Lupa Kata Sandi? Klik di Sini

atau Masuk melalui

Belum Memiliki Akun Daftar di Sini


atau Daftar melalui

Sudah Memiliki Akun Masuk di Sini

Konfirmasi Email

Kami telah mengirimkan link aktivasi melalui email ke rudihamdani@gmail.com.

Klik link aktivasi dan dapatkan akses membaca 2 artikel gratis non Laput di koran dan Majalah Tempo

Jika Anda tidak menerima email,
Kirimkan Lagi Sekarang

Over 1,000 People at Twitter Have Ability to Aid Hack of Accounts

Translator

Tempo.co

Editor

Laila Afifa

24 July 2020 12:15 WIB

TEMPO.COSan Francisco - More than a thousand Twitter employees and contractors as of earlier this year had access to internal tools that could change user account settings and hand control to others, two former employees said, making it hard to defend against the hacking that occurred last week.

Twitter Inc and the FBI are investigating the breach that allowed hackers to repeatedly tweet from verified accounts of the likes of Democratic presidential candidate Joe Biden, billionaire philanthropist Bill Gates, Tesla Chief Executive Elon Musk and former New York Mayor Mike Bloomberg.

Twitter said on Saturday that the perpetrators "manipulated a small number of employees and used their credentials" to log into tools and turn over access to 45 accounts. On Wednesday, it said that the hackers could have read direct messages to and from 36 accounts but did not identify the affected users.

The former employees familiar with Twitter security practices said that too many people could have done the same thing, more than 1,000 as of earlier in 2020, including some at contractors like Cognizant.

Twitter declined to comment on that figure and would not say whether the number declined before the hack or since. The company was looking for a new security head, working to better secure its systems and training employees on resisting tricks from outsiders, Twitter said. Cognizant did not respond to a request for comment.

“That sounds like there are too many people with access,” said Edward Amoroso, a former chief security officer at AT&T. Responsibilities among the staff should have been split up, with access rights limited to those responsibilities and more than one person required to agree to make the most sensitive account changes. “In order to do cybersecurity right, you can’t forget the boring stuff.”

Threats from insiders, especially lower-paid outside support staff, are a constant worry for companies serving large numbers of users, cybersecurity experts said. They said that the greater the number of people who can change key settings, the stronger oversight must be.

Related coverage:

Twitter Says Some 130 Accounts Targeted in Cyber Attack This Week

STUMBLES

The former employees said that Twitter had gotten better about logging the activity of its people in the wake of previous stumbles, including searches of records by an employee accused last November of spying for the government of Saudi Arabia.

But while logging helps with investigations, only alarms or constant reviews can turn logs into something that can prevent breaches.

Former Cisco Systems Chief Security Officer John Stewart said companies with broad access need to adopt a long series of mitigations and “ultimately ensuring that the most powerful authorized people are only doing what they are supposed to be doing.”

Who exactly pulled off the hacking spree isn’t clear, but outside researchers such as Allison Nixon of Unit 221B say the incident appears linked to a cluster of cybercriminals who regularly traded in novelty handles – especially rare one-or-two character account names – that are treated a bit like the vanity license plates of the online world.

Although the public evidence tying the hacking to those was circumstantial, ultra-short Twitter handles were among the first to be hijacked.

In addition, the forums where those hackers were active have long been replete with boasts about having access to Twitter insiders, according to Nixon and Nick Bax, an analyst with StopSIMCrime, a group that lobbies for greater protection against “SIM swapping” – a phone number hijacking technique often used by these kinds of hackers.

Bax said he had seen reference on forums to “Twitter plugs” or “Twitter reps” – the terms used to describe cooperative Twitter employees – since as far back as 2017.

The potential involvement of low-level cybercriminals has particularly alarmed professionals because of the implication that a hostile government might be able to cause even greater havoc.

Access to accounts for national leaders was limited to a much smaller number of people after a rogue employee briefly deleted President Donald Trump’s account two years ago. That could explain why Biden’s account was hijacked but not Trump’s.

Twitter should expand the number of protected accounts, said former Twitter security engineer John Adams. Among other things, accounts with more than 10,000 followers should at least need two people to change key settings.

Security experts said they were worried that Twitter has too much work to do and too little time before the campaign for the Nov. 3 U.S. election intensifies, with potential inference domestically and from other countries.

Said Ron Gula, a cybersecurity investor who co-founded network security company Tenable, “The question really is: Does Twitter do enough to prevent account takeovers for our presidential candidates and news outlets when faced with sophisticated threats that leverage whole-of-nation approaches?”

 

On a call to discuss company earnings on Thursday, Twitter Chief Executive Jack Dorsey acknowledged past missteps.

“We fell behind, both in our protections against social engineering of our employees and restrictions on our internal tools,” Dorsey told investors.

REUTERS



Coordinating Ministry for Economy's Website Allegedly Hacked

50 hari lalu

Coordinating Ministry for Economy's Website Allegedly Hacked

The official website of the Indonesian Coordinating Ministry for Economic Affairs was believed to have been hacked.


Cyber Attacks: Protecting People's Health Data an Urgent Priority

14 Januari 2024

Cyber Attacks: Protecting People's Health Data an Urgent Priority

As cyber attacks increase, healthcare providers risk a loss of patient trust if they cannot guarantee information security.


Social Media Platform X Back Up After Global Outage

21 Desember 2023

Social Media Platform X Back Up After Global Outage

Social media platform X, formerly known as Twitter, was restored globally early Thursday.


Malaysia's Blueprint to Block Cyber Attacks

13 Desember 2023

Malaysia's Blueprint to Block Cyber Attacks

Malaysia faces a surge in cyber attacks, prompting the need for a national cybersecurity commission.


BSSN Records 361 Million Cyber Attacks in Indonesia

17 November 2023

BSSN Records 361 Million Cyber Attacks in Indonesia

The National Cyber and Encryption Agency (BSSN) reported 361 million traffic anomalies or cyber attacks in Indonesia from Jan. 1 to Oct. 26, 2023.


Japan, 8 ASEAN Countries Agree to Bolster Cybersecurity Cooperation

6 Oktober 2023

Japan, 8 ASEAN Countries Agree to Bolster Cybersecurity Cooperation

Japan and ASEAN eight member countries agreed on Thursday, Oct. 5, to boost cybersecurity cooperation in the private sector.


BSSN Talks of Cyber Threats to Election

26 September 2023

BSSN Talks of Cyber Threats to Election

The National Cyber and Encryption Agency (BSSN) spokesman Ariandi Putra says his side has identified at least two cyber threats related to elections.


AJI Indonesia's Instagram Account Hacked

5 September 2023

AJI Indonesia's Instagram Account Hacked

The Alliance of Independent Journalists or AJI Indonesia confirms today that it is losing access to its Instagram account @aji.indonesia.


Immigration DG Denies Data Breach of 34 Million Indonesian Passports

12 Juli 2023

Immigration DG Denies Data Breach of 34 Million Indonesian Passports

Immigration Director-General Silmy Karim rebuts reports of the alleged data breach of 34 million Indonesian passports.


Meta's 'Friendly' Threads Collides with Unfriendly Internet

9 Juli 2023

Meta's 'Friendly' Threads Collides with Unfriendly Internet

Mark Zuckerberg has pitched Meta's Twitter copycat app, Threads, as a "friendly" refuge for public discourse online.