The Anatomy Of The Twitter Attack
techcrunch.com
techcrunch.com
Like many others, I gradually gave up my internal resistance on Google knowing most everything about me and have adopted Gmail as my primary mailbox.
1) Enable SSL by default on Gmail
https://mail.google.com/mail/#settings
Scroll down to bottom and choose 'Always use HTTPS' for 'Browser Connection'. Click 'Save settings'
2) Change your Gmail security question (you may want to do this now because you may have forgotten the answer to your own question that you set way back when you registered)
http://mail.google.com/support/bin/answer.py?hl=en&answe...
3) If you can't answer your Gmail security question, it will send a password reset email to your secondary email address. Consider the risks of having the secondary email address compromised (and decide whether to remove it or change it to one with a secure 'secret question' process - e.g. if you work for a company, your work email)
In order to be aware that someone has compromised your mail, it's essential that they not be able to reset your password to its old value. Therefore, your password for e-mail should never be findable in your mailfile, nor should it be the same password you use for any other web service. Because you never know what stupid web service will send your password to you in cleartext upon request.
Of course, it's not a good idea to share passwords among different services in general, but keeping your mail password separate is particularly important.
http://googleonlinesecurity.blogspot.com/2009/06/https-secur...
Then I just mashed the keys for the security question.
Now going back to Hacker Croll and his list of Twitter employees and other information. Twitter just happens to be one of a number of a new breed of companies where almost the entire business exists online. Each of these employees, as part of their work, share data with other employees - be it through a feature of a particular application or simply through email. As these users become interwoven, it adds a whole new attack vector whereby the weak point in the chain is no longer just the weakest application - it is the weakest application used by the weakest user. For an attacker such as Hacker Croll looking to exploit the combination of bad user habit, poorly implemented features and users mixing their personal and business data - his chances of success just got exponentially greater. Companies that are heavily web based rely largely on users being able to manage themselves - the odds are not only stacked against Twitter, they are stacked against most companies adopting this model.
Could be summarized as "Twitter used Google docs." Everything else in this paragraph repeats things from earlier. (And things from earlier repeat things from earlier.)
That sounds completely irresponsible.
I'm pretty sure they have never recycled old addresses automatically.
A free Hotmail account becomes inactive if you do not sign in for 30 days, or within the first 10 days after signing up for an account. Once an account becomes inactive, all messages, folders, and contacts are deleted, but the account name is still reserved. If the account stays inactive for a further 90 days, it is permanently deleted.
I'm almost positive that the account I had to recreate was no more than 6-9 months inactive.
more fundamentally, the idea of being able to reset passwords like that is kind of insane. I'm a fan of one of the paypal models- they verify credit cards by sending a unique verification pin to the registered billing address. Not saying that would work here, but it's a nice example of mixing online and real world, and institutes a time lag.
For most users, the idea of that kind of password reset is convenient. And it's not easy as you claim nor practical to regularly check the existence of alternate emails, especially with the amount of users Gmail have. And by the way, they already have a new feature wherein you can use your mobile number to retrieve a password reset code.
There is a feature in Gmail where you can see other currently and some previously logged in sessions. Perhaps it can be made more visible to the user, but it worked for me and had actually used it once to halt an intrusion (not really hacked, my password was automatically saved from another computer's Firefox).
Lastly, another feature that makes me feel safer with Gmail is HTTPS and the ability to force your session to HTTPS whenever you log in.
It's pretty highly visible, especially when more than one person is logged in at once - it's highlighted you bright yellow. It's a brilliant touch - I check this every once in awhile, but have yet to find anything.
Most others are just "best practices" that try to keep balance between security and usability. Except for the practice of emailing a password in clear text which compromises a lot of security for little usability gain.
(1) Hacker deduced from Google password reset that a Twitter employee had a Hotmail account as their secondary email for a personal Google login.
(2) Was able to re-register that dormant Hotmail address (!) -- and thus get the Gmail password reset.
(3) Saw a cleartext password confirmation from another web service among the Gmail archives; reverted the Google account password to that, in the hopes it would allow the compromise to evade the user's detection. That worked; the user continued to use their personal Gmail as normal.
(4) From there, extended compromise to other of that user's accounts elsewhere, including a separate Google Apps for Twitter account, which used the same password. Used information now visible -- internal Twitter docs, private coworker profiles, etc. -- to crack other employee accounts, likely by also deducing password-reset security-questions. Accounts compromised included Evan Williams and Biz Stone.
There's some hand-waving at this last step, but if the early-compromised employees were admin assistants, HR, or sysadmins, and/or if Twitter as a matter-of-course trusted Gmail-to-Gmail internal email as being a safe place to share setup passwords and other private information, it's plausible.
This branching-out to multiple accounts included "AT&T for phone logs, Amazon for purchasing history, MobileMe for more personal emails and iTunes for full credit card information" -- as there's said to be a flaw in ITunes that sometimes echoes back full credit card numbers.
Where are their auditors, their bankers, and their trading partners?
SOX won't let us fart on Tuesdays but a public company can store credit card information in clear text? Unbelievable.
If you really aren't doing this for profit, and you really don't want to hurt the victim of the attack, (as Hacker Croll claims) then don't disclose the information you stole to major press outlets. This attack is really in poor taste, and I think we all of us here at HN should recognize the difference between pointing out the dangers of the internet and being one of the dangers ourselves.
Unless you're saying that techcrunch should have waited until gmail/hotmail update their security policies?
I've ignored (or tried to at least) most of the twitter documents hype - but I thought this was an interesting and well written article.
If you are running a company 'in the cloud' you need to make sure you or your system administrators have control over the user's account and passwords. They can't be trusted to choose decent passwords.
What's more likely? A cracker breaking into the office and copying down their password? Or an electronic attack against their lame passwords? Electronic attacks are far more likely than a physical attack.
I can pretty much guarantee that there is a way for some of my accounts to get compromised with an email address I haven't used in 4 years.
Why? Because at this point I probably have a few thousand accounts, and there is just no way to keep track of all of them, when updating your password/email.
Social engineering is the new wave of security breaches and it would seem that strict password policies etc are just as important as an intrusion proof system/network.