{"id":361521,"date":"2020-07-27T14:10:11","date_gmt":"2020-07-27T12:10:11","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=361521"},"modified":"2020-07-27T14:11:23","modified_gmt":"2020-07-27T12:11:23","slug":"twitter-security-issues-caused-by-extensive-access-to-user-accounts","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/361521-twitter-security-issues-caused-by-extensive-access-to-user-accounts.html","title":{"rendered":"Twitter security issues caused by extensive access to user accounts"},"content":{"rendered":"<p>Twitter Inc. has struggled for years to police the growing number of employees and contractors who have the ability to reset users\u2019 accounts and override their security settings, a problem that Chief Executive Officer Jack Dorsey and the board were warned about multiple times since 2015, according to former employees with knowledge of the company\u2019s security operations.<\/p>\n<p>Twitter\u2019s oversight over the 1,500 workers who reset accounts, review user breaches and respond to potential content violations for the service\u2019s 186 million daily users have been a source of recurring concern, the employees said.<\/p>\n<p>The breadth of personal data most of those workers could access is relatively limited &#8212; including such things as Internet Protocol addresses, email addresses and phone numbers &#8212; but it\u2019s a starting point to snoop on or even hack an account, they said.<\/p>\n<p>The controls were so porous that at one point in 2017 and 2018 some contractors made a kind of game out of creating bogus help-desk inquiries that allowed them to peek into celebrity accounts, including Beyonce\u2019s, to track the stars\u2019 personal data including their approximate locations gleaned from their devices\u2019 IP addresses, two of the former employees said.<\/p>\n<p>Concerns about Twitter\u2019s ability to protect user data deepened this month after hackers hijacked the accounts of some of its most famous users, including political leaders, business titans and celebrities, as part of an apparent cryptocurrency scam.<\/p>\n<p>The pressure on Twitter to protect its users isn\u2019t limited to the personal data it collects on them &#8212; which is minimal compared to some other social media sites &#8212; but extends to the influence its users wield, especially world leaders or the political dissidents who oppose them.<\/p>\n<p>While federal and internal investigations are ongoing, Twitter has said that hackers somehow duped employees to gain access to the hacked accounts.<\/p>\n<p>The attackers contacted at least one Twitter employee over the phone in an effort to obtain security information that would help them access Twitter\u2019s internal user-support tools, according to people familiar with the investigation.<\/p>\n<p>Twitter required employees to take an online security training course last week, which covered a number of phishing techniques including phone calls, the people added.<\/p>\n<p>A Twitter spokeswoman said the company conducts regular security training \u201cin line with our commitment to protecting the privacy and security of the people we serve.\u201d<\/p>\n<p>The spokeswoman disputed the former employees\u2019 characterization of the company\u2019s oversight of user accounts, while claiming the company has tools to \u201cstay ahead of threats as they evolve.\u201d<\/p>\n<p>Twitter is consistently improving its security apparatus with new tools, she said, and cited recent privacy-related programs that have bolstered user protections, including new employee training.<\/p>\n<p>She confirmed that Twitter\u2019s oversight of user accounts includes 1,500 full-time employees and contractors, but said \u201cwe have no indication that the partners we work with on customer service and account management played a part here,\u201d referring to Twitter\u2019s recent account breach.<\/p>\n<p>Employees and contractors have access only to the tools they need to do their jobs, which includes permissions to execute password resets to accounts, the spokeswoman said. Access also comes with \u201cextensive security training and managerial oversight,\u201d she said.<\/p>\n<p>Dorsey, addressing the recent hack, told investors this week that the company \u201cfell behind, both in our protections against social engineering of our employees and restrictions on our internal tools.\u201d<\/p>\n<p>This account is based on interviews with four former Twitter security employees, in addition to more than a half dozen other people close to Twitter.<\/p>\n<p>According to the former security employees, Twitter management has often dragged its heels on upgrades to information security controls while prioritizing consumer products and features, a source of tension for many businesses.<\/p>\n<p>Efforts to better govern Twitter\u2019s user-support staff and contractors have also gotten short shrift, resulting in a workplace where too many people have access to too many powerful tools, the former employees said.<\/p>\n<p>Even with some basic tracking systems in place, contractors have found workarounds to explore details about former lovers, politicians, favorite brands and celebrities, they added.<\/p>\n<p>In the July 15 attack, 130 accounts were compromised &#8212; including those belonging to Barack Obama, Joe Biden, Jeff Bezos and Elon Musk &#8212; and account data was stolen from eight of those, Twitter said without identifying the accounts.<\/p>\n<p>Tweets were sent from the hijacked accounts promising followers who sent Bitcoin to a specific address would be paid back double &#8212; or their support would contribute to pandemic relief efforts.<\/p>\n<p>Twitter acknowledged that several of its employees were the targets of a malicious campaign to acquire credentials for its internal system, \u201conly available to our internal supports team,\u201d according to a July 17 statement.<\/p>\n<p>An obscure hacking collective that is devoted to buying and selling short and clever Twitter and Instagram usernames has claimed to have been involved in the attack, which is being investigated by the FBI.<\/p>\n<p>Concerns over insider access to Twitter accounts were brought to Twitter\u2019s board of directors almost annually during a period from 2015 to 2019, only to be deferred for other priorities including other cybersecurity programs, according to two of the former security officials.<\/p>\n<p>Those presentations weren\u2019t always presented as an urgent threat to Twitter security or its users\u2019 privacy, according to four people familiar with the board\u2019s presentations.<\/p>\n<p>Security programs, like shoring up the system that houses Twitter\u2019s backup files or enhancing oversight of the system used to monitor contractor activity were, at times, shelved for engineering products designed to enhance revenue, according to two of the former employees.<\/p>\n<p>Some of Twitter\u2019s contractors that became proficient in snooping on Beyonce\u2019s and other celebrity accounts were employed by Cognizant Technology Solutions Corp. in as many as a half-dozen locations, the two former former employees said.<\/p>\n<p>Cognizant, which continues to work with Twitter, declined to comment. A representative for Beyonce didn\u2019t respond to a request for comment. Twitter declined to answer questions about access to Beyonce\u2019s account.<\/p>\n<p>Through a company spokeswoman, Twitter\u2019s board declined to comment.<\/p>\n<p>Snooping on accounts wasn\u2019t considered a major security concern among Twitter executives, even as the company\u2019s dependence on contractors to handle back-office support functions has grown in the last half decade, according to two of the former members of Twitter\u2019s security team.<\/p>\n<p>Spying on accounts happened so often that members of Twitter\u2019s full-time security team in the U.S. struggled to keep track of the intrusions, according to the two former employees.<\/p>\n<p>While some of the contractors were caught and fired, others started beating the formal logging system by creating fraudulent tickets that claimed something was wrong with a user account, only to grab that complaint themselves to resume their escapade, according to the employees.<\/p>\n<p>\u201cVery few companies understand how vulnerable their operations are to compromise as they expand outside of their headquarters,\u201d said Paul Ortiz, a supply chain security consultant. \u201cThis risk exponentially increases if third-party contract workers are introduced into the equation.\u201d<\/p>\n<p>Last week\u2019s attack was the latest in a string of embarrassing security breaches at Twitter in recent years, some of them involving internal access to accounts.<\/p>\n<p>In November 2017, President Donald Trump\u2019s account was temporarily deleted as an act of rebellion by a customer support employee on his last day at the company.<\/p>\n<p>In August 2019, Dorsey\u2019s account was hacked and used to post anti-Semitic messaging. Twitter blamed Dorsey\u2019s mobile carrier.<\/p>\n<p>Last year, the Justice Department charged a pair of former Twitter employees for allegedly spying for Saudi Arabia and abusing their access to collect the private data of prominent Saudi critics.<\/p>\n<p>Twitter\u2019s intrusion highlights a security failing common among high-flying startups and younger tech companies, according to\u00a0<a href=\"https:\/\/www.cyberteamsix.net\/patrickwesterhaus\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Patrick Westerhau<\/strong>s<\/a>, a former FBI cyber and cryptocurrency investigator.<\/p>\n<p>\u201dThe problem we see over and over again with technology companies that are hyper-focused on growth and revenue is an immature framework and general lack of concern for security, third-party risk and anti-fraud controls,\u201d said Westerhaus, chief executive officer of\u00a0<strong><a href=\"https:\/\/www.cyberteamsix.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Cyber Team Six<\/a><\/strong>, a security company.<\/p>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/internet\/361203-twitter-reports-big-surge-in-daily-users.html\" rel=\"bookmark\">Twitter reports record surge in daily users<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Twitter Inc. has struggled for years to police the growing number of employees and contractors who have the ability to reset users\u2019 accounts and override their security settings, a problem that Chief Executive Officer Jack Dorsey and the board were warned about multiple times since 2015, according to former employees with knowledge of the company\u2019s security operations.<\/p>\n","protected":false},"author":341034,"featured_media":277003,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[15227,8197,405,16784],"class_list":["post-361521","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cybersecurity","tag-online-security","tag-twitter","tag-twitter-hack"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/361521"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341034"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=361521"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/361521\/revisions"}],"predecessor-version":[{"id":361527,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/361521\/revisions\/361527"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/277003"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=361521"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=361521"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=361521"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}