Twitter internal panel linked to account hijackings
vice.com
vice.com
This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no technical countermeasures.
I'd like to see a system where it is physically impossible for a customer service rep to discover any info about me until I authenticate and authorize it. Or to at least offer me the option to lock my account such that I need to authenticate and authorize before any access is given to the customer service rep.
Does anyone know of customer service panels at big companies or government departments where this is the case? I.e., it is literally impossible for a rep to browse random customer information even if they are willing to break the rules? If it's been done somewhere, it would be interesting to hear how it was implemented.
From their perspective, they want the ability to ban/kick/etc as special powers; but from my perspective that feature is an exploitation target that's vulnerable to any unknown bugs, and probably in twitter's case, social exploitation.
I would _much rather_ see all users be equally powerful and find some means by which the services can be designed such that everyone can be comfortable and safe.
Isn't this the objective of Tim Berners-Lee Solid Project and their Personal Online Data storage (PODs) in the spec?
The only way to get some assurance is run vendor app in your environment in a secure network without the ability to phone home.
The point about schemes like this is that instead of having to give 1000 support reps full access, you only give a few sysadmins full access. The likelihood of something going wrong with the data (through mistakes, willful abuse, extortion, whatever) goes drastically down.
In fact, once you got such a permission system in place, it becomes very attractive for the organization to use it. I mean, customers love it, they spontaneously write comments about it on Hacker News.
Even if you begin adopting it only for security theater (i.e. everybody still actually has full access), eventually some principled engineer brings up the idea to maybe remove full access for everybody cause now they have the access-granting system anyway, and this time they'll make a convincing case because the "move fast and break things" people have way fewer practical objections.
Then after that I have to read off my 2FA code. In other words, they have to log in with the same 2FA that I do.
So a random customer service rep couldn't access my account without my phone in their hand, even if they managed to clone my SIM to get past the text message check.
Whats the point of this step
Then, people searching for things like "Microsoft tech support" would get the scammers number and call it. Google and other search engines will even pull that number from your site and handily present it to you at the top of the search results to make it appear even more legit.
Taking over unclaimed Google map listings for businesses is also really common.
Simply buying a toll free number that is close to the customer service number for a large company is bound to get you more inbound callers than you care to scam.
So no, absolutely no excuses for teaching people to share their 2fa codes.
But you would need to educate people with access about the importance of impartial management of user data.
Banks had a culture enforcing neutrality and most importantly discretion. That is not true for modern payment processors like paypal or mastercard though.
You certainly don't want Twitter activists in such a role, regardless of political affiliation.
When I worked at Apple Retail, there was an internal iCloud dashboard you could log into and see _metadata_ about customer accounts. You couldn’t see anything juicy, for Find My iPhone/Friends it was just the name of people would could see your location, not locations themselves. Number of documents, not access to actual documents.
But nothing was visible to you until you verified the customer through security questions, last four digits, etc.
Yes - no names for obvious reasons but where I work (trust me you've heard of them/probably use them and they are a huge tech company) it is very hard to get access to anything even slightly customer related. You need to go through multiple levels of review and approval (often your manager, their manager, and then directors/VPs) with genuine business justifications that actually looked at (no "asdf" here) to get access, and then it is usually only permitted for a window of months at most before it is auto-revoked. Then once you have access, every actual time you look at the data you need to provide justification (e.g. a ticket number that is actually checked to make sure it is open, not reused over and over, and not just 1234567890 etc and so on), and every single action you do with the data is tracked and audited so there is a complete 100% paper trail of who looked at what, when they did it, and why they were doing it, with traceability through to the tickets/bugs/etc for why there were even doing this in the first place. Abnormal things (e.g. systematic/repeated/etc) raises flags that do terrible things to your career. Each system/data source needs its own independent approval process.
There is no "god mode".
It is not uncommon for people to wait weeks for approvals to go through to access their own data to validate a bug fix etc. I think these safeguards are worthwhile - many would see them as a hindrance.
At past places, I implemented a call-centre UI once. We made it so that the service rep would initially not see anything about the customer, so the "Please can you confirm 3rd letter of your memorable word" or whatever meant that the service rep literally had a text box to type that letter in which had to match before they could proceed - they didn't see the whole world on screen and wait to see if the user got it right. I am not sure how common this is - when I do this from the customer side these days often the answer is immediately acknowledged by the rep without any kind of delay or typing noises so I am guessing they have my entire record on their screen and are just waiting for me to say the right things before continuing the call :(
Doesn’t mean there isn’t a way around it for some reps with special access. If you don’t have a PIN someone can go and open up multiple new accounts separate from your primary account in your name with different addresses. AT&T won’t even bother to tell you.
Every month or two I’d fill in the google support text area explaining the problem. No response for ~4 years. Just this Feb, for whatever reason, I decided to call T-Mobile and report it. Problem was fixed by a higher up tech that described the problem as “very strange” and the “first time” he’d seen something like this. It took approx. an hour.
Upon rumination I full accept that I took the “easy way out” by filling in the text box vs trying to talk to someone. End result is that google lost a gvoice customer and no one calls me anymore. meh
I can’t verify this 100% unfortunately but they are notable because of how rare it is
The technological measures have to account for human behaviour. Otherwise you just end up with almost everyone not being able to access almost everything almost all of the time. People are forgetful, irrational, stubborn and stupid. So are institutions. Put them together and you have a social engineering dream world (literally our current world).
It appeared that normally they not really check if it matches, but this time given the transfer amount they did. And it just so happened that the signature they had scanned in their system was the first one I ever made as a kid (30yrs ago) when I opened the account.
Finally after many retries they turned the monitor to show me the expected signature and let me practice it on a piece of paper, so it would pass some other approval stage.
With a 200 yard line waiting behind me, sweating profusely, I finally managed to reproduce something. The sale went through, luckily, and immediately after I ditched that bank account.
Because they showed you the signature and let you practice, right?
I believe most banks allow their customers to change their signature to something they can replicate more consistently — but it probably relies on showing up to a branch and producing sufficient ID.
Helpfully, they provided me with a screenshot of the one they had on file... one copy and paste later and the problem was resolved.
One copy and paste
If you added up all the costs of the people at the lowest extremes (by various metrics), I'd venture to guess that we could increase our prosperity (by various metric) by an order of magnitude.
Example: When I started my startup, we made the decision not to hire any salesperson who wasn't proficient in using a computer (we have no IT support line). We also made the decision to not sell to any customer that couldn't figure out how to use the website (we have no telephone support).
I cannot even tell you how multiplicative the benefits are. The 2% employees who couldn't use a computer or clients who couldn't use the website were responsible for 90% of the issues we had at my prior company. Everything from regulatory complaints, to lawsuits, to ad-hoc report requests, to virus infected PCs, to... the list goes on and on.
Having smart people is great. Not dealing with idiots is equally important.
As your parent said, it's not 2%, it's more like everyone. No one is perfect all the time.
More importantly, it's one thing when hiring, but are you seriously suggesting 2% of the population shouldn't be able to use Twitter or online banking or other online services? 140,000,000 people should effectively face social death because you can't be fucked to help them?
This is backwards, we should be sacrificing profits and convenience to be more inclusive.
...and it's not correct to say that "everyone is imperfect sometimes" because the correlation between people who are problems across various metrics, is high.
I guess one, admittedly brutal, solution is for customers to act like the immune system. Call up, fudge your way through to something that should be protected, and then escalate to a manager and report that you got access to your own account with vague details; they can listen to the call log to verify.
Worst case is that the rep gets fired (which sucks..) but if enough reps get fired then future reps will be hired and trained more diligently.
Yup. Doubly so for sysadmins, many of which have abhorrent data security practices.
My personal solution is to use cover names, disposable phone numbers, and unique email addresses (the + trick is insufficient) for most services. My assumption is that the data is eventually either going to leak, or be used to threaten or harm me in some way.
If none of the PII overlaps with me, it becomes a lot harder for such an event to affect me.
The only downside is that sometimes you get companies (Airbnb, Instacart, some others) that have CSRs that demand a government photo ID to do certain tasks. Of course I don’t have any documents for these cover names, so usually the workaround is to just abandon that account, make another, and re-place the order or transaction in a way that doesn’t flag it for manual review/intervention.
Works pretty well for me most of the time.
From what I have seen, it is common to have additional restrictions on accessing high profile individuals and specific groups data. There is also a ton of auditing around this stuff.
It is more primitive than what you described, but things are heading in that direction. It is a somewhat harder problem space because many parties need access to a customer's records in that domain.
Ultimately, the only reason things are even this far along in health insurance is the regulatory environment. It'd be nice to have stronger privacy laws that compel companies to build good controls.
Banks just don’t give support reps remote access to accounts.
Think about your own life: how often do you lose money because an insider hacked your credit accounts and bank accounts? How often do you get pulled over and your car taken away because someone changed the title/tags in DMV records? How often is your identity stolen by an employee at the IRS?
These bad things all happen to some people, of course, but the VAST majority of the time, they do not.
It is obvious that there are effective countermeasures to prevent and mitigate insider threats. Insider threat is not a new concept, and there are well-proven tactics for addressing it.
Around the same time, at a nearby call center, two employees were caught ordering multiple manager's laptops, which managers can use to access customer records from their home. These laptops were sent out to multiple addresses and never found.
i would bet that most of the places you are thinking about (banks, credit card, and so on) where you get on the phone with a rep, with a phone entry system ahead of the agent, the agent can only access that specific data during the call, the access is logged, and any other access (some other account) is flagged for review. by calling in you are granting access. most users simply don't care about privacy and extra hurdles are just asking for complaints. limiting access to specific accounts during live calls is a fair compromise and a tight control.
xero (they suck, so this is not an endorsement) requires you to give the rep access explicitly, as an option, when requesting tech support. of course i have zero doubt that senior reps can get access anyway (which would be audited), so the explicit control is more about signalling comfort to you about their security measures.
after google had the SRE stalker incident they implemented very tight access controls to user data.
i walked into a verizon store the other day to buy a hotspot. the rep could not get access to any info whatsoever (even billing status) until i acknowledged a message on my phone. it's clear they only had access to my specific data (ie, they don't get to enter any phone number and get access) for that specific interaction.
This is simply not true. For example with banks, high-profile accounts can't be accessed by regular tellers. If someone attempts to, it is logged and someone is notified that Teller X tried to access the account.
Now that Twitter is being used for high-profile official communications, they need to re-design their employee control panels to limit, alert, and control what an employee can do with an account.
The fact that important credentials on so many high-profile verified accounts could be changed without notifying employees or locking the affected accounts until the actions are verified is unacceptable.
E-government services in Estonia have nice features, aimed at giving more control to the owner of the data [1]. Among other: "It allows the Citizen to query who has accessed his/her records. [...] In Estonia, this feature has led to some very public cases of government officials being caught accessing private data of Citizens - without any legitimate and authorized reason for such access."
> we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take over accounts; not sure on the specifics here at the moment
https://twitter.com/jason_koebler/status/1283594885292077056
That being said, what was the employee's endgame here?
General disgruntlement maybe? Maybe they were simply pissed off and looking for a way to hurt the company.
Sometimes people behave very irrationally. In the most sensational cases that manifests as violence, but I think it might also manifest as acts of sabotage.
Especially if the real motivation is not the BTC scam, but the access to who knows how many DMs for possibly blackmail/propaganda down the line. (And not necessarily just DMs from the known compromised accounts, either.)
Without this bit of information from Vice it would make what Twitter officially posted downright scary and not add any comfort factor to what the heck is really going on.
People seem to assume everyone takes tweets at face value and won't do a double take when it doesn't sound like something they would normally say.
Even here there was plenty of people on HN who were claiming outlandish possibilities while it was happening.
Poorly executed, frankly. The tweet just wreaked of spam.
e.g., Vietnam is a livable place and GDP per capita is ~$2600. That'd get you a very modest living. GDP/capita is also up 2x from 10 years ago and 10x from 20 years ago. You could maybe squeak out 20 years with very modest living and few unplanned expenses and assuming the economy and thus cost of living doesn't grow tremendously (like it likely will).
Somalia would give you a little more value for your money. But I think if someone suddenly had that much money in Somalia, they'd probably be getting out of Somalia or hoping nobody found out.
Almost anything else I can think of would require either (a) substansal amount of starting cash (for example trying to crash Tesla's stock price), or (b) be almost impossible to pull off without getting caught (blackmail, or again stock manipulation if you do it in a big enough way to make some decent money).
In terms of risk/reward, assuming someone found some easy trick and wanted to cash out ASAP, this feels like the best option.
Alternatively, is it possible they bought options on twitter itself? It’s down 4% in after-hours (which is less than I expected, but still enough delta to make some cash).
It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts.
It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid.
Of course, could also be something more serious - but if it's really just the BTC piece and the people are dumb enough to talk to the press, it may not be a group of criminal masterminds.
I hope for the employee's sake they have communication that can help the feds catch the BTC group. Either way, an incredibly stupid thing to do on their part and I don't see a good ending for them.
If this turns out to be true, they'd be lucky not to go to prison.
If you're a sysadmin on a company email system, then you do technically have access to everyone's data on that system.
However, you're generally limited by company policy that you are not permitted to access/modify that data without direct authorisation, say from the employee themselves or from HR.
So, therefore, if you go and read the email of your boss, you're still in breach because you didn't have the authorisation.
The only item I can see here is fraud (impersonating the people whose accounts have been taken over), of which the mole would be complicit.
That's been exceptionally controversial, as it can turn contract breach into a federal criminal offence in the US.
Doesn't something similar happen with employer-provided accommodation and burglary laws?
People's accounts get hacked all the time. To help them recover is often a manual process, because the true owner of the account can become unclear. To be able to do that a support worker must be able to change the email address on an account, undo 2FA settings and make other changes because hackers will typically change the email address and add 2FA of their own phone as the first step in an account takeover.
Twitter is a disaster waiting to happen.
I can't think of any serious risk posed by 'the general population'. Maybe particular stocks would dip a bit?
I’m not sure what you’d charge them with?
I know HN doesn't believe in laws, but the rest of the world does, and they're the ones with prosecutors.
They could argue, with the advent of remote working getting more and more predominant, that they simply left their computer unattended for a second while logged in.
Beyond that, they could argue they simply clicked on a link and something might have happened they aren't aware of. Or that they didn't know what running that one executable would do.
Parting shot: unnecessary, obnoxious. -1
Net: 0
On the other hand, $1M in BTC might do the trick. Interesting thought experiment...
And/or they just thought it couldn't be traced back to them.
And you're also making the assumption that the accomplice thought about it rationally. All the attacker has to do is find someone who doesn't realize that they will get caught.
If that was the case they could only deal with bitcoin. Blackmailing with bitcoin may be smarter but maybe they figured that would be investigated more or treated more harshly? They could have released fake financial tweets and shorted the market - but that still would be investigated much faster.
I'm sure the 100k or whatever they got isn't as much as it could be - but for a random dude who paid 10k to a disgruntled employee it is pretty good.
I don't think there is something super nefarious involved. Probably some unpaid intern in a third world country where Twitter outsources tech support.
If the attackers had a big short position in TWTR, they may have made a lot more money than they received from BTC.
Also, if you had Elon tweet that, I am not sure if the price will go up or down like you expect. :)
Oddly enough, posting the screenshots resulted in some users getting their account suspended or Twitter pulling the picture down.
[0]: https://video-images.vice.com/test-uploads/_uncategorized/15...
Apparently sworn statements have been made about this.
[0]: https://blog.twitter.com/en_us/topics/company/2018/Setting-t...
Also what do people consider as a shadow ban?
- Removing the tweets from people’s feeds, and only showing them if you browse/go to the offending users profile ? (Personally I don’t think this counts as a shadow ban)
- The offending user is the only person who can see their tweets, even if other users look at their profile (This is shadow banning imo)
This doesn't seem to contradict what's shown in the screenshot (which only shows blocking from the search and trends page).
Some of the scuttlebutt says that these guys are tied to multiple crypto hacks.
But my personal opinion is that this is just a 20-something trying to make a mark for themselves. We'll see within a week or two.
Such social media platforms have to be tamper proof even from the CTO, the reddit incident proved that years ago.
This is going to hurt their credibility hard in the run up to the election.
The tool in question is likely used by low level support/abuse control workers. The huge pressure put on social media firms by liberals in recent years to crack down on "abuse", "hate" etc means they need a vast army of people to review complaints about harassment, "fake news", account hijacking etc. Those employees aren't all sitting in expensive San Francisco on a corp VPN, are they? They're probably going to be in places like India.
From the mention of BeyondCorp, it feels like there are a lot of Googlers in this thread who aren't really familiar with how Google handled the same problem, or at least, used to. For example back when Orkut was big there were huge numbers of people in Brazil who had the power to censor content, ban users, handle victims of phishing and so on. It was the only way to scale the moderation users and governments there demanded.
An ideal user admin tool is very fine grained. But once account hijacking entered the picture, it gets hard to truly restrict takeover permissions to a tiny number of people, because accounts are constantly being taken over by third parties and need to be reset back to the true owner via manual intervention. Attempts to automatically handle that are very hard, I know from experience. Hackers like to abuse any system put in place to stop them taking over accounts (like 2FA) to stop the true owner taking it back once captured.
It is so important to critically examine and limit the blast radius of administrative actions. This is both from a vulnerability perspective as well as honest human mistakes.
For certain actions like taking over an account and impersonation there should be rate limits all around. Overriding them requires a break glass process where multiple people may have to approve (or even just acknowledge that it is happening).
Social engineering happens. It can happen to the best of us who hold the keys to the kingdom. The goal is that no one individual can completely break all the barriers. They need a bit of help, time, or both.
It would have been fascinating to see which which account had the best conversion rate.
I know one person who actually sent money to Elon – "it seemed like something he'd do". Seems likely Elon's followers have the highest rate of people who understand crypto, combined with the fact that he's more likely to do something like this than, say, Joe Biden.
Even worse, I'd say his followers probably have enough understanding of crypto to be able to send him money, but not enough understanding or skepticism to realize it's a scam.
Because the audience needs to know how to quickly send BTC.
In addition, it's a running joke on Elon Musk's feed anyway where people constantly to do this using fake accounts of his.
So, maybe some thought today Musk is having it and finally doing it for real! If there is a person to run such a campaign for real, it would be him - so it could even be plausible.
Yep, I agree with this.While mine guess was purely on "amount of money available to give", your speculation seems more on point.
How does twitter allow this spam?
I also hope these incidents remind people of how little control you really have over your online identity. We're all just IDs in a database somewhere, waiting to be impersonated. Decentralization is the only solution for this IMO.
The reason why this attack worked is primarily because of a recovery system. I agree this is a significant vector, but I can't see how decentralized solves this?
At the moment with blockchain wallets, once you've lost your private key, you're screwed. There is no recovery.
So, I'm all for decentralized but if it is truly my identity, I need a way back if I lose it. Not sure how to solve that vector even in a decentralized case.
Do I need to upload my identity to specific 'verifiers'?
I read @elonmusk because I trust it's him and I'm interested in what he says. Personally, I genuinely like Starship + Starlink updates... I ignore most the other stuff. But still, I want to see those awesome rocket tweets!
So, I want to know what he says.
He can change his username because it got hacked/whatever... but then I personally have to see what he changed it to... how do I know that he is the one who changed it? how do i know it's not some rando dude impersonating him?
You could trust it was Elon because it's published on his own website instead of on the worst thing to happen to human communication since writing was invented (I.e., Twitter)
For other cases we can evaluate merit based on previous performance and character of published material instead of "identity". I do not care who is behind a pseudonymous blog if the blog is good.
Obviously you can scale up your security according to the value of your account and your threat model.
We need to keep the conversation in recovery because eventually it'll happen. Your 5/9 people could have n+1 unwilling parties where n is the losable amount.
It is unrealistic to say it will _never_ happen.
When my identity is lost... is it lost for good? how do i recover?
If it's lost for good, and i make a new 'identity' then what is my 'identity'... is it just... my reddit username?
Give enough people using the system, it's not if, it's when. So how do I recover?
I don't think there is any solution to this. "Decentralization" in this context seems equivalent to a centralized system that simply gives up on any ability to recover accounts. Whoever owns the authentication details of an account is the owner, period. If you lose the password or the account gets hacked and stolen from you, tough shit. Start a new account.
I think the real solution is that social media should simply be valued lower. No one should care if their Twitter account gets hacked. The fact that politicians and important people use it in an official capacity is the problem that needs fixing.
I don't disagree, but with what?
It's easy to say this is 'wrong/broken', but I don't see a great fix other than people 'rolling their own solution' and that's not realistic.
Post it on congress.gov using some inefficient boring process or whatever the official communication method of your role is.
As far as I’m aware they didn’t even make him create a new one and he thought everything was totally fine.
It was the moment where I realized I want nothing to do with IT Management/Security in the future and am actively working to distance myself from that aspect.
https://twitter.com/TwitterSupport/status/128359184496275046...
I’m guessing someone re-used a hacked password and SMS 2FA is to blame. Maybe it’s not even that sophisticated.
I'd like to think it's a bit harder to intercept a former President's text messages.
SMS is fine for end user access but companies can do better, even RSA/Google authenticator are a lot better option than SMS
SMS is seen as less safe because the transport layer is not encrypted. But there isn't much difference in the practical security of the average user.
Lack of encryption is only part of the problem. Lack of proper authentication is more important. Mobile networks are vulnerable to SS7 redirects, SIM-Jacking and plain old social engineering.
The 2FA reset function is also a part of doing 2FA properly. Your reset needs to be at least as secure as the regular 2FA flow. Meaning that "just phoning support" isn't an option. Yes, resets will be cumbersome and might involve stuff like physical presence, showing a government ID and maybe being vouched for by a third party. Most companies fail badly at this.
Edit to the topic: As I said, the transport layer of SMS isn't safe, but I don't think it has practical merit. How often were SMS redirected or spied upon? In high profile cases? Even that would be difficult to determine, but the occurrence is probably very low.
And for a twitter account? Seriously? Depends on the account but assessment of threats is the first step of an honest security review. My reddit pwd has been 'reddit' for years. That wouldn't fly if I were Madonna and if I had any attachment to it.
>"We used a rep that literally done all the work for us," one of the sources told Motherboard. The second source added they paid the Twitter insider. …
If you're doing something shady to your employer, it seems to me that it would feel a lot safer to do so while working from your home office by yourself then when sitting right in the middle of an office pod with other coworkers.
If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisticated attack on multiple employees via social engineering, I have to think the attackers thought about it. And if they thought about it, they weren't just after 150k of BTC.
1- (Tinfoil hats please) This is a state owned attack, which is a retaliation from US Government to ruin Twitter's credibility and introduce social media regulations.
2- The hackers are gray hat hackers, who know that reporting this vulnerability will not make them any money and they want to get what they think they deserve, so they make it public and get some good amount of cash.
3- The hackers had realized they had a massive vulnerability in their hands by accident and did not know what to do with it.
I find second and third option plausible, which also reminds me of the npm hack, where a very, very popular library was compromised and installed on a huge amount of developer machines, but only thing they did was to try to get hold of some bitcoin accounts.
I do not condone any type of crime but in both cases, it feels like a huge opportunity was missed by both hackers.
the obvious qui bono is not twitter. and twitters biggest opponent at the moment is?
the pound of salt for that is just that once clandestine motives are introduced theres no bottom to the subversion one would introduce to make attribution difficult.
Just the massive blast radius of the hack reminded me of the NK Sony hack and release of documents. Big up yours to Hollywood from Kim Jong.
The "massive blast radius" of this hack lies more in the damage it could have done, rather than the damage it actually did. This amateur execution makes me think it was some small-time cyber criminal who happened to have the bright idea of bribing a Twitter employee, but didn't have the know-how/creativity/patience to reap its full benefits.
Remember when Twitter fact checked those Trump tweets?
Trump is the type of petty person to not let something like this go.
Can't it just be that they're not that knowledgeable about stuff outside their domain? The things you mentioned require knowledge of stocks and politics. If I, personally, woke up tomorrow with access to a Twitter backdoor and the desire to exploit it, I wouldn't know how to do any of those things, because I also don't know anything about stocks or politics.
Example: Contact Trump's kids. Demonstrate your power. Tell them you'll make Joe Biden tweet "8 year old girl nude hair" at a time of their choosing, in exchange for 5 million BTC held in escrow. This doesn't require anything more than knowing that Trump is rich and corrupt and that Biden is his opponent.
A variation of this is that you demonstrate the power to rich public figures and tell them that unless they pay you X, you'll do it to them to make them look bad. Then you don't even need to use your exploit.
I think this was probably worth tens of millions, and they blew it on 100k.
And then you get tracked down and killed by a three-letter agency. I think people underestimate how risk-free receiving small amounts of btc from random schmucks is, and how risk-averse these hackers may be.
I agree with this
> and how risk-averse these hackers may be.
And I agree with this statement in most cases, but not in this particular one. The wide spread and super high profile nature of this attack makes it a high risk play no matter what. Being cautious when it comes time to collecting the loot seems like too little too late for them to get away easily.
Also, if you search for the source for one of the images (mentioned in the article), you can find this tweet: https://twitter.com/UnderTheBreach/status/128349929454113177... which says the recent hacks were done through that tool.
Tweeting on behalf of another user seems like an unnecessary feature to give admins.
My experience with internal tooling in general suggests otherwise.
But I'm surprised it's still a thing.
If you mean "log onto the machine and change the config" then it isn't really an air gap anymore. Usually it's a group of VMs, you change the image master (via Chef, docker etc) and boot a new instance. Ideally it's architected so most admin tasks go through an API, with auth, access control, logging, change control, etc. If you have a standardised message bus for your API you can used a Trusted Guard, aka CDS, which is a carefully designed (for high assurance, formally verified) protocol inspector designed to only allow correct protocol messages to transit. If the guard and it's ruleset pass independent analysis it is considered airgap equivalent under govt rules.
They support a total of 1 (one) U2F token on an account :( The only other company I know that does that is AWS and one U2F token. Every other site I use allows multiples, usually at least 5 or more.
I setup U2F on Twitter but then got rid of it after realizing they only allow one.
It makes sense technically to have a single token anyway. Otherwise you either need to include then identifier of the auth token (in addition to the secret) or have the verification step try out all N options.
I'm not sure if that is true. Most sites support multiple tokens. Off the top of my head I can think of Google, Facebook, Github, Gitlab, and more that support multiple. So it seems like the normal method is to support multiple.
One one site I have over 5 auth tokens configured. And tested with four of them connected to my PC at the same time. I could tap on any one of them to authenticate. This is on a Windows 10 PC.
as you've described: the U2F functionality is completely useless because if you lose/break your single U2F key then you're completely screwed
and they still have no support for ed25519 keys (which were added to OpenSSH in 2013), unlike every other cloud service
I have to have an RSA key just for AWS (particuraly annoying as I have all my other ssh keys stored in a hardware token)
if they didn't validate the damn key type then it would probably just work out of the box
That thought makes it so much for frustrating. ed25519 is the future anyway, it’s hilarious how many cling to RSA (I’ve got nothing against RSA but at some point we’ll have to switch anyway)
> if they didn't validate the damn key type then it would probably just work out of the box
Yep. So incredibly frustrating.
Although I could be wrong if the reports are wrong too.
Perhaps a higher tier of user support personnel handles verified accounts (or accounts somehow flagged for extra review in a non-public fashion), but I'd still be surprised if anyone particularly high-level is doing the grunt work of using this tool.
I imagine a support person does more than in an average day.
And while we might have seen all the tweets at the same time, they might have been changing emails and passwords over few hours.
Remember twitter has so many users they probably get tens of thousands support requests per day.
Even if you have monitoring, I don't think volume was enough to pick it up.
“ Once we became aware of the incident, we immediately locked down the affected accounts and removed Tweets posted by the attackers.”
The accounts were posting for hours after it seemed Twitter became aware what was going on.
Oddly, it was just Elon Musk's account that had multiple tweets over a long period of time. The other accounts did just one.
All assumptions on my behalf bit it explains your question.
https://www.washingtonexaminer.com/business/jack-dorseys-per...
Does confirm past claims that they shadowban accounts (which does hide them from search, among other things) at the very least, even if the exact criteria are unknown.
My problem with it is how it's not acknowledged.
This is admin UI given to operations staff , far more trivial to have writes protected ,I cannot imagine anyone need to write to customer data that often in this kind of app.
To prevent this kind of mess, Twitter should add more restrictions do disable 2FA on an account (multiple admin authorizations, email notification, add delay before the action is performed) and also change the account state to unverified and add to the feed a "email changed" or "identity changed" status. I also think that changing the email should not be immediate and that the old email should be notified of the change.
This must be some new meaning of the word 'immediately' that I wasn't previously aware of. It took them quite a while to get these accounts locked.
There's no reason that certificate can't be used directly for the HTTPS connection to the admin UI, providing the same security benefits without actually requiring a VPN.
Furthermore depending on how "deep" the social engineering attack goes, a local user with administrator privileges can typically export those certificates unless they are stored on a hardware module (either a smartcard or an internal TPM/secure element).
I'm thinking specifically of direct messages that could have been scooped up before they went public and started tweeting on these accounts.
They most certainly don't. I have no idea why that fact is not obvious to some.
Trump had two liked tweets for all of time back from like, 2012. Around 2017 or so a group realized this and bought or otherwise messed with the site the liked tweets linked to and made them have pictures making jokes about trump. It took more than a year for anybody to give a shit enough to take down. They don't use the site for anything more than direct statements/retweets.
But Elon? Some of these bitcoin exchanges? Maybe. How about accounts that were accessed (if any) that never blasted out the bitcoin tweet, but had their messages harvested?
Also, I really hope there’s a set of users whose accounts cannot have new devices connected without special authorization, and if so, you’d have Biden, Obama and Trump on that list.
Edit: 5 minutes after posting, I saw Obama and Biden were on the list of people hit, and I missed it in the early reports. Unbelievable.
With a highly public hack like this one can simply manufacture messages afterwards and claim they came from the hack. Most people would believe it.
A potential whistleblower , somebody having dirt on opposition .
It could be worse , even if you didn’t respond the fact that someone let’s say a foreign government or a spy or terrorist reached out to you can played in media they way your opponents want it
This kind of compromised messaging is not unknown while being attacked , when browserstack got hacked few years back, the attackers send official email to all customers whose emails they got in the leak saying the company was shutting down.
Because Jack Dorsey is a real human and a powerful real human and he hasn't done that, we don't have to envision the cyberpunk PURDAH identity scenario for proof from him and we don't have to think this is a secondary Moab run. At least now that it's been up for a few minutes.
For example try this with JS disabled vs enabled (404): https://mobile.twitter.com/JoeBiden/status/12835123178466590...
curl -fSsL https://mobile.twitter.com/JoeBiden/status/1283512317846659073 | grep -i bitcoincurl 'https://mobile.twitter.com/JoeBiden/status/12835123178466590... -H 'cookie: m5=off;'
FFS Twitter, get your act together.
had that feeling... wonder how much more vulnerable working from home is making us to such things.
also scary that targeted employees with such level of access fell for it. must have been really sophisticated.
Sure, the hackers here have committed a crime, but this was more of an embarrassment for Twitter than anything else. If they had posted from Trump's account though...
It's kind of bizarre when you have the highest levels of government doing their critical communication on a free social media service to the point where they are critically dependent on it, then begging for support when things go wrong.
Maybe you shouldn't use a free service that is not under your control or any proper regulatory or quality constraints for your most important messaging to the public then?
"Maybe government should embrace popular communication media instead of spending billions on custom IT infrastructure to post a message on a custom page that everyone screenshots and copies to their timeline anyway."
(Also if they don't create an "official account", someone else will do it for them)
What do you mean? How would anyone not affiliated with a given government agency convince human verifiers at Twitter that they're official?
If you don't snatch up your (organization's) name first, someone will surely do so for you.
(Honestly not trying to incite anything by using him as an example; I just hardly use Twitter and he was the first to come to mind.)
Yes, but this account will still not have the same legitimacy. Right now, if Trump tweeted a declaration of war, it would have been reasonable to assume that it was real, because, for all we know, it's an official channel. Previously at lot of people would've at least checked back with the official channel before taking it for granted.
And, to make matters worse, having Twitter as an official channel now gives everyone at Twitter the possibility to make official announcements - hardly a good state of affairs.
The government could put it's decisions and publications on a website, official, verified, more or less controlled by them. There's no reason that has to be done with consultant scams - oppositely, posting on Twitter doesn't guarantee consultants aren't raking in money for adding or removing periods or whatever.
But I guess its easier to just complain about Twitter.
But we hate it when governments spend money on things. And no one would trust a word that came from any service the government controlled or regulated.
And on top of all of that, people will still complain that their tax dollars are being used rather than existing public platforms (Twitter, Facebook, etc.) Whichever administration puts it up, the next administration of the opposing party will call it waste and propaganda and burn it down.
> Maybe you shouldn't use a free service that is not under your control or any proper regulatory or quality constraints for your most important messaging to the public then?
What are you referring to exactly? I thought the govt had their own IT and websites across the board, and only used things like twitter to aid in communicating to the public.
No, I think they should use best-in-class media and Twitter is exemplary for that. Twitter is only dangerous for this because it is very effective at being a communication medium.
Yeah no one is going to fall for the 5th ColdFusion site with an admin backend left open on sqolkla7.info.gov.us/press-releases but that's because no one is reading that site.
I wonder if this attack was facilitated by some security measures being relaxed to allow work from home.
At least the GP comment contained actual information, however little.
Had to go through DuckDuckGo to find his handle.
I was surprised because I searched for users with the name "Scott Adams" and it was promoting users with 0 followers and not showing his verified account at all. This was through Tweetbot iOS.
This leak seems to be legit.
Curious as to what types of changes might come out of this going forward
Also, the ability to impersonate people (not just celebrities) should require at least manual approvals. Not sure why this ability even exists.
The original speculation (that it was an API vulnerability) is actually easier to stomach.
1: https://www.washingtonexaminer.com/business/jack-dorseys-per...
EDIT: thanks for the downvotes, twitter.
It's against the site guidelines to do that, so please resist.
I wonder the size of the population of employees that have access to these internal tools. How many people can independently fire off a Tweet from Jeff Bezos or Elon Musk and erase billions from the stock market? How many people can seize the account of Joe Biden (or presumably Donald Trump) and cause a huge international incident?