Twitter Tells Users They May Be Targets of a 'State Sponsored Attack'
motherboard.vice.com
motherboard.vice.com
Twitter denies this in the article, of course:
>(Twitter has denied blocking Tor. In September, Twitter spokesperson Nu Wexler told Motherboard, “Twitter does not block Tor, and many Twitter users rely on the Tor network for the important privacy and security it provides. Occasionally, signups and logins may be asked to phone verify if they exhibit spam-like behavior. This is applicable to all IPs and not just Tor IPs.”)
I get why they want to keep suspicious actors out of their ecosystem, but the only suspicious thing I did was try to be anonymous. If protecting people from "state-sponsored attack" was actually a priority, they'd figure out ways to enable people to protect themselves.
Temporary IP blocks just work to block that person for that session (in sense of time) in cases where login is not required or can easily be created (like wikipedia). In most cases the people are incapable (through willingness or technical restriction) of changing their IP address and they move on. Short term IP blocks work wonderfully for this.
At least for services like wikipedia which do not require registration for making changes, (which is a great usp), temp IP bans are the best and possibly only solution except for browser fingerprinting.
Other services that require an account creation, like twitter can easily block users and require something like a phone number for known problematic IPs. As can be seen here.
- There might be a bigger uproar if they started doing this than twitter asking for a phone number if you are on a blacklisted IP.
I block connections from most of the world to my various network resource admin points because only I am going to be connecting to them and I'm not going to be connecting from China or Nigeria or Romania. And if I am, I unblock them temporarily.
What would a good solution for this be? Any anonymous proxy would quickly be used by people who want to spam Twitter. (So, among other things, this means that Twitter running a hidden service isn't directly useful.) Could a proof-of-work or rate-limiting system allow building a proxy that couldn't be practically used by spammers?
How does Facebook deal with this problem?
If you really value privacy, you should be willing to pay modestly for it, no?
They also require a mobile number for account activation.
One designs her own anonymity according to one's relevant threat model. For practical reasons, one can reasonably aim at evading global surveillance by not standing among the low hanging fruits, but aiming at staying out of reach of a state sponsored probe is an altogether different matter, think edward snowden different.
Then again some VPN providers exist where they can legally operate without collecting and retaining data about their clients. In any case, be sure to check your VPN provider for the level of anonymity it provides[1].
[1]: https://torrentfreak.com/anonymous-vpn-service-provider-revi...
It comes down to the point made by cperciva in his post "Playing chicken with cat.jpg": http://www.daemonology.net/blog/2012-01-19-playing-chicken-w...
Whereas if you wanted just one anonymous Twitter account badly enough, you could get a burner prepaid cell phone using cash (make sure to not turn it on at home or at work).
Besides, a state-backed attacker will still be able to figure out at least the region where you bought / used the phone for Twitter activation.
The stores keep track of which bar codes have which IMEI.
And of course the register keeps a log of when and what is sold.
I read this in a police report. The police went to the store and got video of the person buying the phone. I wouldn't be surprised if long term video storage was a requirement for selling prepaid phones.
To make completely sure you are not mistreated, you might need to anonymously obtain access to an IP from a residential or mobile ISP; finding out how to do so is left as an exercise for the reader.
Though I could be wrong, of course.
And yes, there will likely be surveillance video records, license tag captures, MAC logs, and so on.
I find it extremely unlikely for this attack to have been perpetrated by the United States; after all, Twitter is an American company and a three-letter could just NSL them for the data they wanted on these "activists".
I received one of these alerts from Gmail years ago, and frankly... it was completely useless to me.
Telling someone they're being attacked doesn't provide much value, what are you supposed to do? I ended up wasting loads of time going through all of my account logs and searching through months worth of emails trying to find signs of this supposed attack... and discovered nothing at all.
Although, props to twitter for recommending Tor. That's significantly better than nothing, although of little use since you are in for a bad time trying to use twitter over Tor.
I got the notification too, it was around the time protests in turkey heated up for the first time.
I see this as nothing but positive. Could it be better? Sure, but what can't be better.
Kudos to the Twitter team for doing what's right rather than what's easy. Here's hoping others will follow your lead.
What I'm saying is that to consider the larger and deeper than the framed picture.
However, some of these attack groups follow specific patterns, use specific IP addresses, domains, emails, etc. because there is no real consequence to them doing so. Kaspersky, Mandiant et al [1] often have great writeups on these types of things that are often posted to their own blogs and to netsec-related mailing lists that show some of these common attack patterns.
On top of this, Twitter could have been tipped off by law enforcement or intelligence.
With the inside visibility of the traffic across their network Twitter would be able to estimate (whether with their own internal security experts or an outside service) the sophistication of the attacker.
Would expect that at this point there was some discussion with FBI as well. Also, as pointed out, very common for a tech company to be notified by FBI/NSA/police in these situations.
I work with one of the people interviewed in the article, we've been having some fun on Slack with it :)
> I work with one of the people interviewed in the article, we've been having some fun on Slack with it
Ooh boy. I don't think there's much you can do about something like this other than laugh it off, and also maybe recognize that hey, you're probably doing something of influence. (And probably make lots of jokes about APTs.)