Watching the slow motion Twitter trainwreck is just amazing. I hope we get an amazing postmortem out of this, but chances are their security team is just incompetent/understaffed and this just boils down to someone's credentials being stolen and them failing at containment.
-
Show this thread
-
Short of a nation state level attack, there's no reason this should've taken more than 5 minutes to contain, TBQH.
2 replies 2 retweets 32 likesShow this thread -
Word is this was a compromised user admin panel (screenshots are floating around). If so, it should've taken 40 seconds to disable that thing entirely, then 15 minutes to dig through the audit logs (they have audit logs, right????) and undo the damage.
6 replies 3 retweets 40 likesShow this thread -
Replying to @marcan42
40s? I wouldn’t estimate anyone the ability to deploy that quickly, let alone do root cause analysis to figure out what the leak actually is in that span of time.
1 reply 0 retweets 0 likes -
Replying to @jon_roelofs
I would expect them to have a killswitch for internal admin tools in case of abuse.
2 replies 0 retweets 1 like -
Replying to @marcan42
I’m still surprised. It takes time to detect these things & conjure meetings to decide proper course of action. Consider how such a killswitch could be abuse, and then consider what process would be put in place to mitigate such abuse... and only then weigh it against this.
1 reply 0 retweets 0 likes -
Replying to @jon_roelofs
Meetings? What? It's a killswitch. The whole point of a killswitch is to stop dangerous things from running amok. If your process requires meetings to respond to this kind of incident, your management has gone insane.
2 replies 0 retweets 2 likes -
Replying to @marcan42
broken management or not, how do you balance the ability to cripple production systems with these features behaving as a killswitch for legit emergencies? (I’ve seen plenty of broken management, and that may bias how I’d perceive this)
1 reply 0 retweets 0 likes
Again, it's a killswitch *for an admin tool*. There is zero user impact to using it, and no excuse for it to not exist. At most some support tickets might take longer to resolve. No reason not to have a ton of safety nets around internal tools that can take over accounts.
-
-
Replying to @marcan42
maybe I’m just tainted by broken, terrible systems (not naming names here)
0 replies 0 retweets 0 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.