Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

third-party apps are incredibly common and usually have unrestricted access to post or alter profiles.

I'm not sure if I buy the internal tool angle here.



Yes, but there's a big difference between random account getting hacked and verified world leader account getting taken over by compromising an internal Twitter system?


I don't think Twitter ever disclosed whether an internal system was compromised or not (if they were, please inform!)

Third party app developers are more likely to have been. It's also likely for a third-party dev to have bad intentions.

I periodically review and make sure to disable third-party app access to my Twitter accounts. Who's to say your average celeb is likely to do that?


https://www.theverge.com/2020/7/15/21326656/twitter-hack-exp...

> We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools.

It was social engineering, but still access to internal tools which made this bypass possible.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: