Graham Ivan Clark, Onel de Guzman and Michael Calce. These three names will go down in the history of internet commerce, right alongside Jack Dorsey, Mark Zuckerberg and Jeff Bezos.
Were all familiar with the high-profile entrepreneurs who gave us the tools and services that underpin our digital economy. However, Clark, de Guzman and Calce are equally notable as leading members of the Hall of Fame of script kiddies youngsters who precociously shed light on the how these same tools and services are riddled with profound privacy and security flaws.
The trouble is Clark, 17, of Tampa, Florida, is teaching us much the same lessons in the summer of 2020 that de Guzman and Calce did in the spring of 2000. De Guzman authored the I Love You email virus that circled the globe infecting millions of PCs; Calce, aka Mafiaboy, released the Melissa Internet worm that knocked offline Amazon, CNN, eBay and Yahoo.
Judging from the success of script kiddies, the tech giants apparently have not learned very much about security in 20 years. Clark was arrested in late July and charged with masterminding the hijacking of the Twitter accounts of A-list celebrities, and then Tweeting from those accounts to pull off a Bitcoin scam. His caper is worrisome on two counts. First it shows how resistant companies continue to be with respect to embracing very doable cyber hygiene practices measures that would prevent these sorts of hacks. And second, it reminds us how much capacity to wreak havoc truly malicious parties not just script kiddies possess. This is chilling considering the times were in. On the cusp of electing a U.S. president, with the world struggling to recover from a global pandemic, there are nuanced lessons we can learn from the Twitter Bitcoin hack. Heres what all consumers and companies should heed going forward.
Court records and reporting by the New York Times portray Clark as a self-absorbed youth who got started down the wrong path by cheating other players of the video game Minecraft, and then gravitating to mobile hacking scams to steal Bitcoin. Using the handle Open and OneHCF, Clark became notorious for selling cool Minecraft names and accessories, like capes for characters, for $50 to $100 to other players; hed make the sales pitch, collect the cash, but then never delivered the goods, or quickly reclaimed the items.
He next graduated to SIM swapping. This involved gathering personal information about a targeted victim, and then using that intel to persuade a wireless carrier employee into swapping the victims SIM card metadata onto a blank SIM card in his possession. In 2019, Clark gained control of the smartphone of a tech investor from Seattle and allegedly stole 164 Bitcoins, then worth $864,000, from him. The U.S. Secret Service got involved and returned 100 Bitcoins to the victim. Notably, authorities let Clark off the hook, though they had evidence of his role, according to the New York Times coverage.
Emboldened, Clark next took aim at Twitter. Clark and several co-conspirators used a two-step approach. First he phished his way onto Twitters corporate network. Next, they moved laterally, where ever they could, to gain an understanding of how Twitters network was laid out.
This knowledge then enabled them to target additional employees who did have access to our account-support tools, the company said in a statement. Using the credentials of employees with access to these tools, the attackers targeted 130 Twitter accounts, ultimately tweeting from 45, accessing the DM inbox of 36 and downloading the Twitter Data of seven.
The intruders took control of the accounts of Barack Obama, Jeff Bezos, Elon Musk, Bill Gates, Joe Biden, Mike Bloomberg and Kanye West, among others. Tweeting from the official accounts of these celebrities, they carried out Bitcoin variants of the classic Nigerian Prince-type of grift, hauling in $118,000 in Bitcoin payments in a little over an hour, before Twitter spotted the bogus activity and shut it down.
Its easy to dismiss a teenager cleverly using rogue Tweets to sell gullible victims on a too-good-to-be-true, get-rich-quick scheme as a triviality. However, the Twitter Bitcoin hack highlights the capacity for social media to be abused for malicious purposes. In these times, this is anything but a trivial development. Consider how social media services have emerged as potent tools for influencing public opinion at a time when some weighty questions about civilization as we know it are on the table: Will democracy give way to authoritarianism in the U.S.? Can the nations of the world unite to arrest climate change? What will the global economy look like post Covid-19? Is social injustice and skewed wealth distribution destined to carry on, as usual?
Further reading: The big Twitter hack vs. privacy
Another script-kiddie hack, of sorts, vividly illustrates the immense potential of social media services to be abused by anyone, with whatever motives. Im referring to how the youthful users of the TikTok and K-pop social media sites registered en masse for tickets to attend a Trump rally last June in Tulsa, Oklahoma. This duped the rally organizers into bragging about receiving 1 million reservation requests. Only 6,200 people showed up at a venue set up to cater to an overflow crowd of 20,000.
Meanwhile, Facebook CEO Mark Zuckerberg has come under fire this summer from his own employees for equivocating and ultimately declining to do anything about Trumps Facebook posts inflaming the George Floyd protests. By contrast, Twitter CEO Jack Dorsey has been forthcoming about details of how his company got hacked and has promised to do better. And on July 21, Dorsey, in something of a mea culpa, also directed the removal of thousands of Twitter QAnon accounts used to spread baseless conspiracy theories.
Zuckerberg finally caved to public pressure, and on August 7 followed Dorseys lead by suspending the Facebook account of one of the largest public groups fomenting QAnon conspiracy theories. QAnon for several years now has been using Twitter and Facebook to kindle fear and hatred. You might recall this is the group that spread the Pizzagate, a conspiracy theory accusing Hillary Clinton of operating a child sex-trafficking ring from a Washington, D.C., pizzeria. This led to a vigilante gunman turning up at the restaurant in December 2016 and opening fire into a closet.
Im not at all surprised that the public is demanding that social media companies get more in line with the social justice movement. Moving in that direction would put Twitter and Facebook in much better standing with a wide percentage of the populace. Yet doing so conflicts with the profit making imperative of their own boards of directors.
Facebook and Twitter are in the unenviable position of being stuck in between titanic, multi-front societal conflicts, observes Karthik Krishnan, CEO of Concentric.ai, a San Jose, California-based supplier of artificial intelligence systems. Theres no way these social media giants are going to make everyone happy.
It would be a major step forward if Twitter and Facebook would at least do more to shore up the security posture of their corporate IT systems. Like many large enterprises, the social media giants have put far too much emphasis on agility on opening up their systems to all-comers and not nearly enough on basic cyber hygiene. Theres really no excuse for this. Twitter has a market valuation north of $30 billion dollars, yet when its Chief Information Security Officer (CISO) left last December, the company did nothing; it was still searching for a replacement CISO seven months later when the celebrities accounts got hijacked.
Clarks successful hack showed Twitter was not even taking a least privilege approach to account access, which is a baby step towards adopting full zero trust identity and access management (IAM) procedures, something that many progressive enterprises in the tech and financial sectors have moved to. Had it been enforcing least privileged access, Twitter would have had a very narrowly defined and closely monitored list of employees who could take control of the celebrities accounts. It wouldve been much harder for the young Mr. Clark to find, and dupe, someone on that short list. And even if he did, any unusual use of that access would have quickly tripped an alert.
Zero trust, actually, is where Twitter and Facebook should already be, given the sensitive personal data they collect and monetize. Zero trust boils down to never trust anyone until they can prove who they are and why they deserve access. In order to do this, zero trust uses automation and machine-learning to slice and dice access queries on several planes. This makes breaches much more difficult to pull off; it limits the damage that can be caused by any hacker who does break through.
We could all just wait for human users to somehow become much less gullible. Short of that ever happening, zero trust is the future. Twitter and Facebook should have been steering towards zero trust long ago. Will they do so now, given all thats happened thus far in 2020? Well see. Ill keep watch.
Read the original here:
Big Lessons From The Twitter Bitcoin Hack | Avast - Security Boulevard
- Bitcoin r/Bitcoin - reddit [Last Updated On: September 20th, 2017] [Originally Added On: September 20th, 2017]
- Bitcoin Exchange Rate Bitcoin Live Converter Preev [Last Updated On: September 29th, 2017] [Originally Added On: September 29th, 2017]
- The Rise and Fall of Bitcoin | WIRED [Last Updated On: November 17th, 2017] [Originally Added On: November 17th, 2017]
- Bitcoin Crashes and Then Surges in Wild Weekend Action ... [Last Updated On: November 17th, 2017] [Originally Added On: November 17th, 2017]
- WeUseCoins - Official Site [Last Updated On: November 21st, 2017] [Originally Added On: November 21st, 2017]
- Bitcoin Price Index - Real-time Bitcoin Price Charts [Last Updated On: November 21st, 2017] [Originally Added On: November 21st, 2017]
- Warning Signs About Another Giant Bitcoin Exchange [Last Updated On: November 23rd, 2017] [Originally Added On: November 23rd, 2017]
- Everything you need to know about Bitcoin mining [Last Updated On: November 23rd, 2017] [Originally Added On: November 23rd, 2017]
- Bitcoin hits $13,000: The rally is back, big time - Dec. 6 ... [Last Updated On: December 7th, 2017] [Originally Added On: December 7th, 2017]
- SEC suspends trading of red-hot bitcoin stock - Dec. 19, 2017 [Last Updated On: December 20th, 2017] [Originally Added On: December 20th, 2017]
- The Bitcoin Boom: In Code We Trust - The New York Times [Last Updated On: December 22nd, 2017] [Originally Added On: December 22nd, 2017]
- Bitcoin Opacity Medium [Last Updated On: January 24th, 2018] [Originally Added On: January 24th, 2018]
- Bitcoin Forum - Index [Last Updated On: February 1st, 2018] [Originally Added On: February 1st, 2018]
- Mining - Bitcoin Wiki [Last Updated On: February 11th, 2018] [Originally Added On: February 11th, 2018]
- Bitcoin Cash - Wikipedia [Last Updated On: February 17th, 2018] [Originally Added On: February 17th, 2018]
- Bitcoin Energy Consumption Index - Digiconomist [Last Updated On: February 27th, 2018] [Originally Added On: February 27th, 2018]
- Paypal Files Patent for Expedited ... - news.bitcoin.com [Last Updated On: March 12th, 2018] [Originally Added On: March 12th, 2018]
- Bitcoin - MarketWatch.com Topics [Last Updated On: March 12th, 2018] [Originally Added On: March 12th, 2018]
- What is Bitcoin? - Definition from WhatIs.com [Last Updated On: March 13th, 2018] [Originally Added On: March 13th, 2018]
- Bitcoin and Blockchain - Bloomberg [Last Updated On: March 13th, 2018] [Originally Added On: March 13th, 2018]
- Bitcoin (BTC) price: News & Live Chart - Trading Analysis ... [Last Updated On: March 27th, 2018] [Originally Added On: March 27th, 2018]
- Will a 1099-B form work best for reporting bitcoin ... [Last Updated On: April 4th, 2018] [Originally Added On: April 4th, 2018]
- Must I pay tax this year if I transfer bitcoin from ... [Last Updated On: April 4th, 2018] [Originally Added On: April 4th, 2018]
- Standard Exchanges Bitcoin.com [Last Updated On: April 9th, 2018] [Originally Added On: April 9th, 2018]
- Bitcoin - Bitcoin Price Live, BTC Value, Mining, BTC to USD ... [Last Updated On: July 11th, 2018] [Originally Added On: July 11th, 2018]
- Things you need to know Bitcoin.com [Last Updated On: July 27th, 2018] [Originally Added On: July 27th, 2018]
- Bitcoin Dips Below $7,000, Hitting Lowest In 2 Weeks [Last Updated On: August 7th, 2018] [Originally Added On: August 7th, 2018]
- One Chart Explains Why You Should Own Bitcoin And Other ... [Last Updated On: August 12th, 2018] [Originally Added On: August 12th, 2018]
- XBT-Cboe Bitcoin Futures [Last Updated On: September 29th, 2018] [Originally Added On: September 29th, 2018]
- CoinDesk - Leader in blockchain news. [Last Updated On: October 25th, 2018] [Originally Added On: October 25th, 2018]
- Bitcoincharts | Charts [Last Updated On: November 12th, 2018] [Originally Added On: November 12th, 2018]
- Bitcoin (BTC) Price, Chart, Info | CoinGecko [Last Updated On: November 28th, 2018] [Originally Added On: November 28th, 2018]
- Bitcoin Technical Analysis - FXStreet [Last Updated On: November 28th, 2018] [Originally Added On: November 28th, 2018]
- Bitcoin Crypto-Economics Index Real-time Price Charts ... [Last Updated On: November 29th, 2018] [Originally Added On: November 29th, 2018]
- The Beginner's Guide To Bitcoin - Everything You Need To Know [Last Updated On: December 2nd, 2018] [Originally Added On: December 2nd, 2018]
- Bitcoin | Definition, Mining, & Facts | Britannica.com [Last Updated On: December 2nd, 2018] [Originally Added On: December 2nd, 2018]
- What Is Bitcoin? The Ultimate Beginners Guide To Bitcoin [Last Updated On: December 2nd, 2018] [Originally Added On: December 2nd, 2018]
- XBT - Bitcoin rates, news, and tools - xe.com [Last Updated On: December 2nd, 2018] [Originally Added On: December 2nd, 2018]
- Pay with Bitcoin Online | Use Bitcoin to Pay for Gold and ... [Last Updated On: December 2nd, 2018] [Originally Added On: December 2nd, 2018]
- Bitcoin (BTC) for beginners - Coin Rivet guide to BTC [Last Updated On: December 2nd, 2018] [Originally Added On: December 2nd, 2018]
- Bitcoin extends falls as selloff in crypto currencies ... [Last Updated On: December 2nd, 2018] [Originally Added On: December 2nd, 2018]
- Bitcoin - Investopedia - Sharper Insight. Smarter Investing. [Last Updated On: December 9th, 2018] [Originally Added On: December 9th, 2018]
- Bitcoin | Bitcoin Price | Bitcoin News | BTC | Info ... [Last Updated On: December 21st, 2018] [Originally Added On: December 21st, 2018]
- Bitcoin Price Today - Live Bitcoin Value - Charts & Market ... [Last Updated On: January 6th, 2019] [Originally Added On: January 6th, 2019]
- News - Bitcoin News - Page 952 [Last Updated On: January 7th, 2019] [Originally Added On: January 7th, 2019]
- Bitcoin price | index, chart and news | WorldCoinIndex [Last Updated On: April 25th, 2019] [Originally Added On: April 25th, 2019]
- Something Very Strange Is Going On With Bitcoin And BTC ... [Last Updated On: September 6th, 2019] [Originally Added On: September 6th, 2019]
- Will Bitcoin hit $12000 by the end of the year? - Khaleej Times [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Bitcoins $1000 Breakaway CME Gap Demands Attention From Analysts - BeInCrypto [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Bitcoin Trending On Google Next To Call of Duty, Kanye West, and Rudy Giuliani - newsBTC [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- A Bitcoin Price In The Millions? But We Have To Wait A Decade - Bitcoinist [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- No Bitcoin Price Breakout for Another Year; Heres Why - newsBTC [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Bitcoin Price Back Over $10K Following 36% Gains on the Day - Cointelegraph [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- When Will Bitcoin Sidechains Send Ethereum, Ripple, And Other Crypto Prices To Zero? - Forbes [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Why the Price of Bitcoin Has Jumped 25% in Four Days - Barron's [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Bitcoin Price Surges as Bitfinex Gets Chance to Recover $850M from Crypto Capital, VanEck Expert Believes - U.Today [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Bitcoin (BTC) Price Steadies Uptrend But Another Correction Likely - newsBTC [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Bitcoin and child pornography a connection we cannot tolerate - The Dallas Morning News [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Congressman Warns Bitcoin Is A Threat To The U.S. Dollar - Forbes [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- The Bitcoin Halvening Is Coming - Forbes [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- China Roundup: Xis power on bitcoin, the rise of Alibabas new rival - TechCrunch [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- This U.S. Congressman Thinks Bitcoin Will Have Enormous Value And Utility Over The Long Term - Forbes [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Game Is On Again For Bitcoin, ETH, XRP, And XLM - Forbes [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- These Are The Only 2 Major Crypto Assets Outperforming The Bitcoin Price This Year - Forbes [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Stablecoins Are The New Bitcoin In Congress - Forbes [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Bitcoin Has Crashed AgainWhat Now? - Forbes [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Forget ChinaIs This The Real Reason Bitcoin, Ethereum, Litecoin, And Ripples XRP Bounced? - Forbes [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- After Recovery To $10,000, Bitcoin Should Hit $100,000 In 2021 - Forbes [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- A Former Bank Of England Governor Warned The 2008 Crash That Inspired Bitcoin Could Happen Again - Forbes [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Bitcoin Bears Are Still There When You Zoom Out, Warns Analyst - BeInCrypto [Last Updated On: October 29th, 2019] [Originally Added On: October 29th, 2019]
- P2P Bitcoin Trading Volume in India Explodes Past All-Time High - BeInCrypto [Last Updated On: October 29th, 2019] [Originally Added On: October 29th, 2019]
- Exchange Tokens Have Outperformed BTC This Year - Bitcoin News [Last Updated On: October 29th, 2019] [Originally Added On: October 29th, 2019]
- Coffee for Crypto? ICE to Launch Bitcoin Consumer App with Starbucks - newsBTC [Last Updated On: October 29th, 2019] [Originally Added On: October 29th, 2019]
- Is Edward Snowden the Anonymous Bitcoin Time Traveler? - BeInCrypto [Last Updated On: October 29th, 2019] [Originally Added On: October 29th, 2019]
- Latest Bitcoin Cash price and analysis (BCH to USD) - Yahoo Finance [Last Updated On: October 29th, 2019] [Originally Added On: October 29th, 2019]
- Bitcoin and cryptocurrencies had a very bad day - TechCrunch [Last Updated On: October 29th, 2019] [Originally Added On: October 29th, 2019]
- Bitcoin price prediction: China-induced surge will continue if cryptocurrency defies dreaded 'Death Cross' - The Independent [Last Updated On: October 29th, 2019] [Originally Added On: October 29th, 2019]
- Russia: Government Official Expects To Mine 20% Of The Worlds Bitcoin - Cointelegraph [Last Updated On: October 29th, 2019] [Originally Added On: October 29th, 2019]
- Bitcoin Exploded: What Now? - Forbes [Last Updated On: October 29th, 2019] [Originally Added On: October 29th, 2019]
- Bitcoin Time-Traveller: Not Really From The Future, Shock! - Bitcoinist [Last Updated On: October 31st, 2019] [Originally Added On: October 31st, 2019]