Twitter down; hacked by "Iranian cyber army"?
techcrunch.com
techcrunch.com
The rest is an scripture quote ("The partisans of God shall prevail", or literally, "Hezbollah will win" ;-) and what seems like a stanza from a nationalist poem.
http://1.bp.blogspot.com/_xpwq_Sv0p98/SysgktMZ9fI/AAAAAAAAAq...
In the name of God.
I, as an Iranian, hack (deface) this website in response to the wrongdoings of this service provider which are commanded by U.S governors.
"Banam Khuda
Beh Inwan Eik Irani dur basikh dakhalat hai shatanat Aamiz ai sarwis dahunda beh dastur maqat Amrika'i dur amur dakhili kashrum.
Aain sait beh `inwan hashadir hek ma shod"
I just parsed out whatever that seemed most Arabic-like; and that is "Amrika dur amur dakhili" ;-)
Even worse, any Twitter client which used Basic Auth without SSL would silently be compromising people's passwords when they auto-refreshed.
Since the API uses the twitter.com domain name, unless I'm missing something the only way that's possible is if the API was being man-in-the-middled.
Something doesn't add up.
...which is very annoying when you're moving a business site. :/
All I can say is that I am glad I do not make money from the availability of websites :)
http://apiwiki.twitter.com/Things-Every-Developer-Should-Kno....
Post a status update and get the resulting status back as JSON: curl -u username:password -d status="your message here" http://twitter.com/statuses/update.json
what it doesn't tell you is that it sends the pw in the clear (unless you count base64 as crypto!)
It's easy to obtain a free but legal CA if you have control of a DNS. Only very few users would notice the change via the hash. Even your browser's SSL detection wouldn't yell anything.
I always think browsers should be developed in two versions and can be switched by one key, one like MSN Explorer, one for advanced geeks with a console.
And given that commercial certs change fairly frequently (they expire every year or two, in most cases), you would have a lot of false alarms for each actual DNS hijacking. The vast majority of the times users saw such a message would be for the wrong reasons, and they'd be well-trained to ignore it long by the time an actual hijack attempt caused it to display.
Also, consider the case of multiple HTTPS servers, each with its own valid server certificate, in round-robin configuration, serving the same domain. Each time a user went from one server to another, the cert would change (but still be valid). They'd get errors all the time -- and my understanding is that this setup (separate certs and private keys for each server, rather than copying the same cert and private key across multiple machines) is considered best practice.
The real problem is that CA-based security relies on the CAs to not hand out certificates stupidly. Yet that's exactly what they do, when they use DNS (in the form of MX records, by sending email) to verify ownership of a site and issue a valid certificate.
You're correct that browser developers have the power here, but their power lies in threatening to drop shady CAs from the trusted root list (which would put a CA instantly out of business -- if your certs cause errors in a major browser, you're dead meat as a CA), not building in more warnings that will just give users bad habits.
IMO, any CA that is doing domain "verification" via DNS records (rather than going through WHOIS or, better yet, the domain's registrar and contacting the domain's owner of record) ought to be dumped from the trusted root list.
There needs to be a much stricter auditing and enforcement/removal system for bad and sloppy, lazy CAs. They are supposed to be the keystone of X.509 PKI, but in reality strike me as being closer to its Achilles Heel.
No other ways, right?
What the fuck else do you want to see twitter do before you think twice about one line joke comments that hurt this community?
I'd argue that the lampooning of such breathless awe, far from being some malevolent outside influence which is "hurting" the community, is a part of the community.
Twitter is making many millions from their search deals. They may not be worth a billion dollars, but I'd bet with the current business configuration, they could become profitable if they focused on it.
What part of "we're focusing on product and growth, not on making money" is hard to understand? Do you not believe them? Think they're actually pushing out ad sales and content licensing as hard as they can? Or, more likely, you're just ignorant of how their business is actually run. Ignorance is actually a generous term - you might know they're already making money and willfully ignore it.
I actually agree that twitter's image is inflated. But the US government was the first to make a move here. They didn't ask facebook to try to stay up (they didn't need to). I think this response by cyber terrorists (if it isn't some teenage in ohio) is rational.
It isn't what you were saying that I reacted to particularly, but how you said it. It would be the equivalent to my just responding "you're obviously an idiot who doesn't know anything about twitter".
Or at the very least they would be monitoring for such intrusions and be able to stop them quickly.
How long did this last anyway?
You might want to mess with a dummy object first to practising instantiating without producing any person objects.
Twitter need to really step up: I can't imagine this is something that couldn't have been prevented by paying for some security analysis. Considering their total $155M of funding, I'm shocked this wasn't done. Between their continuing difficulty scaling, their private documents leak, and now this, twitter really needs to get their act together.
Poor Twitter ops; I'm sure they're having a great evening.
http://www.reddit.com/r/reddit.com/comments/ag0gn/twitter_ha...
Of course, if their DNS was compromised, status.twitter.com could be compromised too...
Given that and the speed at which the service recovered, I'm going to say it does not seem like a DNS attack.
Many people have been wondering, 'Hey, who are these DST guys that are continuously going long on Facebook at ridiculous valuations?'
'They even let employees at places like Facebook and Zynga cash out early!'
'Gosh, Russian businessmen must be nice.'
Now if I had large sums of money that I wanted laundered, the method right up there at the top of my list is venture capital firm investing exclusively in overseas assets. Money is laundered via profitable exits on investments in foreign countries. In fact, strictly speaking, the exit does not even have to be profitable.
Unless you are greedy.
Which brings me back to Russian businessmen. Accusing anyone of anything is not the intention here, but a word of caution to Silicon Valley is in order. In Russia, business is a game played in somewhat less cordial a fashion. Also keep in mind that in Russia . . . you stab with a borrowed knife.
I think we can expect many more attacks on Twitter. From hackers claiming to be 'Chinese', 'Iranian' or 'North Korean'.
Do you really think the focus of a cyber ops campaign or anti-competitive campaign would be ... to put a stupid message on Twitter's website? There are no doubt cyber ops teams in foreign (and domestic, naturally) intelligence, but they don't waste their time on shit like this.
"Is the Twitter API down? Not likely: Twitter hasn't had more than a couple minutes of downtime in a while. Requests may lag from time to time, but chances are pretty good we're not down."
I'll be watching http://groups.google.com/group/twitter-development-talk?pli=... for interesting comments
Looks like Twitter just took down the entire front page though. Going to be a late night in California...
"Older tweets are temporarily unavailable."
where older seems to be > 8 days
Can you even fathom Google getting hacked.
Granted, they briefly managed to serve some content as twitter, so it does look like a genuine hack rather than merely a DDoS or something.
[edit] TechCrunch is reporting it's a DNS redirection attack, so their machines were probably never compromised (your password is safe). It also probably means the site will not be back up for a while, as it will take time for the DNS to propagate everywhere even after they fix it.
[edit 2] ...aaaand it came back up 3 seconds later.
Wouldn't they be posting your account password to http://twitter.com, or twitter only uses HTTPS? If there is any way to login using standard HTTP, the same server that is used to deface the website can be collecting tons of user credentials.
And even if twitter uses only HTTPS, what's the policy of twitter clients in regard to bad certificates?
Who is "they"? the drones were hacked by Taliban, twitter by the Iranian Cyber Army.
Similar dilution of the term occurs here on a daily basis.
I don't even like the idea of microblogging, so to me this is about as big of news as hearing that the IRA managed to bomb a backyard chicken coop.
ed: didn't mean hacked, I know it was just a matter of listening to the data feed, not actually doing anything to the drone.
(Iranian Cyber Army -> Indian Cyber Army)
but with all the new deals they got, they are probably going to restart growing soon. And of course there are lies, damn lies and web-statistics-selling companies.