Reply to post: insider trading

Twitter hackers busted 2FA to access accounts and then reset user passwords

Mike 125

insider trading

"the attackers successfully manipulated a small number of employees and used their credentials to access Twitter's internal systems,"

This is an attack from inside the security model. This is equivalent to an Intel processor side channel attack.

*Some* employees will always have access to tools which permit account access, at the very least enabling a credential reset. *Some* can modify system code! If those employees go rogue, or stupid, then it's game over. There's no mystery to that.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon