Twitter Disables SMS-to-Tweet Feature After Its CEO Got Hacked Last Week (zdnet.com) 20
Twitter is disabling the ability to send tweets via SMS messages after an incident last week when the company's CEO Twitter account got hacked via this feature. From a report: The social network said the move is only temporary, but did not provide a timeline for the feature's reactivation. Twitter blamed the whole issue on mobile networks and "vulnerabilities that need to be addressed by mobile carriers."
Yes the mobile networks have vulnerabilities (Score:5, Interesting)
Yes the mobile networks have vulnerabilities, but it was your dumb ass that treated them as secure in the first place.
Re: (Score:1)
I'm not so sure it was an accident. This seems like a good way to try to force the mobile carriers' hands by making it a conspicuous public issue that wealthy megacorp owners are likely to sympathize with.
Re: (Score:2)
Yet big tech trusted wide open mobile networks?
Re: (Score:3)
Except it wasn't. It was done by breaching the mobile gateway service they used, not the mobile network itself (i.e., they didn't clone a SIM card or hack SS7 or anything like that).
Instead, they breached the service that was handling the SMS to twitter interface and did things that way.
Mobile networks are insecure, yes, but it wasn't that insecurity that was the problem. It was the gateway
Re: (Score:2)
need better network security ! (Score:2)
they need to sort out their network security
No DNSSEC so many countries and ISP's intercept their network traffic and place a TLS tap (MITM)
No TLS security by allowing client side TLS renegotiation again aiding the interception and no way to force TLS 1.3
No DANE for their email (even though their email platform can support this)
time to get on it twitter engineering before the advertisers realise that traffic can be faked and intercepted
fake vs intercepted (Score:4, Insightful)
note that as Twitter is a network whose main purpose is to shout as widely as possible your opinions,
the *faked* part is much more critical (somebody trying to pretend being you, in order to shout things in your name) than the *intercepted* part (nothing impressive in trying to steal information that is going to be made widely public anyway. It would be like a spy trying to bug... somebody shouting in a megaphone)
Re: (Score:1)
Re: (Score:2)
Allowing countries to do MITM attacks might actually be a feature for Twitter, as it allows them to continue operating in those countries as opposed to being banned.
Re: need better network security ! (Score:2)
Having everything explicitly banned is better than the illusion of freedom we currently tolerate.
I have a real problem with American business that operate on a completely different set of principles than the American people. Not that We the People are not without our faults, we do have this weird assumption of individual expression being an inalienable right.
Ya know ... (Score:4, Insightful)
Re: (Score:3)
It's sort of the security team's job to keep track of high profile accounts and secure them accordingly. It's not priority #1 but something like priority 3b. Lack of ability to keep tabs on 3b is indicative of lack of ability to do anything other than keep tabs on priority #1. This kind of blind spot would indicate that either somebody is sleeping on the job or there are many more unknown unknowns out there than previously thought. I would not want to be the Twitter CSO right now.
Re: (Score:2)
More likely the security team brought this up. But Twitter decided tweeting via SMS is more important than security.
Re: (Score:2)
More likely the security team brought this up. But Twitter decided tweeting via SMS is more important than security.
Being able to update a micro blog via SMS without access to the internet was Twitter's whole point originally. Turning SMS off globally seems like overkill. For most accounts, it's not worth the effort to clone their phone in order to impersonate them. They'd be better off adding the ability to disable less secure posting methods on a per-account basis makes more sense for high profile accounts.
Re: (Score:2)
So... Twitter Turned Off Twitter? (Score:4, Interesting)
Re: (Score:3)
Am I the only person who seems to remember that Twitter started life as an SMS repeater/broadcaster?
Yes, in all the world you are the only one to remember that.
Re: (Score:2)
No. I remember it, too. Twitter was like a brand-new thing and debuting at some tech conference, and that was literally how everyone was using it at the time.
Tweet via SMS was useful in emergencies (Score:1)
Twitter was a key part of my emergency communication plan for Hurricane Dorian; I had planned to rely on it to to reach people in case the web (mobile and wired) became unusable for some reason, including congestion during an emergency. SMS will generally get through even if data connectivity is broken, and with a single SMS I could broadcast my status to people who needed to see it, just by issuing a tweet. This worked without my people needing to create accounts or register anywhere, as they could just vi
Caller ID (Score:5, Interesting)
Is that how Twitter "validates" origin ?
Regardless what happened. Twitter "security" team are fools. How many times did this happen now ? 4 ?
You would think that with that much money can buy you at least decent security team...or I don't know.. steal couple guys from facebook.