> Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees."
https://www.npr.org/2019/11/06/777098293/2-former-twitter-em...
1,000 people, including contractors outside the company, is not a "limited group of trained and vetted employees." It's news because they misled people about their security, again.
That's not necessarily true. 20% of the company could fairly reasonably be deemed "limited", and there being a thousand of them doesn't mean they're not trained on their tasks.
Once you want to add more people to any business, you need to add even more people to that business.
Lets say you have 10 engineers and want to add another. Suddenly HR's workload has tipped over the limit and you need more HR people. Now communication is fracturing for those 10 engineers and you need a Product Manager and an Engineering Manager to centralise the steering and cohesion of those 11 engineers. Now budgets, payroll and accounting has increased and you need another Finance person.
Suddenly your office is too small so you need a bigger office and an office manager.
This is obviously a contrived example, but having worked at very early stage startup, a mid sized startup and a global megacorp while seeing all of them go through various growth cycles you start to appreciate how headcount can creep in ways which feel indirect to the most pressing problem at hand (ship more features, deliver more customer value).
You see it software terms too - as your software project scales suddenly you need more infra, your CI environment gets more complex. Suddenly your workflows don't scale as too many engineers are working on the same code, so you rearchitect (components/microservices) then you need to start building dev tooling and metrics/observability....
I guess as some kind of system scales, the leverage you gain from adding a thing to it has some diminishing curve / inverse relationship to the size of the system.
Anyway, even if they had provided a figure, I think you're taking it out of context - the quote says access to "sensitive account information" is limited, not access to account recovery options. So it's potentially someone outside of that limited group whose credentials were compromised.
I notice it wasn't Nestle or Verizon or Disney or Heinz or Unilever accounts that got hacked.
You know, the information about "accounts". The records of monetary transactions.
https://www.statista.com/statistics/1094351/us-twitter-adver...
I don't think this is misleading at all. Your bank probably has thousands of people who can get equivalent access to your account, and they serve a lot less people than Twitter, and mostly during business hours, in one language, in one country.
1000 people in total when they have to have some available 24/7 isn't many.
Say 200 of them are individual technical staff with access for specific debugging purposes. Then it's only 200 people per 8 hour shift.
There's probably requirements for specific language support too, which increases the head count. There was a period of time some years ago when Twitter's peak usage was from Japan, in Japanese hours, in Japanese language.
In an organization as large as Twitter or a bank, that still means thousands of people. You are seeing 1000 as large because you are forgetting the scale on which they operate.
You have unreasonable expectations for what "limited group of trained and vetted employees" means in a CSR environment for millions of customers.
Spear-phishing by its very definition is a highly targeted attack. I wouldn't count on any level of training to prevent someone from getting phished. Given some of the spear phishing campaigns I've seen, I wouldn't trust even myself not to fall for them.
It's a problem that needs to be solved with technical solutions like hardware U2F, locked-down customer support devices (e.g. Chrome enterprise policy managed ChromeOS devices), and special account VIP/anomaly locking and auto-escalation.
The cynic in me reckons "Hell no! Those sorts of people are way too often _proud_ of their zero-thought blind clicking and lack of understanding of how things work"...
EDIT: Voice mimicry scam? Verify via known channel before taking action.
I also think this is a much stricter standard than you're recognizing. In my company's last spearphishing test, they sent out a link purporting to be a company survey immediately after an all-hands meeting announcing there'd be a survey (the real survey link came a few hours later). Expecting that nobody will be distracted enough to fall for such a thing seems unrealistic no matter how well you train them.
The corporate security team sent out the email. It had a link with no actual content, giving an error, but that got you on the list of people with bad security behavior.
The trouble at my office was that most employees were highly capable security researchers. These are people who reverse engineer malware for pay and for fun. Of course they eagerly attempted to download from the link! They wanted fresh new malware. People would typically download via wget in a virtual machine on a PC without important data.
And there is no magic bullet. Trying to educate people gives some results, but mostly just prevents low effort phishing attack.
I have never seen pentest that include social engineering fail. (This might be just our customers. I would expect govt or infrastructure organization to be better)
It seems like Twitter has none of this, and while you can argue it's not the same a banking, there are still sensitive communications and there's no real reason why anyone should be able to post new tweets or access private messages without several approvals.
Unless new information has emerged recently, this wasn't the attack vector. The attack was resetting account emails/passwords and turning off 2FA.
I agree that there should have been more protections around this, but it's hardly newsworthy that Twitter employs a large support team to support their large userbase - my main gripe is with how the headline is framed.
The reset via admin tools must have bypassed the normal email workflow.
Changing the email is effectively changing the identity attached. It's akin to an account recovery and should require several verification steps before it can be done.
For operations on accounts where illicit access can cause massive irreversible damage -- either by exfiltrating private information (emails, DMs/PMs, posts on locked accounts, etc) or by making a post that appears authorized (the more notable the victim the worse it gets) -- there has got to be some sort of two-man rule (https://en.wikipedia.org/wiki/Two-man_rule) integrated into the system that can't be bypassed by the people with authority to make changes to accounts. Otherwise any insider / careless spear-phishing victim will make the changes they want, and theres no reason the adversary will limit themselves to posting shoddily-executed (they used the same address instead of generating one per victim!) bitcoin scams.
Furthermore, i'd really like there a way for any user (not just bluechecks) to opt-in to some sort of feature where Twitter enforces more stringent requirements/documentation/delays for the email/phone-change / password-reset processes -- at the cost of accepting higher delays or maybe even monetary payment.
There's no reason i need such critical account procedures to happen on twitter (or my email accounts, for that matter) to happen in real-time, and i would happily give that up in order to require that such a procedure only happen after, like, a week of enforced, non-bypassable delay where they contact me with details of the change on all my phone-numbers and emails every day.
With twitter, the damage is not practically reversible since it was a bitcoin scam.
The analogy/comparison works to a degree, but misses some key differences as to why this is actually worse with twitter than a bank.
For example, education programs do squat against me attacking the employees directly (targeted malware, getting on their computer somehow, offering each of the thousands of employees $10,000 for temp access to their account). And each additional employee only strengthens my attack.
Let them do it... the bank will always be responsible and it will always be solved without much issue.
Twitter accounts though... good luck taking back theses bitcoins from all the one that got scammed. Good luck even getting back your account if you aren't named Bill Gates.
Also I don't think thousands of call center people typically have sole ability to directly overwrite bank and brokerage key data fields.
That's false equivalence. If a bank employee drains my account without authorization, it won't be difficult to prove and get back. But once your data leaks, it's out there.
Do you have some data to back that up?
Sounds implausible