Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So many accounts are affected, this seems to be a system-level hack rather than a compromise of individual accounts.

Someone has found a way to post a tweet from any account they like?



The email address associated with the account(s) appear to have been changed as well: https://twitter.com/sniko_/status/1283485972286656517


I do not think that a 3rd party tweet scheduling program has been hacked, because the tweets say they have been sent by “Twitter Web App”. Maybe the new feature on twitter.com to schedule tweets has a security vulnerability?


One theory is it's a tweet scheduling platform, rather than Twitter itself that was hacked.


No. Clicking into a tweet shows you which app was used to post it. https://help.twitter.com/en/using-twitter/how-to-tweet#sourc...

These tweets are showing up as being posted from the Twitter web interface.


Tweets posted through Twitter's ads platform, even non-ads scheduled tweets, will show up as normal twitter web posts.

And approved partners can use the corresponding API to post this way.


I've not checked twitter api docs but I've seen stuff like "Posted from: Zombo smart fridge" and was under the impression an app could fill that field in with whatever they like.


No, it's the name of the app, which undergoes Twitter review.



It is now. Twitter has made all new apps by application only. A bunch of folks lost their “just for one” ones last year to this.


Its not hard to fathom that someone who was able to pull off a hack like this could have also found a way to mess with the metadata there.


It kinda is, if the premise is "they hacked a 3rd party app"


Idle speculation isn't very helpful.


Parent takes the posted-from metadata as absolute truth.

I say it can't be relied upon when an active & involved hack is underway.

You provide nothing of value. What do you think this entire thread is, but for idle speculation?


But is it necessarily true that the authentication token was generated with the same app used to post the tweets?


Suggestion on Twitter is a third-party app that has write access to the accounts was compromised.


Might be a third party client, browser extension, insider threat... not necessarily a compromise of the Twitter backend.


Some folks are saying some of these accounts had 2FA, so can be the case but I guess if it was a system thing, we might have seen tweets from more prominent accounts.


You would think they would do something with Trump if it was arbitrary accounts. But maybe his has additional protections


I believe I read something (trying to find it) about Twitter internally having additional protections on Trump's account. Only a handful of people within Twitter can touch it.


It was likely after this incident:

http://www.bbc.com/news/world-us-canada-41854482


They're clearly trying to avoid the risk of being tracked. For example, they could have done stock manipulation and made more money. Trump is someone with the power and craziness to spend a hundred million tracking you down and literally dropping bombs on your head. So it'd be poor risk management to go after his account.


I agree, but only until the bombings, I mean he's the most anti-war president in living memory.


He killed a general from an opposition nation state...


Bombing != war. Trump administration has had plenty of people killed by drone strikes.

https://www.washingtonpost.com/world/iran-strike-live-update...


yup, trump hates war because it's bad for the businesses he's in (like real estate and luxury branding), but drone strikes don't have that downside.


https://www.nytimes.com/2017/04/13/world/asia/moab-mother-of...

> President Trump has bestowed additional authority on the Pentagon in his first months in office, which the military has argued will help it defeat the Islamic State more speedily. Mr. Trump did not say whether he had personally approved Thursday’s mission.

> “What I do is I authorize my military,” Mr. Trump said after a meeting with emergency workers at the White House. He called the bombing “another very, very successful mission.”

I think we can imagine being more anti-war than Trump.

Do you remember Jimmy Carter? Being anti-war means deescalation, diplomacy and solving problems without violence.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: