[0]: https://twitter.com/TwitterSupport/status/128433914877449830...
[0]: https://twitter.com/TwitterSupport/status/128433914877449830...
That just raises more questions for me! It would make sense if an attacker was trying to pull the data of some celebs/VIPs as an attempt to hopefully strike gold. But for them to do it on some non-verified account? That makes it seem like these specific individuals may have been targeted. If the attackers were just randomly picking accounts to download, I can't imagine them picking solely non-verifieds.
Imagine you walk by the beach, and see that the sea has washed up a pirate treasure chest. You crack it open, and see it full of gold, jewelry, old manuscripts, letters. Would you just throw the chest back into the sea, taking only a single ring, and a nail from the chest to hang a price list on your lemonade stand with?
Because that's what happened here. The attackers hit gold, and threw it all away.
The hacker managed to get an amazing level of access, but exploiting that, and extracting value from it, and getting away clean is probably really hard. So they sold the access to whoever was willing to pay for it for a guaranteed return. That also gives you an extra middleman that law enforcement has to get past before they get to you, and confusing the trail between the middleman and you might be easier than confusing the trail between your targets and you.
Except whoever paid for the access and used the exploit just didn't have the imagination to do something that made as full use of the hack as they might have done. And now dozens of other criminals are facepalming themselves to death for not having been the ones to have bought this opportunity for their own ends, which they think would have been much more epic.
[0] https://krebsonsecurity.com/2020/07/whos-behind-wednesdays-e...
The original idea that the bitcoin scam was a diversion starts to look more plausible in this light, but in the absence of any information about the downloaded accounts, there’s really no way to guess what their value may have been and to whom.
Alternately, to throw cold water on the above, maybe the process to kick off a download for verified accounts has extra safeguards and the eight non-verified were simply tests to try to determine why the verified downloads weren’t working.
People like you're talking about don't communicate anything of value over twitter. Bezos only follows his ex-wife who doesn't follow him back, barely uses twitter and would be unlikely to have any DMs at all. After the saudi hack, I would be surprised if he has much of anything installed on his phone.
The only real reason to hack celebrity accounts in this instance, and which they should have done, would be to deflect attention from the accounts they actually went after.
I honestly didn't believe you. But it's true. That's... kinda weird.
One possibility I can think of is that a state actor, such as China, was investigating state enemies, such as suspected dissidents. They wanted to get the DMs, but also didn't want the general public to catch on. So they set things up so public discourse would be centered around the Bitcoin scam and celebrity hacks.
This is still absurd to me. What diversion? Twitter knows exactly what was downloaded, and in fact they’re looking at this even closer due to the supposed diversion.
It seems like a sophisticated attacker running a targeted attack such as a government agency would presumably have avoided doing anything noticeable like the public tweets in the hope of being able to avoid detection and target additional people in the future.
Twitter is fundamentally a web app. Users can log in from any browser and read their messages, which are stored on the server. This is a very different situation from Signal or WhatsApp, where an account is tied to a device, and messages can be stored there.
The only reason someone wouldn't do this is if they didn't want the heat and if they didn't want the heat they wouldn't have hijacked high profile accounts to begin with.
They say it but downplay it very much.
Obviously this means the attackers had access to DMs.
Let us imagine that I am Jeff Bezos, why would I use my official account to DM people? I would rather use one where I look like everybody so that it is less likely to be the target of an attack.
AFAIK, deleting Twitter DMs only deletes the conversation from your end, so if the verified user, worried about this exact situation, periodically deletes their DMs, but the unverified user, not nearly so worried, doesn't...
Maybe that's going too far down the rabbit hole but I'm really curious now.
Verified accounts, are surely mostly media-company controlled?
Nowhere they say DMs of the celebrities were not accessed. Some sort of lying by omission.