It would be very easy to phish your followers with a website that looks like twitch but is in fact twtich.com for example. And then charge them when they think they are donating to you. It's honestly probably going to hit you hard if you have to move to an alternative service. But you have to weight that against the very real threat of this leak being used to steal from your followers or you.
- ALittleLight 5y agoAlso change any account with a password that's the same as your twitch account. Once they know your twitch password they will try it on your related accounts.
- shapefrog 5y agoReport your earnings on your tax.
- rasz 5y ago> including its source code This will help with ad preroll blockers. I would love to see someone look deep into Twitch recommendation system - last time I tested the thing they call "Feedback" is a rolling buffer and wont let you exclude more than ~100 things, adding more simply removed oldest entries and started spamming you with things you already excluded in the past. This looked like performance optimization (less things to track per user).
- mariusor 5y agoThis won't help with preroll ads because the video segments themselves are replaced in the stream data. They're not ads, but it's not the stream either. You get a "twitch commercial break in progress" video for the time the ads are playing. You can check this by loading a stream with MPV.
- rasz 5y agoaaand new ad bypass dropped 4 hours ago :) >You can check this by loading a stream with MPV I watch all of my twitch using mplayer. "magic incantations" when generating access token is what produces ad free .m3u8. For example early methods involved setting origin and/or referrer headers to internal Amazon systems.
- iuri1 5y agoSince the main leaked files are from github, I'm assuming they got it from one of the many reported github auth flaws which don't get fixed and allows access to private repositories. Or more unlikely, via someone getting sloppy with their laptop. Now I wonder if the commit history has database dumps or sensitive information, which is a common practice, or if any twitch servers have been accessed through a breach or privileged information found in some of their source code.
- fhood 5y agoHang on, is this just a repo dump or not? Because it looks like a repo dump, in which case I would be very surprised if any passwords or other personal information is included, at least at a reasonable scale.
- anthk 5y agoFrom banned usernames, "Jesus". Yep. From Mexico to the Pagonia and Iberia, let's screw a few millions of users.
- rawoke083600 5y agoat we least know their backups were 'complete' ! This hack seems to includes everything and the kitchen sink !
- 1vuio0pswjnm7 5y ago[deleted]
- jackson1442 5y agoI thought it was pretty obvious that that was a joke.
- imwillofficial 5y agoIs this the first time actual Amazon infrastructure has been hacked? Anyone has Amazon been hacked pervious to this? (Not talking about insecure AWS accounts)
- personjerry 5y agoThe top streamers' earnings were also leaked: https://www.twitchearnings.com/ https://www.twitchearnings.com/
- andrewstuart 5y agoWhat language is the main website written in?
- bob229 5y agoTripe article, stating the obvious
- staysafeanon 5y agoActually in Twitch's codebase: OR replace($1,'_','') SIMILAR TO '%(hate|kill|keel|hang|burn|gasthe)%(black|bl4ck|black|jew|trans|gay|african|afrikan|minorit|asian|nig|n1g)%' Twitch: "Hatred against Blacks, Jews, Asians, trans? BANNED! Hatred against Whites? I'LL ALLOW IT!"
- doctorshady 5y agoArchive of the original 4chan post from this morning: https://archive.is/8rQNK https://archive.is/8rQNK
- throwaway729272 5y agoI cant wait for some to look at the experiments they ran. I imagine something like: commit b160b523b0fa6a747fd217fed778f281334ee64f (HEAD -> master) Author: john smith <john@twitch.com> Date: Wed Oct 6 17:41:42 2021 +0200 exp_promote_gambling make experiment to promote gambling content for kids with loot boxes to see if they donate more money, if not we will try to show them promiscuous content. I think developers should be personally responsible if they knowingly act against their fellow men. Its not facebook or twitch or tiktok that are magically stalking us and making us addicts, it is the hundreds of thousands developers that are taking 5x salaries to (very knowingly) do so. The engineers of nazi Germany spend time to make gas chambers that use human fuel.. Now developers are literally and knowingly making addict kids, teen suicides, depression, finding more innovative and creative ways to stalk us, etc etc. I recently interviewed a person who was working in a gambling company, and they knew very well what they were doing there, who were they hurting and exactly how much. How is that different than selling drugs to addicts? We are engineering the next gas chambers, and we have to be held accountable, and we have to be able to say 'no, i am not going to build this feature' without losing our job. This is extreme statement, but things can not stay like this.
- evilboy12 5y agoAmazon is full of shit lol, and so it’s their twitch
- evilboy12 5y agoAmazon is full of shit and so is their twitch. This breach was gonna happen sooner or later. Nothing surprising!
- j_galt237 5y agoIt looks like this bot gives access to the leaked data: https://t.me/twitcheroo_bot https://t.me/twitcheroo_bot