So yeah, it was just compromised internal credentials with the ability to take over user accounts. This is a big no-no and clearly the controls around those internal tools were woefully inadequate. This points to deficient security culture inside Twitter.https://twitter.com/TwitterSupport/status/1283591848729219073 …
-
Show this thread
-
Also, that the internal account takeover happened at *all*, presumably remotely, is inexcusable in 2020. If your corporate authentication does not require non-spoofable 2FA (e.g. U2F/WebAuthn) to achieve this level of access, you are doing many things wrong.
2 replies 6 retweets 46 likesShow this thread -
Replying to @marcan42
FIPSmode Squad Retweeted Jason Koebler
well, reportedly, it wasn't stolen/leaked credentials, it was attackers paying off someone inside the organizationhttps://twitter.com/jason_koebler/status/1283593252202074115 …
FIPSmode Squad added,
Jason KoeblerVerified account @jason_koeblerOK, we talked to another hacker. Were able to confirm how they got accounts: Twitter employee used internal tool to change email addresses associated with accounts. Twitter seems to have just confirmed this in tweets as well https://www.vice.com/en_us/article/jgxd3d/twitter-insider-access-panel-account-hacks-biden-uber-bezos …Show this thread1 reply 0 retweets 1 like -
Replying to @anthonypants
In that case, even more reason that they should've been able to catch this person and control the situation before they could even leave the building. But the multitude of screenshots of internal Twitter admin tools makes me think this wasn't just one logged in person.
1 reply 0 retweets 3 likes -
Replying to @marcan42 @anthonypants
Remember everyone is working from home. The compromised employee(s) are all remote, possibly sitting with the attackers.
1 reply 0 retweets 0 likes
Good point, though that sounds even more ridiculous on the part of the insider.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.