Watching the slow motion Twitter trainwreck is just amazing. I hope we get an amazing postmortem out of this, but chances are their security team is just incompetent/understaffed and this just boils down to someone's credentials being stolen and them failing at containment.
-
-
Word is this was a compromised user admin panel (screenshots are floating around). If so, it should've taken 40 seconds to disable that thing entirely, then 15 minutes to dig through the audit logs (they have audit logs, right????) and undo the damage.
Show this thread -
Worth mentioning that if these tools didn't exist, it's almost certainly because management didn't let security staff build them, or didn't care, or they're understaffed, not because of sec staff themselves. This is Twitter being incompetent as an organization, not individuals.
Show this thread
End of conversation
New conversation -
-
-
Reasons you shouldn't go light on your security or ops teams: exactly this
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.