Who’s behind Wednesday’s epic Twitter hack?
krebsonsecurity.com
krebsonsecurity.com
Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value:
Archive: http://archive.is/8lCMV
https://www.washingtonpost.com/news/worldviews/wp/2013/04/23...
This twitter hack could have literally destroyed economies, started a war, potential for black mailing politicians and others etc.
This really needs to be looked at with much bigger eyes. This wasn't just a bitcoin scam.
>"The supposed panic was so tiny as to be practically immeasurable on the night of the broadcast. ... Radio had siphoned off advertising revenue from print during the Depression, badly damaging the newspaper industry. So the papers seized the opportunity presented by Welles’ program to discredit radio as a source of news. The newspaper industry sensationalized the panic to prove to advertisers, and regulators, that radio management was irresponsible and not to be trusted."
and
"Welles later embraced the story as part of his personal myth. "Houses were emptying, churches were filling up; from Nashville to Minneapolis there was wailing in the streets and the rending of garments," he told Peter Bogdanovich years later."
"CBS, too, found reports ultimately useful in promoting the strength of its influence. radio management was irresponsible and not to be trusted."
It's perfectly feasible for every trusted source of knowledge to run a web server, and they actually do it, so it's sad that consumers don't connect directly to those servers and instead use middlemen.
Yes, except the FCC can forcefully suspend the operations of a radio station.
We've entered a world where the lowest common denominator of information is being used as primary source for current events. That's asinine.
This is largely through their own actions. Examples are legion, but a recent one is debacle at NYT over an op-ed. The news-consuming public was able to view the shenanigans of NYT reporters and staffers, which would formerly been done being the scenes.
Many eyes were opened, and I'm certain I wasn't the only one thinking "These are the people in supposed to be trusting for my news and analysis?"
Is it though? According to Pew, only 20% of US adults use Twitter: https://www.pewresearch.org/fact-tank/2019/04/10/share-of-u-...
In comparison, Fox news is used as a source by 40% of the US population: https://www.pewresearch.org/fact-tank/2020/04/08/five-facts-...
The share is bigger for Facebook, though (69%)
But the world we live in is full of "web services that let people post whatever they want at any time". News from Twitter may be weird but many people want to get their news from the BBC website, or the New York Times, or Reuters or whatever. Or their own government's websites. Just web services that people post from - presumably with levels of editing and checking but all presumably with security flaws that could bypass them.
It's not clear exactly what you're asking for. A technological solution involving careful checking of cryptographic signatures? Or some sort of super-expensive-to-spoof source of all important news?
But it is fair to say that there is no sane channel of information. The channels of public discourse in the US, once controlled by a few "loyal, patriotic" corporate owners fed by advertising revenue, are now channels controlled by unprincipled corporatism that supports a two-party system of untalented puppets.
And the un-talent pool is bigger than ever.
Not.
Company X presents the public with communications of known public figure. Company X assures the public, via a blue checkmark, that said communications are from a "verified" account.
Shouldn't company X be liable if someone other than the known figure is making public statements?
It seems logical, fair, and a societal 'good thing', that company X should either let go of the pretense of "verified" communications, or get its act together, or pay the legal price.
The platform derives power from the audience. Stop giving it your power.
As for the blackmail and war starting you probably couldn't do much with public tweets (nobody is going to go to war over a tweet without fact checking it) but access to private messages is an entirely different story.
Equity destruction: sure. War: no way.
Wars start from smaller conflicts, which come about through escalation of smaller conflicts, lies, or misunderstandings. I think all that is necessary to start a war is a geopolitical event of sufficient severity to provoke a retaliation; once the first retaliation happens, there is high risk of further escalation.
So the question is whether a deception on Twitter could trigger a real-world event significant enough to provoke a retaliation. It might be hard to do that with a single message, but they had access to multiple accounts. These tweets were stupidly obvious scams. You could create a huge amount of panic with a series of posts from different influential accounts if they were designed to be believable.
> War seems very possible.
No. While there may be a "last straw" event that precipitates the war, it take a lot of build up to lead to it.A salty remark on twitter that is rapidly taken-back?? I don't think so.
Let’s not speculate war here. We’re on HN:)
Tweets were about bitcoin, therefore broad public was not the target of the attack.
Hence Twitter just prevented verified accounts from posting and deleted some messages. Had president's account been hijacked and threats of imminent nuclear strike etc. were thrown around, DoD would have been quick to contact to Twitter and they would have been disabled the whole account, put notifications about hijack for everyone to see (like these COVID notifications) or maybe even take the whole platform offline until they fix it.
You would click a link to go to the said tweet, but you'd only see president's account is not there, and there's a huge warning saying it has been hijacked, and devs are working to get it back. That's it.
Now please try to convince me otherwise, I'd love to be challenged on this.
No. Bitcoin was used because it's the only way to get money without being tracked (hence why drug dealers and even hitmen use it).
The rest of your argument is all speculation. Nobody knows what would've happened, so you can't convince anyone you're right, just like no one can convince you you're wrong.
I will just say that with the current distrust of Russia/China and in recent years, the US becoming an "unreliable" ally for Europe, a few tweets from a President and perhaps some other senior members of Government could easily have started a disastrous series of events (if unlikely to cause war directly).
This hack had been going on for over two hours, with new high-stakes accounts being steadily taken over (and possibly have their DMs siphoned) and their only action was to disable posting for verified accounts. I think we can safely say that IF Twitter had the possibility to effectively pull the plug, we would've seen that on Wednesday.
Get Trump's account, and tweet something like, "I've ordered a NUCLEAR STRIKE on China! The missiles are already in the air. The DEEP STATE is trying to take me out. They will try to silence me and delete these tweets and use deep fakes to say this was a hoax! The storm is here, Q is real, it's time to take up arms and kill democrats."
Then continue tweeting escalating things over the next half hour (since apparently the hackers couldn't be stopped for a while).
Even after dozens of high profile accounts were hacked many were still commenting that they didn't think it was possible for it to be a twitter vulnerability, but rather individual accounts being compromised or a 3rd party. If you only tweeted plausible things about war and corroborated it from multiple accounts at the same time you can reinforce things pretty easily.
Twenty years later, a substantial part of American society is still insisting Moab really was nuked, drives around with "Remember Moab" bumper stickers, and considers the purported continued existence of Moab to be something like a Deep State plot.
> My fellow Americans, I'm pleased to tell you today that I've signed legislation that will outlaw Russia forever. We begin bombing in five minutes.
Only few people have Twitter accounts, it's a walled garden. Almost nobody cares what people shout in 140 chars, and likewise nobody cares about people streaming video on Twitch or YouTube in 20 min, what could be written publicly and read in 10 seconds.
In the meanwhile Trump would appear after some minutes on TV, youtube, and whatever other channel they have around, proofing that he is not sending the tweets, while twitter would do their stuff.
>Get Trump's account...
At this point he's said so many batshit crazy things, I think people are over it.Tweets from Stable Genius are now just grist for a media-industrial complex of outrage.
I dont even have a twitter, facebook, instagram, or... anything i think. just you people : )
This is ridiculous, there is ample room for criticism against Trump. This wouldn't fit at all. I guess you can blame him on Turkeys reaction in Syria, his staunch anti-Iranian policies that made talks more difficult. But the criticism of him starting random wars comes from an emotional corner beyond reality in my opinion.
Could a Trump tweet (real or fake) cause a pivotal escalation in a series or escalations leading to war? I think probably yes.
May be different for internal politics. Since people are often irrational.
Thankfully, his account is under special 'lock and key' protection, so a regular CS rep can't hijack it.
And, with conspiracy theorists, imagine the consequences of Trump's account tweeting a distress message that he was attacked and replaced by a clone controlled by QAnon.
I'm happy whoever did this wanted money.
Seems to me having them there is about 99% downside, 1% upside.
Disclosure: I dislike Twitter on principle.
> This twitter hack could have literally destroyed economies, started a war [...etc.]
Woah, slow your roll man, it takes a lot to start a war. And temporary glitches in the market are just that-- temporary glitches. If someone loses their shirt over that they deserve it.It's not hackers which are the true danger, "legit" people abusing media (whatever it may be) are the threat, a good example would be the Stable Genius.
1. https://www.history.com/news/6-wars-fought-for-ridiculous-re...
We are very far from a stray remark triggering a war unless either/both sides are already heavily primed and itching for one in the first place.
To be clear, that value wasn’t erased. The market makers just lowered their willing bid during the uncertainty.
Something like this right before the election or after could wreak havoc if targeted to the right accounts. I imagine certain state sponsors would pay handsomely for that.
I think there is a big organisational difference between the AP and Twitter, but that's just me. Twitter does not employ journalists. Twitter is not the press.
At least when Twitter is secure, you see the exact words that were typed, and not through the filter of a reporter who may have misread.
I've personally been misquoted in media interviews. Not a major thing, but I could now use that newspaper article to claim I've done more than I really have, because hey, the newspapers said I did! It must be true!
(I didn't downvote you though, I think the downvotes are unfair.)
No they don't.
https://www.whitehouse.gov/presidential-actions/presidents-e...
The hack would have been a powerful weapon if used in a more strategic way. A "shot across the bow" as a tactic is useless when the weapon can only be used a single time and never again. The code will be patched now.
>Also, the crystal clear implication that the damage done could have been far worse, would seem to indicate someone was sending a message.
That's hindsight knowledge. To me it looks more like an un-sophisticated actor that stumbled over a critical vulnerability and had to use it haphazardly before it somehow becomes obsolete with code update.
>From whom and to whom can only be the subject of speculation, but again, whoever did this must have known that the it would be interpreted as an attack from China to the USA. So either they didn't care because making that obvious was the whole point (ergo, attacker probably China), or the misdirection was the whole point (ergo, attacker probably a power that would stand to benefit from increased tension between USA and China).
Actually I don't see much speculation that China is behind the hack other than from the people who are quick to blame China anyway. The sloppy execution actually speaks against a nation-state actor. The loss of trust in Twitter only plays into Trump's hand regarding his personal feud with the platform.
> Also, it seems clear that this Twitter hack could have let the attackers view the direct messages of anyone on Twitter, information that is difficult to put a price on but which nevertheless would be of great interest to a variety of parties, from nation states to corporate spies and blackmailers.
My understanding is the hackers used the admin panel to change the email addresses of the accounts, which means they could reset passwords and perform full account takeover [what about 2fa?]. That means they could login as the user, and so it means they could read the user's direct messages. (Ironically, Twitter's solution of disabling posts from blue checkmarks would not have stopped exfiltration of direct messages while an account was compromised.)
It is not as much money as pundits probably think it is worth. And also, trying to negotiate a blackmail is time consuming and opens the risk of being caught especially if it a high profile target, with no guarantee of being paid. Do you really think someone like elon musk will pay a bitcoin ransom assuming there is anything incriminating? Paying off a blackmailer is an admission of guilt and does no good if the info is released anyway.
It also depends on how sophisticated the thief was. Did he have everything automated to dump anything everything from the inboxes while automating the posting of the spam tweets, or was he frantically doing all his postings by hand before twitter could shut it down. If the thief is not sophisticated his main priority would probably be making as much money as possible with the posts and ignore the private messages
A somewhat odd blog post by Jeff Bezos about blackmail from last year is quite interesting in this context. [1]
[1] https://medium.com/@jeffreypbezos/no-thank-you-mr-pecker-146...
Maybe? I mean I certainly don't dismiss the idea out of hand. The one strong counter-argument I can think of is that very few things would actually embarrass Musk at this point.
They used different approaches on different twitter accounts, some suggested a coin return, others suggested a charitable donation match, etc. But, they all used the same bitcoin address. If they were sophisticated, they would have used a different bitcoin address for each to evaluate the more profitable messages for a future scam.
Sure helps keep down on the public effect though... feels mostly like a PR move.
I've worked for multiple fully-remote companies that were easily able to protect tools like this from the outside world.
The company I currently work for (fully remote) has tons of internal services that our engineers (who we trust) can access as needed in order to debug problems and help our clients. None of it is accessible from the Internet.
This hack probably underscores the importance of zero trust. Although if the system is compromised from within (like this hack is) then there is not much you can do.
If you have the means, certainly use a corporate/smb/personal vpn. It is one layer in a multitude of layers you should be using to protect your network.
Its not as if once you achieve vpn access you have no other authz gates to internal applications. Its a "great filter" to help narrow the possible avenues of attack and it works. If your inner layer of authz fails its not the vpn's fault.
Whats your alternative? Just make every application and network endpoint publicly accessibly on the internet?
VPN and IP restrictions in general is a very good tool to limit the attack surface. That does not mean that Karen from accounting should be able to log into the production environment servers.
How do you jump from "VPN is not authorization" to "VPN is an anti-patern"? It's at a completely different layer than authorization ffs! You don't give up on seat-belts because they don't stop bullets coming through the windshield.
"Defense in depth" is not an anti-pattern. Using an VPN as the only layer is, certainly, but that is a straw man.
> If the account with VPN access is compromised, then the attacker has full access to these sensitive systems.
No. Logging in the VPN is one thing, logging into the internal systems requires an extra login
This is not hard
I could be wrong, but I think they mean that access to the internal site should have been behind VPN (whether at the IP network level or via an HTTP proxy) even when accessed over the internal network. That is, the internal network should not be trusted any more than the network at the cafe down the street.
By whom? It's another layer of security, nobody claimed it should be the sole defense.
It's a part of security, along with other multi-faceted authentication routes.
Additionally, TLS1.3 is better than most VPNs from a cryptographic standpoint.
Now, we see the potential of social media to be a tool for coordinated attacks against the western world. Just imagine this attack during the protests last month in the same narrative that started civil wars in other parts of the world. When tens of people start shooting and killing eachother, nobody would discuss what triggered the chain of events.
This is a simple test that reveals how fragile is society in contrast to how much attention they pay to Twitter. The worst, the value we get from social media is also unclear. Low quality, unreliable bits of information turned millions to pigeons jumping from there to there and those who own the seeds can control the mass.
It exacerbated it first in the middle east, maybe because those societies were close to conflict to start with, but the western world doesn't seem that far behind.
Added to which he has somebody in the comments essentially calling for the death penalty over this. If he has this personal information and evidence, pass it to the relevant authorities and don’t sensationalise it on a blog. Technical details fine, but people’s personal information feels like it’s crossing a line on something like this.
What small step is that? Looks like a textbook case of doxxing to me.
https://itwire.com/security/infosec-researchers-slam-ex-wapo...
Yeah this is definitionally doxxing
Once you look at Lucky225's Ham then you get an address. Of course, what is somewhat interesting is their listed address actually is located at Colorado's Division of Central Services building, which very interestingly is a way to obtain a confidential mail forwarding address. It says it is only to be used by victims of stalking/violence/harassment but who knows how well that is enforced: https://www.colorado.gov/pacific/dcs/acp-faq
Either way, I think SexyCyborg (well-known Maker) is quite right to call out HAM license as a vector for getting doxxed.
serious media outlets generally don't name suspects untill they are convicted.
This is a rule that we as a society have established after generations of experience with how media works.
Then we get "social media", and all the old rules get thrown out... So, how long will it take to reinvent the same rules for this new platform?
Don't feed the trolls. If anything we've seen a lot of praise for this person. That has probably been the most responsible hack when you think about it.
Zero tolerance policies don't make any sense to me.
After the Boston marathon bombing, Redditors thought they found one of the responsible terrorist. He wasn't.
I'm not sure I understand your comment actually.
See https://en.wikipedia.org/wiki/Sunil_Tripathi for an example that should make your blood boil
If Krebs got it wrong, well, he can suffer the consequences of that, too.
And, if he got it wrong, the innocent person he doxxed has to suffer the (potentially much more harsh) consequences of someone else's irresponsible actions. While Krebs begins working on his next story, and if we're lucky, posts an "oopsie" comment.
How can you justify that as okay?
A recent example was the biker misidentified as a man who assaulted a child putting up posters.
Alphabet Inc should be held liable.
The first one I saw was a Rip of a SpaceX livestream. I watched it for a bit then noticed all the BitCoin references and got confused then realized it was a scam account. How they get promoted basically to the front page is the issue.
I thought it was very well-known that Lucky225 made that story up as a cover to hide the fact that he gained control of Adrian Lamo’s @6 Twitter via a SIM swap hack himself, and also took control of Lamo’s Facebook in order to hijack ownership of the 2600 Magazine group on Facebook.
It's a very awkward thread where Lucky225 accidentally demonstrates that he has indeed taken over Adrian Lamo's email account. Note this doesn't say anything about whether they were or weren't friends. They definitely had overlapping interests.
Imagine a celebrity saying some 'not so politically correct' things to a friend in private 8 years ago, and now imagine this becoming public while the Twitter cancel culture is in full force. There's a lot of money and power in having that information.
I don't want to argue about what's wrong or not, I just want to point out what I find really concerning about the hack.
Another idea is, hijack customer service request DM's from crypto exchanges, and lead customer to phishing login page. Perhaps could athorize API access to the account, and then change email back to original, without the owner realizing account breach.
I think some people are possibly just sending the scammers some money for the banter? A sign of respect for the hack.
There's an argument to be made that the only reason Bitcoin became popular the last few years is because of the amount of non-techies who have been falling for all the same, tired "join my ICO and get rich!" scams.
My friends in social media positions heard about the twitter hack from me, not the other way around. Given how this info disseminated, combined with the breaking of twitters fundamental feature, i'm surprised more people didn't fall for the scam. A commenter yesterday claimed Coinbase had blacklisted the wallet very early on. I assume Gemini and Binance had similar reactions. Without this swift action, i'd wager the actual haul could have been many times the ~13 BTC they ended up with.
//That scam still works today, never underestimate the gullibility of people.
‘Mom can I please buy $50 worth of bitcoin, pretty please?’
1) Accessible via corporate VPN only (requiring 2fa)
2) Admin panel protected by 2fa plus necessary authentication+authorization controls
3) Audit trails
Short of cooperative access (device handover), I could only see an outsider gaining access to the system due to poor security practices or a remote access trojan getting installed. Though more likely, Twitter lacked these basic controls.
Verified accounts could probably be subject to 2nd person controls so IF someone were to modify an account via admin panel, then a 2nd support person (preferably in a different location), would have to vet the change.
And the best part, support personnel often doesnt have MFA, because its outsourced to countries where smart phones with Authenticator apps are not as common to own for the regular person. I'm not joking.
That said, tokens are probably simpler than zero trust network setup. Even if you had a zero trust network, you'd still want tokens in case an employee machine is compromised.
But now these tools are accessible from the homes of twitter admins. How many of them are running behind compromised home routers, etc? Everyone in the house has access - spouses, partners, teens, visitors.
I bet twitter doesn't have a lot of extra security on their admin tools. They probably write straight to the production database. Those safeguards would really slow down day to day support and be expensive to build, and they probably assumed the physical security of the office building was good enough.
I think the most like cause was a disgruntled employee working from home plus a little bribery.
Putting VPN and MFA on shouldn't slow down people much. They'd just have to spend a bit more time logging in each day. Annoying? Yes, but that's better than a breach.
If you're facing a government though, you do need to be wary of physical attacks.
The most important aspect to the American people is that the largest real estate holder in San Francisco and employs roughly 5,000 employees can’t figure out how to secure their platform. Which means they are a joke of company.
Similar to Google who can’t figure out how to provide customer service when they employ roughly 119,000 employees. Yes, that’s hundreds of thousands of employees and they haven’t figured out how to provide support when their “bots”, which is really their outsourced India techs that cancel their corporate customer accounts on a whim.
Again, this is Google, that distributes malware on their Google Store for months and years at at a time.
Seriously, the ridiculous interview bullshit we’ve all heard about regarding Google and not one smart person ever recommended taking some of Google’s billions and offering customer service or figuring out how not to distribute malware through their official store.
We shouldn’t forget that Google engineers that have access to everyone’s email have also been caught and it’s only a matter of time before Google gets hacked in the same ways Twitter has.
Anyways, Twitter is a cesspool.
Google is also a cesspool that can’t even get search right these days.
It’s a shame that America has these joke of companies on its soil.
There is a healthy contingency of Google and Twitter employees on HN, so I expect the down votes. However, I know there are a ton of people out there that share my message.
How is this acceptable? That's practically (thus effectively) identity theft.
I personally saw one of the official @elonmusk scam tweets earlier this week.
It doesn't help that Twitter's own CEO legitimises and normalises "twitter giveaway bonanza" tweets with his own Square Cash giveaways.
If access were being sold via message board, I wonder if the thread contains stipulations on which accounts are off-limits for being hacked. My theory to why we didn't see any active government officials accounts get pranked is because the hackers, no matter how confident they were about covering their tracks, still might have worried that such a breach would almost guarantee FBI/NSA-level involvement.
"U.S. FBI is leading an inquiry into the Twitter hack, sources say"
https://www.reuters.com/article/us-twitter-cyber-fbi-exclusi...
This could be mostly the attackers’ own money. It’s impossible to tell, but I haven’t seen anyone explicitly mention this.
On the other hand, they can’t really do that. At that point the attackers would be able to poison any wallet just by sending a small amount of BTC to it. Therefore it seems like the only penalty is that they’d have to re-wash their coins.
But a lot of those transactions will be from people who enjoyed the hack and want to reward the hacker for their work.
Bold move to trust the "twitter stream" in the middle of an impersonation hack.
"You can update the email address of any Twitter user, [...] without sending any kind of notification to the user" sounds like a bug, but if your repro starts with "get access to the internal dashboard" it'll get rejected out of hand.
https://news.ycombinator.com/item?id=23860584
"No, you couldn't have made more money than the Twitter hacker" https://fortenf.org/e/security/2020/07/15/twitter-hack.html
No 2FA, just pure and simple hardware token that's chap and easily accessible.
Discord wants my phone number for forums about sexual topics that could get me killed if I was in certain countries. Obviously I don't want to give them something which actually identifies me.
function adminPanelShow()
{
if ( !isInOurVPN() )
throw logSecurityBreach();
if ( !isLoggedIn() )
throw logSecurityBreach();
slackSecurityChannel("AdminPanel Access: " + userName);
...
}Nobody mentioned indieweb.org/POSSE yet as a way to mitigate such?
Likewise, it's not a bitcoin scam when bitcoin is the method of transfer, just like it's not a US-dollar scam every other time dollars are used in theft.
I think simple account takeovers started being called "hacks" jokingly on Facebook, when a friend would find your phone or computer unlocked and logged in.