Watching the slow motion Twitter trainwreck is just amazing. I hope we get an amazing postmortem out of this, but chances are their security team is just incompetent/understaffed and this just boils down to someone's credentials being stolen and them failing at containment.
-
-
Worth mentioning that if these tools didn't exist, it's almost certainly because management didn't let security staff build them, or didn't care, or they're understaffed, not because of sec staff themselves. This is Twitter being incompetent as an organization, not individuals.
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
It would surprise the shit out of me if they have audit logs.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
You know as well as me that not everybody is Google :P
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Making all the verified users unable to post is actually the best solution they could've chosen, in my unverified opinion.
-
Nah, their solution has the one fault that they didn't stop blue checkmarks from posting forever
End of conversation
New conversation -
-
-
40s? I wouldn’t estimate anyone the ability to deploy that quickly, let alone do root cause analysis to figure out what the leak actually is in that span of time.
-
I would expect them to have a killswitch for internal admin tools in case of abuse.
- Show replies
New conversation -
-
-
Vice seem to be saying someone on the inside got paid.https://www.vice.com/en_us/article/jgxd3d/twitter-insider-access-panel-account-hacks-biden-uber-bezos …
-
Doesn't really change the fact they should've been able to lock them our quickly, though.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.