So yeah, it was just compromised internal credentials with the ability to take over user accounts. This is a big no-no and clearly the controls around those internal tools were woefully inadequate. This points to deficient security culture inside Twitter.https://twitter.com/TwitterSupport/status/1283591848729219073 …
-
Show this thread
-
Also, that the internal account takeover happened at *all*, presumably remotely, is inexcusable in 2020. If your corporate authentication does not require non-spoofable 2FA (e.g. U2F/WebAuthn) to achieve this level of access, you are doing many things wrong.
2 replies 6 retweets 46 likesShow this thread -
And apparently Twitter is retaliating against users tweeting screenshots of the internal tool (even censored of private info), which speaks volumes as to their priorities during this kind of massive security incident.
1 reply 10 retweets 48 likesShow this thread -
Remember this is apparently a *support tool*. The issue of insider access from *engineers* is a tricky one, because ultimately engineers need to be able to engineer the system. It's possible, but tricky, to build sufficient controls around engineering procedures.
2 replies 0 retweets 17 likesShow this thread -
But support tools? There should be high-level overrides for all of that stuff, and auditing up the wazoo, at the very least a kill switch that is always accessible to on-call engineers/security team. It should've taken minutes to identify and lock out the attack.
1 reply 1 retweet 23 likesShow this thread -
There is absolutely no reason why anything someone working for Twitter support does shouldn't be immediately identifiable, controllable, and reversible by someone at a higher level, on-call, as soon as it happens. We have access hierarchies for a reason.
1 reply 0 retweets 22 likesShow this thread -
Replying to @marcan42
lol I hadn’t heard of thishttps://www.wired.com/story/twitter-insiders-saudi-arabia-spy/ …
1 reply 0 retweets 2 likes
It's like they didn't learn anything since that time.
-
-
Come on, it's not like it was a pattern or anything.https://www.cnbc.com/2017/11/30/former-twitter-employee-who-deleted-trumps-account-it-was-a-mistake.html …
0 replies 0 retweets 1 likeThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.