Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I would be really surprised if they did not have audit trails. What gives you the impression they did not? The suspicion is that the credentials were stolen via social engineering. I wonder if employees needed 2FA to log in to these tools.


> The attackers successfully manipulated a small number of employees and used their credentials to access Twitter’s internal systems, including getting through our two-factor protections.

https://blog.twitter.com/en_us/topics/company/2020/an-update...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: