Watching the slow motion Twitter trainwreck is just amazing. I hope we get an amazing postmortem out of this, but chances are their security team is just incompetent/understaffed and this just boils down to someone's credentials being stolen and them failing at containment.
-
Show this thread
-
Short of a nation state level attack, there's no reason this should've taken more than 5 minutes to contain, TBQH.
2 replies 2 retweets 32 likesShow this thread -
Word is this was a compromised user admin panel (screenshots are floating around). If so, it should've taken 40 seconds to disable that thing entirely, then 15 minutes to dig through the audit logs (they have audit logs, right????) and undo the damage.
6 replies 3 retweets 40 likesShow this thread -
Replying to @marcan42
40s? I wouldn’t estimate anyone the ability to deploy that quickly, let alone do root cause analysis to figure out what the leak actually is in that span of time.
1 reply 0 retweets 0 likes -
Replying to @jon_roelofs
I would expect them to have a killswitch for internal admin tools in case of abuse.
2 replies 0 retweets 1 like -
Replying to @marcan42
I’m still surprised. It takes time to detect these things & conjure meetings to decide proper course of action. Consider how such a killswitch could be abuse, and then consider what process would be put in place to mitigate such abuse... and only then weigh it against this.
1 reply 0 retweets 0 likes -
Replying to @jon_roelofs
Meetings? What? It's a killswitch. The whole point of a killswitch is to stop dangerous things from running amok. If your process requires meetings to respond to this kind of incident, your management has gone insane.
2 replies 0 retweets 2 likes
The only abuse you could inflict with the killswitch is delaying account admin actions, which is an entirely reasonable response to abuse and a feature you must absolutely implement if you have user access tools like this.
-
-
Replying to @marcan42 @jon_roelofs
It's common sense that any time you're mutating user data or viewing private user data, you audit the hell out of everything so you can immediately respond to abuse and revert it, and lock out the attackers. They should've had alerts for this kind of thing too.
0 replies 0 retweets 5 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.