Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They social engineered access to a Twitter employees internal account, not the individual end users affected.


I understand, but that sort of behaviour should have been thwarted quickly by their security team or policies setup against abuse.


Yep, for one, you shouldn’t be able to just hand over your credentials to other people and they can immediately start doing stuff in your systems.

Also, the ability to impersonate people (not just celebrities) should require at least manual approvals. Not sure why this ability even exists.

The original speculation (that it was an API vulnerability) is actually easier to stomach.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: