News: 1605680768

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

No, the creator of cURL didn't morph into Elon Musk and give away Bitcoins. But his hijacked Twitter page tried to

(2020/11/18)


The creator of cURL reassured The Reg on Tuesday that he's not a billionaire rocket man giving away Bitcoins, no matter what his Twitter account claimed.

Daniel Stenberg, who maintains the widely used Swiss army-knife of network data transfer tools, had his verified Twitter account hijacked by person or persons unknown, its name and avatar was changed to that of Elon Musk's, and it was used to peddle a Bitcoin scam.

Speaking to El Reg shortly before he finally managed to convince Twitter to give him back control of his profile, Stenberg said he was “pretty confident” that none of his cURL work has been compromised or had malicious code sneaked into it. The hack appears very similar to a widespread one earlier this year in which Musk’s Twitter account was commandeered to con marks into handing over their stocks of the cryptocurrency in exchange for more in return.

“No, I have no idea how they got into my account,” Stenberg told The Register . “I feel pretty confident that they did not go through or breach any my local machines/accounts and that this is entirely done on the remote Twitter account. Other than that, it is a mystery to me how this happened.”

Security much? Twitter should have had a CISO to prevent Bitcoin hack, says US state financial body [1]READ MORE

Writing on his website, Stenberg [2]said someone seized control of his Twitter account, which has 24,000 followers, while he was busy debugging cURL code – that person rapidly switched the account’s registered email address and password to lock him out before turning it into a Bitcoin scam.

“At 0042 in the early morning of November 16 (my time, Central European Time), I received an email saying that 'someone' logged into my twitter account @bagder from a new device. The email said it was done from Stockholm, Sweden and it was 'Chrome on Windows'. I live in Stockholm,” wrote Stenberg.

In short order he was forcibly signed out of all his other Twitter sessions, and realized that he had been hacked. At 0050 he reported it to Twitter; at 0051 he provided additional verifying information. He wasn't given back his account by Twitter until nearly two days later.

"At 20:56 on November 17 I received the email with the notice the account had been restored back to my email address and ownership," Stenberg wrote.

The digital joyride appears to have coincided with Bitcoin reaching $17,000 for one coin, a high it has not reached since January 2018.

Sorry for that little interruption. I noticed the hihack immediately and reported to twitter it after a mere 8 minutes, then I had to wait 45 hours and now I'm here again. [3]https://t.co/vqSLZvvNVb [4]pic.twitter.com/JBc4tfqD0Y — Daniel Stenberg (@bagder) [5]November 17, 2020

The cURL maintainer speculated: “One of the more puzzling things that I can’t stop thinking about is how I got the notice email from Twitter saying someone had logged into my account *from Stockholm*. I mean, what are the odds that someone trying to hack my account would do that from an IP range that is geolocated in the same general area as I am? But I can't seem to make any sensible conclusions based on that, it just seems... too unlikely to be a coincidence.”

Indeed it may not be. A group of Dutch hackers who said they guessed US president Donald Trump’s Twitter password earlier this year [6]reckoned that the site enforces geo-based controls as a form of authentication, having found and bypassed that feature themselves on Trump’s account by using a VPN.

For now, don’t transfer Bitcoins to strangers on Twitter. Not even if it’s an electric car salesman telling you to. ®

Get our [7]Tech Resources



[1] https://www.theregister.com/2020/10/15/twitter_hack_report_new_york_post_censorship/

[2] https://daniel.haxx.se/blog/2020/11/16/i-lost-my-twitter-account/

[3] https://t.co/vqSLZvvNVb

[4] https://t.co/JBc4tfqD0Y

[5] https://twitter.com/bagder/status/1328818092609245185?ref_src=twsrc%5Etfw

[6] https://www.theregister.com/2020/10/23/trump_twitter_account_no_mfa/

[7] https://whitepapers.theregister.com/

Gah

W.S.Gosset

Now I've got that old internet animation stuck in my head.

Bagder Bagder Bagder Bagder, Bagder Bagder Bagder Bagder

...Sanke! Sanke!

Bagder Bagder etc.

Pointless

chuBb.

I still don't get why twitter exists

Other than to facilitate scams, bullshit and provide skiddies targets

Also what's the point of a char limit if you can post wall of text images...

Re: Pointless

werdsmith

It exists so people can create fictional anecdotes to trigger outrage and then wallow in an echo chamber of similarly outraged people. And also so people can pointlessly whinge eternally about anything, usually governments.

It also exists so people can get into “discussions “ and then cowardly block people when it doesn’t go their way. They can then return to their echo chamber and have their false beliefs reinforced.

It’s a cess pit, but a less noxious cess pit than faecebook.

Re: Pointless

werdsmith

I forgot the billion times recycled memes and gifs of actors pulling faces that have no relevance to the conversation.

Re: Pointless

veti

You could say the same of the Web.

Twitter is no worse than any other forum. Anything that sticks around long enough, and attracts attention, gets abused sometimes.

That's what scumbags do: they study the environment and find its weaknesses.

Re: Pointless

Anonymous Coward

It exists so people can get news from other than the censored, approved official mainstream media outlets.

You still need a brain to seperate the wheat from the chaff, though.

Re: Pointless

werdsmith

The wheat from the chaff. Like mining for diamonds in a cat litter tray.

electric car salesman

Fruit and Nutcase

any relation to an electric carpet cleaner salesman?

About the Stockholm geolocation

Jenny with the Axe

It's not hard to figure out that Daniel lives in Stockholm.

If I wanted to do this, I'd get a free trial account with any provider of VPNs that has endpoints in the area where the mark lives. Or even just an AWS EC2 instance hosted in Stockholm would probably work. Or a previously compromised random PC that is in the right area.

Re: About the Stockholm geolocation

W.S.Gosset

Easier and free:

Twiddle your Tor config file to force it to only exit in Sweden. Chances are you'll pop out in Stockholm.

(I use this trick if I want to to watch BBC TV in/from Australia : their iPlayer site bounces you if your IP is ex-UK.)

Bitcoin spam

John Sager

Definitely on the up ATM. I'm getting quite a few and some scrote used my email address as the 'From' so I got lots of bounces from MTAs all over the globe ☹️

Dave 126

Depends how much pressure and heat you apply to the cat...

In Mexico we have a word for sushi: bait.
-- Josi Simon