Twitter wasn't 'asking for it', and neither were the individuals who lost bitcoins; the 'hackers' intentionally perpetrated deceptions, misrepresentations, and fraud against both Twitter and the general public. If you compare what these three did to a white-collar crime, the dollar amount was small, but the behavior was egregious.
Now, I don't think the government is prepared to do this proactively and effectively, but the idea of a telco that advertises resilience to hacks (whether through social engineering or technical incompetence) sounds like it would be quite appealing to a growing segment of the connected world and whatever such promises that find success in the marketplace might be used to inform legislation or regulation, eventually...
This is probably off-topic, but companies shouldn't even be sending the passwords over HTTPS; passwords should be hashed client-side and then the hash should be sent to the server (preferably over HTTPS).
Surely if the server accepts a client side hash of a password, then the hash has become the password
1. Api gives user a fixed salt.
2. User types password into input.
3. Client hashes and sends hash to server.
4. Server has another salt and uses the client sent hash to hash it again.
5. This final hash is compared what is in the database.
This way server never has knowledge of the original PW and it's never sent over the network. This reduces for instance the chance of password getting logged in the service etc.
Let's imagine a situation in which someone breaks into my house and steals my TV. I deserve a decent amount of blame if I left my front door wide open before it happened. I deserve much less blame, but still some blame if I left my front door unlocked. I don't deserve any blame if someone broke down my front door to do it.
In this situation, Twitter left their front door unlocked.
Furthermore, Twitter is not even the primary victim here. The biggest victims are the people whose accounts were stolen and the people who were tricked into losing their bitcoin.
I mean, you could have gotten a more sturdy door... drawing the boundary between someone opening an unlocked door and breaking down the door is hard; so I'd agree with "even less blame", but if we believe you are ever at blame here, there isn't anything magical about the lock that shifts you from having blame to being blameless.
Back on topic, I think lots of people would agree that allowing low level employees the ability to completely hijack the accounts of some of the most prominent people on the planet with zero oversight is not a reasonable level of security.
In fact, I would then claim pretty forcibly that a lock strong enough that someone has to break your door is absolutely not the thing reasonable people should have to do to prevent theft (assuming one believes in the idea that people own things, of course ;P).
Like maybe a chain lock should be good? I remember a glorious scene of some cartoon which was like "you know what this chain lock says? it means you aren't getting in here... unless you push with your hands". Closing your door is really not good enough? Having an exposed area with a door--even if open--that looks like a door of a household and not a business?
Look: I appreciate and even agree with the idea that Twitter should have blame here in some very real sense, in that someone always could have done better to protect you if they take responsibility for something about you, particularly if they don't really leave you much choice in how they do it: you friend who borrows your car and leaves it unlocked with its windows down is being negligent; and Twitter here looks like they didn't even try hard to protect anything.
But the reality is that we shouldn't think there is some magic level of "responsible" below which there is blame and above which there is no blame... in this kind of tug of war either we are working in the philosophical regime that you are ever to blame--in which case we can talk about matters of degree--or you are never to blame, but drawing some arbitrary line about "well the data storage was technically X3 7066 compliant, so this is on the other party" is actually an extremely dangerous thought process as it sets us up for companies putting in place minimum security theatre provisions that they know don't work but which they know technically absolves them of blame as it is reasonable (which is a thought process that crops up constantly).
(And seriously: is using a large, centralized social networking site and not expecting your data and accounts to be hacked every now and then reasonable? All of them get hacked. Thereby why are we stopping the blame at Twitter? If we are going into the philosophical regime of truly assigning blame, users should "know better by now" and stop using systems with centralized databases, right? I work in the field of decentralized systems and I absolutely am confused as to why people think their data in the "cloud" is secure and absolutely do not consider their usage "reasonable".)
(And like, to explain that context: this is all coming from someone in the field of hacking and security research who is also in progressive politics and thinks throwing the book at this kid with 30 felonies is ridiculous and maybe he should get some community service at best for what he did, and that we should be regulating big tech more to increase their liability as if we don't then it is essentially giving "moral subsidies" to centralized systems and making it harder for distributed, self sovereign, and end-to-end encrypted systems to compete. I actually agreed with your original comment, but in your defense against an accusation of "victim blaming" you actually do seem to have an inconsistency in your mental model and it is the same one we have to push back against in arguments about victim blaming for sexual assault: the lack of any specific protection doesn't mean you have something to blame for someone assaulting you. The argument for regulating against Twitter and holding them accountable has to come from somewhere different.)
As such, my proposal of punishment would be to give this fellow an unpaid, mandatory internship at Twitter. This teaches them to learn their victim, and Twitter can teach the perpetrator the proper way to handle a company's problems. Show him how fun red teaming or blue teaming or pentesting can be.
Should we blame women for dressing provocatively if they are raped? Should a murder victim be afforded less justice if they were walking around in a bad neighborhood? A crime isn’t a crime if the potential criminal chooses not to act. The ease of committing the crime should have no relevance. Someone doesn’t just accidentally walk into your unlocked house and steal a TV. It’s a choice and blaming the victim is simply wrong.
A woman that goes in a bad neighborhood dressed provocatively and that eventually gets raped, made the mistake of going there in the first place - and honestly speaking, the dress makes no difference. She placed herself in a situation where she is powerless against potential predators, and thus she will go by the predator's rules - because she is forced to do so. That does not mean we should not change this. We should do everything in our power to protect women, and make sure there ARE no such places dangerous for women. Until that happens, to avoid the danger wherever it is is better than rightfully punishing the criminals after the crime happens.
That is not a sexist matter, that goes for countless situations in this world. Women and men alike, or whole other groups are powerless against other people, depending on the situation, and it IS wise to avoid the danger, until we fight to eradicate this powerlessness on each occasion. You can go on despite the dangers to make a statement or in order to contribute to eradicate them, but you know what you are getting into.
"As long as it can be established that your possessions have been taken without your permission most policies will pay out on a claim even if your front door was unlocked or your window open."
so - as it says later "Familiarise yourself with the terms of your policy" which I guess would lead me not to buying insurance from your company.
Aside from that allowing insurance companies to determine who 'deserves blame' seems to run counter to the common perception regarding the moral worth of insurance companies.
Certainly the burglar deserves the lion's share of the blame for what happened, but there's plenty to spread around.
My view is that if a reasonable person would have taken actions that would have avoided the issue in the first place, a person not taking those actions shares in the blame.
My bicycle got stolen from my garage a couple weeks ago. The garage was closed and locked, but someone forced the door at 4am and stole my bike. My bike was not locked to anything. My neighbor's bike was locked to a railing a few feet away from my bike, and did not get stolen. I share some of the blame here because if I had locked my bike up -- an entirely reasonable and prudent thing to do -- my bike would likely not have gotten stolen.
I think maybe the issue is because people are conflating blame with shame. No one should be shamed for stuff like this; it's a learning opportunity. I accept blame and responsibility for my part in my bike's theft, and if/when I get a new bike, I'll take better care to secure it, even when it's indoors.
If people locked bikes in garages, people eager to steal bikes would have tools to cut chains in garages. So while it is safer to lock the bike, the blame for stealing goes to whoever stole it.
And remember that "the problem" is that the attackers hijacked the accounts of people using twitter. Twitter had a duty to take adequate measures to protect those accounts, and failed to do so. The victims are the people whose accounts were stolen, and the people who were defrauded by the hijacked accounts.
That’s hobo mentality.
It’s not your pie. Keep your goddamn hands off the fucking pie.
If hackers are a known problem, a huge company like Twitter has no right to claim it was completely blindsided when it gets hacked.
Twitter is a multinational corporation with access to the personal data of hundreds of millions of users.
It has a duty of care to those users, and at a minimum it should have a dedicated team with security policies and recovery plans.
Aside from the reputational damage, an aggressive and ambitious lawyer could make a good case for a very expensive class action if those plans turn out be defective and/or inadequate.
I have a feeling that a vast majority would agree that choosing to send your money to a celebrity’s (apparent) bitcoin wallet for any reason will be tough to feel victim-sympathy for, and possibly asking to never see that money again given all of the well regulated systems and norms of money transfer that we have used for decades to centuries. But I understand that they were still taken advantage of and agree that they are victims.
Twitter is to blame here. The only thing they are a victim of is failing to protect their users (whom they have the obligation to protect) in a game where they have the ability to be solely the masters of their own security destiny.
I used to be CTO of an ecommerce platform - small fry, barely £1bn in annual transactions - but it was always absolutely clear in my mind that any breach would be my fault through negligence.
Twitter is not the victim here; the users who had their accounts taken over are. Twitter did not lose anything, except an entirely reasonable loss of reputation, because they could have taken measures to prevent this sort of thing from happening, but did not.
Companies need to be held accountable for their breaches. Sure, sometimes a company did do everything they could to prevent a breach, and took steps to mitigate the damage in the event of a breach, and they still happen. But that is vanishingly rare. The main thing I've learned from all the breach disclosures (at least where companies are truthful and forthcoming about what happened) is that security practices are lax and insufficient pretty much everywhere.
That's not ok, and we need to do something to incentivize these companies to properly protect our data, before we all become victims. If financial sanctions and public shaming is the best way to do that, so be it.
It's a bit pathetic to extend this rape analogy to a business. We don't hold individuals and corporations to the same legal, and/or quality standards.
So, hopefully we can discuss these important policy issues without worrying if "twitters" feelings get hurt.
sometimes the victim deserves some blame.Or at least their actions analysed to see where blame lays
If they did I bet those numbers would change pretty quickly.
Similarly, if Equifax had been shut down under the mountain of lawsuits they should have had for losing people’s data, I bet security would become a much bigger concern for everybody.
The FBI study basically shows that consequences are important.
He said during his first week he made the mistake of putting a CD-ROM with some official training materials into his work system. Within 10 minute two people showed up to stop him and investigate what was going on with his computer. It was fine in the end but he was seriously reprimanded by his boss.
When you can’t trust users, the answer isn’t just to give up! It’s to acknowledge their fallibility and create a system that doesn’t rely on 100% compliance. In this case that means having software that instantly reports when any external media is connected.
Ah yes here we go, large scale study, 43% of participants gave away their password when bribed with a chocolate bar. People just don't realize how valuable passwords are.
https://www.sciencedaily.com/releases/2016/05/160512085123.h...
Nearly 30% of people just gave out their password and didn't even know they were getting chocolate! They gave it away for literally nothing.
Some where given chocolate before and after , nowhere it says chocolate was offered as payment for sharing the password. Small gifts could have been inducement to establish relationship and trust not the same as a bribe as you characterises it
I find it hard to believe 25 /40 % plus people readily share their password to total strangers , without knowing more details it seems unrealistic
Social engineering is still a problem but am not sure bribes are the real concern . And to insinuate the cost of bribing is as low as candy for significant chunk of the population is just wrong
The premise that integrity of most people is bribed by few bars of candy was offensive to me I hope it is to you as well. The sensationalist headline basically claimed that, the abstract was a very different statement.
I am tired of studies that are constantly being cited these days: readers, journalists and even the principals invariably sensationalize the headlines.
It is a losing battle to get anyone to critically analyse information presented to them, sooner or later you are going to snap. Whether it is alternate medicine, creationism, or conspiracy theories there is a real damage out there everyday , few people ( Jon Stewart? ) are articulate despite being frustrated and are able to civil engage in discussion.
Even if the study actually claimed what the headline said, the bar to peer reviewed respected research in much of psychology and social sciences seems so low that just getting some correlation between two parameters is good enough. Raw data is rarely shared, and statistical methods used are superficially understood and discussed, half the analysis's are just putting data into a tool like SPSS with the whatever defaults IBM puts in these days. There is not much scope for replication of a finding, a core principle of the scientific method.
Idle hands.
Well, that's your problem.
The problem is that they have not revealed the massive discrepancy between the common expectation and the truth which I, and I suspect most people, would consider to be fraud. Some might argue that they did not guarantee the common expectation and therefore it is the consumers problem for engaging in wishful thinking, but that is frankly a ridiculous argument. We generally expect, and the law codifies, certain requirements on the consumer-business relationship which effectively amount to: "Consumers have certain reasonable expectations based on common sense, you can't just willy-nilly toss those in a contract and blame the consumer for not reading a 100 page contract where you get to sacrifice their first born in fine-print every time they buy bananas." I do not believe the law exactly codifies this form of fraud, but I think most would agree that a massive discrepancy between consumer expectation and the truth should be clearly communicated (the larger the discrepancy the more clearly/loudly) and acting otherwise should be at the least in the general vicinity of fraud.
In my opinion, the discrepancy is sufficiently large that it should constitute either criminal fraud or gross negligence depending on how aware Twitter was as to their own internal security. If they were aware, they engaged in fraud given they made no effort to properly inform anyone of their security. If they were not aware, they are grossly negligent in that they could not observe such a massive discrepancy between their beliefs and the truth. To anybody who reads this and says that this is a "heads I win, tails you lose" situation, I say that this is a result of the ridiculous discrepancy. If it were less ridiculous, like say a small group of organized hackers or a top-flight hacker, it would probably not qualify as gross negligence in Twitter's case if they were unaware, though it might still be fraud depending on the expectations laid out.
Incidentally, this reasoning scales to other cases people have mentioned like nuclear power plants or banks where people have certain expectations on their security which are likely different and more stringent than Twitter. The important thing is not that they all have the same high level of security, it is that the expectation matches reality and the reality is properly communicated.
2. I think you may actually have it backwards. I would imagine the engineering group at Twitter (the people who have important credentials) is in some ways more paranoid, or at least more technically savvy and therefore more aware than many of the people at the FBI.
We once had a bachelors thesis comparing the results over multiple years, and the results were mostly stable. (Years are mid 2010s).
[1] https://home.cern/news/news/computing/computer-security-cern...
I know it's obvious, but it feels like it's only obvious to those that think about security. It's the same reason that putting your developers through a yearly OWASP Top 10 secure coding course isn't going to get you to 100% secure code.
Locking down systems seems draconian, but it's the only way:
- Disabling USB storage
- Moving away from passwords to hardware authentication
- Strong controls on internet access
- Stop incoming calls from reaching most employees. Better: take away phones altogether
And so on.
Such clean room requirements could perhaps work when the threat model include nation state actors or your are handling sensitive financial applications.
Most companies are not defence contractors or banks the security levels you propose won’t be worth the cost to a typical internet tech company .
I have a Chromebook running arch[0] that has a borked network adapter than I use to plug weird things into/use as an airgapped box I can reset in about 5 minutes. I'd have no qualms about plugging anything into that
[0] BTW I run Arch
As an aside to that important point, it seems like the solution here is to just remove all random device access points and drives before giving a system to some luddite with no security awareness.
If that didn't work, StuxNet wouldn't have gone anywhere either.
Sometimes the right hand requires the left hand to fuck up.
working at a court room I was bemused by the security talks about usb keys, yet the OS setup still allows usb driver installs automatically (granted their local presence). I know because I brought a keyboard to replace the busted one they had in-house and windows gladly set up everything plug`n`play.
I wonder if OSes have actual rules for this, and if there are secure corporate usb keys
https://docs.microsoft.com/en-us/windows/security/threat-pro...
thanks for the tip
I think calling FBI "security-focused" is a bit too generous. They are essentially glorified police detectives, with greater authority and jurisdiction. I don't believe the average FBI agent is particularly competent, in terms of technical (i.e. computer) skill or knowledge.
We’re constantly presented with evidence to the contrary.