News: 1595226309

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Twitter hackers busted 2FA to access accounts and then reset user passwords

(2020/07/20)


Twitter has revealed more about the [1]July 15 attack that saw several prominent accounts hijacked to promote a Bitcoin scam.

The Saturday, July 18 [2]update admits “the attackers successfully manipulated a small number of employees and used their credentials to access Twitter’s internal systems, including getting through our two-factor protections.”

You read that right: even 2FA failed.

The post continues: “As of now, we know that they accessed tools only available to our internal support teams to target 130 Twitter accounts. For 45 of those accounts, the attackers were able to initiate a password reset, login to the account, and send Tweets. We are continuing our forensic review of all of the accounts to confirm all actions that may have been taken. In addition, we believe they may have attempted to sell some of the usernames.”

Data leaked. Twitter isn’t sure what, but said the “attackers were able to view personal information including email addresses and phone numbers” for the 130 impacted accounts. It’s possible “additional information” may also have been viewed.

Eight account-holders suffered the indignity of attackers downloading the account’s information through the “Your Twitter Data” tool, which offers users the chance to access a summary of their Twitter account details, private messages, and activity. Twitter is contacting those folks directly.

Future scholars will regard most of Twitter’s post as a decent example of the genre known as “Sorry, that shouldn’t have happened, please forgive us, we’re getting more infosec training.”

There’s not much more to the post than that, other than perhaps the revelation that Twitter is collaborating with law enforcement agencies to figure out what happened. And is really sorry, but thinks saying so means it doesn’t have to be quite as sorry as it was when the hack happened. ®

We hope that our openness and transparency throughout this process, and the steps and work we will take to safeguard against other attacks in the future, will be the start of making this right. — Twitter Support (@TwitterSupport) [3]July 18, 2020

Get our [4]Tech Resources



[1] https://www.theregister.com/2020/07/16/twitter_account_hijack_latest/

[2] https://blog.twitter.com/en_us/topics/company/2020/an-update-on-our-security-incident.html

[3] https://twitter.com/TwitterSupport/status/1284331136777256960?ref_src=twsrc%5Etfw

[4] https://whitepapers.theregister.com/

nonsensical ?

Forget It

> We are continuing our forensic review of all of the accounts to confirm all actions that may have been taken.

Is it nonsensical to combine the words "all' and 'may" in that sentence>

Re: nonsensical ?

Mark192

Could be that they want to look at what the attackers had the potential to do, not just what they did.

Alternatively, maybe a PR person thought putting in 'may' made things sound less bad.

Re: nonsensical ?

Khaptain

'May' should be replaced by 'have' as their is obviously work that needs to be done.

This is not a 'must' not a 'might' situation.

Re: nonsensical ?

Khaptain

"This is not a 'must' not a 'might' situation."

That should read

This is not a must but a might situation..

@AC

We know what the hackers did, they had inside men ( by intention or by coercion), what we want to know is what they are doing about it and why measures were not already in place to avoid this kind of possibility.

They can't just sit on their asses thinking these kinds of problems will just go away...So there is defiantly a "must do something" element.

Re: nonsensical ?

Anonymous Coward

Given that they're trying work work out what the hackers have done ("confirm all actions [the hackers] may have taken"), not what is needed to prevent it, no.

The bit that leaps out for me...

IGotOut

"the attackers successfully manipulated a small number of employees"

So it wasn't a single person that messed up, maybe not even two, but multiple people.

That smacks of a bigger issue than a Ooopps, someone pressed the wrong button.

Re: The bit that leaps out for me...

Anonymous Coward

I would suggest a small number may end up being just 1 but they are trying to avoid all the crap landing in one place at the moment.

Plus it suggests very weak procedures for high value accounts if a single person acting in bad faith can compromise them.

Twitter hackers busted 2FA to access accounts and then reset user passwords

Anonymous Coward

... Again.

Ok, hands up, which of you did it?

Shadow Systems

*Notices my own right hand go up*

HEY! Stop that! I did NOT have anything to do with it!

*Grabs the arm with the other & tries to wrestle it back down*

*Fighting with my own arm, gets a punch in the head, shouts in surprise, & Judo throws myself to the floor to try & restrain myself*

Halp! Halp! I'm being repressed!

*A comical cloud of fighting iconography floats up from the floor where I've disappeared*

*A sign on a stick rises up that reads "One moment please. I'm being hacked." and then gets tossed away as the other hand smacks it with a thwap*

Sweet 2FA

Anonymous Coward

no comment.

Dodgy

fronty

Something dodgy going on here if 2FA was compromised.

Re: Dodgy

Velv

Attackers had access to the internal tools, and could view mobile numbers. Presumably they could update user details like mobile numbers, and since they're using tools for trusted staff, no further authentication was required. So change the mobile number of Elon Musk to your (burner) number, then issue the password reset request. 2FA kicks in and sends 2FA request to mobile number on file, but it now goes to your number, not Elon.

QED

(I'm not saying this is what happened, just one possibility for a poorly designed process/system)

Gene Cash

At least they seem to understand they fucked up. They're at least not going "we take our customer's privacy so very seriously"

OTOH I abandoned Twitter at the beginning of the month when they randomized their CSS to kill adblockers. I just don't have the patience to deal with the torrent of ads.

Now hoping for *actual* full disclosure

Flywheel

I'm sure they'll give us all a summary of what happened when this is all over, but it would be useful if we could see the Full Disclosure report when it's published.

Lee D

GDPR lawsuit in 3.. 2... 1...

Velv

Last time I looked GDPR isn't applicable in the USA. Or the UK (oh, they haven't revoked it yet).

insider trading

Mike 125

"the attackers successfully manipulated a small number of employees and used their credentials to access Twitter's internal systems,"

This is an attack from inside the security model. This is equivalent to an Intel processor side channel attack.

*Some* employees will always have access to tools which permit account access, at the very least enabling a credential reset. *Some* can modify system code! If those employees go rogue, or stupid, then it's game over. There's no mystery to that.

SIM Swapping

thondwe

Good in depth blog over on Krebs on Security on this. Seems that "SIM Swapping" is a thing - basically persuade/bribe some mobile phone support/sales body to point a mobile number to a new SIM (As you would if you lost your phone, switched provider etc).

So if you're "forgot password/2FA" process involves reset via SMS... Social Engineering to get e-mail/twitter handle and mobile and SIM Swap and ...

Re: SIM Swapping

Anonymous Coward

SIM cloning costs around US$500 to buy the necessary tools.

The only thing to discourage their use is steep fines and jail time.

Avoid high profile targets and that soon pays for itself if you're prepared for the risk or minimise the risks you take.

Re: SIM Swapping

c1ue

Sim swapping isn't about tools - it is identifying the mobile telco provider and phone number that a target uses, then getting the telco to "recover" the phone number into a new sim.

This can be via social engineering the telco or just finding and paying off an employee with appropriate capability like a local store manager.

Lets hope Square

Chris the bean counter

Has better security

Karmic Justice for this incompetence

Phil Koenig

Not just one but apparently several Twitter employees were socially-engineered to share or compromise their admin credentials which have access to super high-profile accounts?

Is this some kind of bad joke?

Maybe it's karmic justice for being one of the top 3 enablers of the current POTUSCLOWN.

#DefundTwitter

Re: Karmic Justice for this incompetence

bombastic bob

social media is highly overrated, and the world really isn't how it's portrayed there.

I'd like to think that this could be a wakeup call for alleged 'twitter addicts' that (straw man) get all of their news, social interaction, and other information from twitter. If such people really exist, yeah...

as for me - yet another reason NOT to use Tw[a,i]tter.

There is Jackson standing like a stone wall. Let us determine to die,
and we will conquer. Follow me.
-- General Barnard E. Bee (CSA)