Twitter Got Hacked, Is Mastodon Immune?
mikestone.me
mikestone.me
In Twitter's case, it came down to some pretty poor opsec and could have been avoided. Ultimately you're going to have at most N points of failure. With security keys, the number of points of failure in Twitter could have been reduced to one (and that one user could be proactively educated).
In Mastodon, every user is potentially in control of their instance. Every user is a potential point of failure. Users routinely fall victim to social engineering each day, possibly someone is this very second.
On top of that, it's possible that some Mastodon instances have weak security.
But others will not.
So there will never be a full-blown Mastodon hack just like there's never been a full-blown email hack.
So,if users are very huge in single instance(mastodon main instance is the example) and the moderation is not likeable,there will be problems.
Also federation like this is new to people.
Will it work out? Currently, not likely.
Also,it can't be claimed immune. Bugs might be present.
A quick eyeball of the English-language instances listed on instances.social, sorted by # of users, would suggest that this is true. There are a couple very large general-purpose instances, but after that it's largely much smaller topical communities.
My hypothesis would be that, if one tracked these numbers over time, it would turn out that the larger ones aren't just bigger, they also grow at a faster rate. So, if Mastodon were to grow to the scale of one of the major social networks, we'd also find that the users were mostly all clumped into a single instance that's roughly the size (and level of nastiness) of one of the major social networks.
At which point, from a social impact perspective, the fact that Mastodon is, from a technical standpoint, open and federated, would be beside the point.
Furthermore, I think that small instances are just as important as the big ones. If a small group of people has a shared interest and they want to run an instance in a specific way that's possible to do with Mastodon.
There are tons of small Mastodon communities for all kinds of niche interests right now, and their users can make up their own rules for how they interact, what they allow, and so on. This is an incredibly important aspect of the federated model. There isn't one set of rules that applies to everybody the way there is with a centralized platform.
Imagine how twitter will be if it never displayed any counts - followers, like, retweets etc nothing is shown to the user, even if they used all of it in the background, just by not showing it will have enormous impact on user behaviour.
Linkedin did that by not showing connection count beyond 500, to dis-incentivize people from making connection requests like facebook friend requests.
Architecture in Mastodon case makes it not attractive for influencers as compared to other platforms(IG, twitter etc) where they have higher Return on Effort put in.
Could a Mastodon server be compromised? Of course. Would it affect all of Mastodon? Of course not, because it's distributed. Duh.
To be fair, the article is just part of a challenge to write 100 blog posts in 100 days. Nothing wrong with writing whatever you want, although the title of the post is still terrible. The question is, why did anyone think this article was worth submitting to HN?
Mastodon at the moment is basically a cozy little community. If a bunch of celebrities joined you can be sure they would all be on a professionally managed server - a tempting single-point of attack in the same way that the Twitter admin console was.
I can trust Twitter to have backups. I know almost nothing about the community-served Mastodon instance on which I created an account, and I'm kinda locked there.
"I can trust Gmail to have backups. I know almost nothing about the corporate-provided mail service on which my administrator created my account, and I'm kinda locked there."
The twitter attackers had access to everything but only used it to target a few users. A hypothetical Mastodon attacker might only have access to a single server but that would likely be enough to perform the same actions.
On the other side, the argument is "to take over all accounts, you'd have to take over all servers", I guess? That's true, but nobody cared about the egg accounts on Twitter either, they target the influential accounts. If there were serious celebrities on Mastodon (ie some pop singer with millions of followers), I'd expect Mastodon to actually be in a worse situation than Twitter. Twitter generally has procedures that are harder to break than some random individual who runs a server as a hobby. Unless the idea is for every person to eventually run their own server so their accounts cannot be social-engineered out of their hands.
I know that a disproportionately large instance may attract the level of attacks that twitter gets, but - while I'm ignorant of all possible attack vector of activitypub or all mastodon instances - I think it would be hard to take over all those celebrities accounts if they are split among several instances.
Each instance admin could potentially try to interrupt the attack on their users on their own.
I'm sure ActivityPub and Mastodon are not flawless but I think that if they decentralized in the right way, it does prevent this type of attacks such as the ones witness on Twitter. It's not even through obscurity, it's just through friction of having multiple admins to deal with.
Mastodon has "post as user" in its internal tools? Why?
Then check your mail server for outgoing mail, and use the mail sent to the user to change the password.
It could be easier and harder to target celebrity accounts, but would again depend on the specific hosts.
Git is decentralized version control. I would bet a site like Github protects itself from mass attacks because of its popularity. It has nothing to do with decentralized software.
If a specific Mastodon node becomes super popular then it should have a plan to protect itself from these types of attacks.
What’s the purpose of starting a blog post like that? The phrase is a cliché, and not a polite one. Whatever follows that introduction is either something the reader already knows and has fresh in memory (thus useless to mention) or you’re calling them oblivious.
A sentence that’s irrelevant or mocking the reader seems like a poor way to start an essay.
Most of us would do well to “hide under a rock” for a while. News and the way they are presented to us are stressful and largely irrelevant. Chances are you could live the rest of your life without knowing Twitter was hacked.
It reminds of something a little different but on a similar theme: the advice to never say "clearly, ..." in lectures, because it serves no purpose except to intimidate people that don't already know what follows. Actually, it does serve a purpose: so that people who do find it trivially obvious aren't thrown off wondering if there's something deeper there than they had realised.
And yes, it’s possible to abuse such phrases but that doesn’t mean they don’t have their place.
The author didn’t even need to rephrase the sentence. Cutting everything up to the first comma would be an instant improvement with zero effort, conveying the same information just as clearly and in less words:
> You probably know that Twitter got “hacked”.
Why do fairy tales start with "once upon a time"? It helps the reader feel familiar with the text they're about to encounter. Why do formal speeches start with "Ladies and Gentlemen"? The audience knows the expectation of formality which that structure provides.
In this case, the author is using a cliché for a couple of purposes. This first is to let the reader know that this is an informal piece of work and shouldn't be treated as a rigorous scholarly article.
The second is, hopefully, to make the reader feel "in the know". Anyone from the target audience reading that might think "I haven't been hiding under a rock! Unlike other people who read this. I am smart!"
Not every piece of writing has to be original. Clichés exist to help guide people through unfamiliar territory and to provide them reassurance.
And they all lived happily ever after.
The author’s intro will be relevant for a few months at best and has a negative connotation. I doubt anyone will feel empowered or happy by the author’s phrasing.
I agree clichés have a purpose. I’m commenting on this one because I feel it has no redeeming qualities.
Not all writing has to appeal to or be directed towards everyone.
It could read as funny. No way I've been hiding under a rock silly my 4 year old might say.
Informative: I have been at the cottage this week what happened?
Creates a narrative/introduction: I've been following this story what's new?
There are people who will turn it into.. I've only been following this a bit. I suck, I could do better. Why did I waste my time on some other story? I need to do better in life.
How you perceive that old boring saying tells us about you.
I don’t think being old and boring is a reason to not reevaluate our words; I find doing so can be interesting.
As for the negative connotation, it's certainly there, but it sure seems to me that it's meant to be taken facetiously, presumably made under the assumption that it's relatively unlikely to offend anyone. I would guess that a Venn diagram of people who read this blog (or follow news sites that would link an article on this blog), and people who hadn't heard of the Twitter hack, probably looks a lot like an illustration of Mars and the Sun, drawn to scale.
There's always Scalzi's Law waiting in the wings when someone tries to be humorous on the Internet, but, considering that this particular formula doesn't have any clearly discernible minority group as its victim, or anything like that, I'm inclined to say it's safe to stick to HN's 3rd guideline on commenting here.
I agree. I don’t think the author (or most people who use the sentence) wrote that to be intentionally disparaging. But I also think it’s healthy to reevaluate the idioms we use on auto-pilot.
My commentary is on the phrase, not the author.
The author is excusing themselves for beginning the post by adding some context - that is likely already well-known to readership. They are saying "yes, I know you already know this, but please excuse me while I pop in some context in case there's a reader who is unfamiliar with it".
Hope this helps.
> News and the way they are presented to us are stressful and largely irrelevant.
This perspective comes from privilege. Nothing wrong with that but I could just as easily complain that assuming everyone has the luxury of ignoring the news is insulting in the way you think the original post was.
That’s a limitation of text. Were we conversing in person, I doubt you’d have felt that. I don’t feel personally attacked by the sentence, I just don’t think it’s a good one.
> I could just as easily complain that assuming everyone has the luxury of ignoring the news
I did mention “for a while”.
To clarify, there are relevant news we should and want to know. My concern is about the barrage we are fed, not in the name of keeping us informed, but to keep us glued for more.
[1] https://www.politico.com/news/2020/07/02/republicans-parler-...
Different writers have different esthetics, Some have developed a more refined taste and a more exact language; while others have a less cultivated taste and are more given to cliches, mixed metaphors, tired jokes, and so on. It's a matter of style.
Also the amount of time for them to identify it, they had blocked tweeting the address and blocked all verified users from posting before they could find the rogue account indicates logging and analysis of their admin tool actions is also not robust.
Exploiting these two vulnerabilities whether by blackmail, bribe or RAT should not make a difference to consider it a hack
Can people please stop commenting on HN threads pretending to know about hacking and making false claims.
Look, there are really only two general approaches to arguing over the dictionary: Trotskyism (i.e., permanent revolution), and joining with the forces of evil.
https://en.wikipedia.org/wiki/Talk:2020_Twitter_bitcoin_scam...