Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Very relevant: https://news.ycombinator.com/item?id=21747424

Can this be an API leak which Chinese MSS used to track Chinese users?

It may well as be if we believe that API wasn't implementing discoverability restrictions from privacy settings, and only hid users on the UI level.

> Basically Twitter got pwned big time, and now denies it because GDPR will ruin them if breach is proven. Here is what Doubi's online followers figured:

> State security got all phone numbers used for Twitter phone verification up to May 2019 and possibly till July.

> Twitter haphazardly closed the breach in complete secrecy.

> API hole explanation is excluded as people with 100% private accs got police visits.

> People with foreign SIM cards also got into trouble. So the explanation that China compromised Twitter's SMS providers is also excluded, as its improbable that they did it in 4+ countries.

> 2016 breach is also out of question.

> The only explanation is that they got hold on a big piece of their user DB, or, worse, they have an active infiltrator in Twitter, or Twitter voluntarily cooperated.



The story has some problem, Doubi is not an SSR developer, SSR was a high school girl's popular personal fork who mysteriously stopped.

Doubi is a blogger sharing GFW circumvention tips, like easy-to-use installing scripts for VPS, tutorials, reviews and a list of donated free acounts. Before his arrest, his blog had been under attack, domain names blocked.

The phone number thing is very dangerous, twitter bascially won't allow you to use it after a while if you don't provide a valid phone number.

Police monitoring: https://twitter.com/tianlan/status/936909920334528513 https://twitter.com/midiexiang6555/status/117813328167558348...

Fried-rice festival, commemorating the day Mao's only son was spotted and bombed in North Korea while out cooking fried-rice. https://twitter.com/tianlan/status/1198841340865331200


> they have an active infiltrator in Twitter

If I was China, I'd go for this. Twitter has thousands of employees, many of which can surely be turned with some pressure. Also many who has family in China that can be used for leverage.


I’d have to imagine this is very common, and they’ve probably got one at all the big tech companies. It’s an underreported threat IMO. Who would say no to doubling their salary in exchange for running the occasional DB query for their home country?


I expect a lot of people would say no to that and report the attempt to company security.

Of course, if I'm China, I can try it with enough people to get several assets.

Also, of the offer includes "we won't kill your grandma", uptake might be higher.


> I expect a lot of people would say no to that and report the attempt to company security.

Turning someone is rarely an upfront request.

You make friends with them and make small talk about politics to see if there are any sympathies to your cause.

Ask for a small favor and see if they'll do it, then progress slowly. You only ask them to break the law once they're already on your side.


And if a little persuasion was needed, the folder with evidence of assets secrets that would turn their life upside down if revealed. Ideally real secrets, but these days made up ones are probably as effective.


Motives for spying are varied: https://en.wikipedia.org/wiki/Motives_for_spying

> MICE: Money, Ideology, Compromise, and Ego or Extortion (depending on source)

> RASCLS: Reciprocation, Authority, Scarcity, Commitment and Consistency, Liking, and Social Proof.


Social engineering at its finest.


Also common spy recruitment tactic.


Oh boy, I’d encourage you to work in government for a year or two. I did IT for a government department that eventually wound up being investigated for letting the Taliban use their equipment (all I did was help them troubleshoot run of the mill PC issues FWIW). I personally know someone who had root access to a government land auction DB. Someone asked them to run “off the book” queries in exchange for looking the other way if said DBA wanted to run their own unaudited queries.


At competent companies -- I make no claim about Twitter here, but certainly at Google or at my employer -- it is extremely uncommon to have access to that database. All requests to access are logged and individually permissioned. Asking to access without a good reason, such as attachment to an active customer ticket, etc -- will get a hard no.


But at the same time, there's usually a way round it. For example, break the account in some way so the user opens a ticket, then grab the ticket and dump the whole contents of the account to 'debug'.


Who watches the watchers?


Doubling their salary? People have sold secret classified data for just thousands of dollars worth of gift cards.


At a public company like Twitter, for SOX compliance reasons, it will be very difficult to find someone that has such permissions, and running anything unusual can be easily found by auditing. I'd stop with the conspiracy theories.


https://www.washingtonpost.com/national-security/former-twit...

In general, most companies want to scope SOX as narrowly as possible. So if you can, only things that your auditors think will affect revenue reporting.

Querying ads performance data? Sure, we'll SOXify it. Querying user accounts writ large? "Meh, our engineers need to be productive."


SOX doesn't really stop this kind of prying, and it has happened in the past.

https://www.npr.org/2019/11/07/777352750/how-saudi-arabia-us...


SOX is about financial compliance. It is not a computer security standard.

I’ve worked for lots of SOX companies as a third party and had root/sqlplus on most of them. There’s really to relationship between SOX and security.


There are always weaknesses and internal vulnerabilities in every system.

If it was from the inside more likely a privileged user was compromised. It could also explain why Twitter is being quiet, especially if the investigation is ongoing.


Anyone who isn't stupid. Considering how may big corporations have ties with government agencies, if you try to pull something like that and you get caught you could easily be charged with espionage.


Even people with large IQs can be 'temporarily' stupid. Hence the term "lapse in judgement." Somebody who's intelligent but lets their ego run wild might believe they're too smart to get caught.


Why go to all that trouble? Why not just send their version of a National Security Letter?



Saudis and many OGUsers kids.


Saudis are amateurs.


It doesn't scale -- the more you do it, the more likely one of them is to squeal or be caught, then MSS would be leaking their priority target list straight to the the FBI. Instead they would carefully target people with access, but not necessarily force them to divulge information / tamper with systems except when they really need it.


Occam's razor supports this one. Which would also bring liability to Twitter for not taking adequate steps to secure their servers.

It's not like they get l337 h4xx0rs to pwn their internal systems; they probably just have login credentials or permissions they shouldn't have, which aren't audited, and they can sneak things out in plain sight.


this begs the question: is it a security liability to hire anyone with any family in China?


If China got OPM, they could easily get most of Twitter's DBs. Most likely through Nationals passing vulns back to home state intelligence agency, who can exfil data but not finger the moles.


That's really a non-sequitur. OPM was a basket case, unmaintained legacy systems in a backwater agency.


You answered your own question yourself it that thread it seems:

> API hole explanation is excluded as people with 100% private accs got police visits.

Still, thanks for sharing, that's hell of a story. I don't speak Chinese and have no idea what's ShadowSocksR and why this Doubi guy was so hated by Chinese govt for that. Would appreciate more details.


As it is speculated now, this API leak also leaked private accounts as "privacy" check was possibly done client side.

Doubi was one of main developers of Shadowsocks, a traffic obfuscation tool to jump the Chinese firewall.

As said, the guy openly defied Chinese 3 letter services for years, and even trolled a number of agents whom he managed deanonymise himself.


Woah, this is something I'd been wondering since that comment thread.

Twitter needs a whistleblower/leaker at this point.


What is SSR? Sorry for the dumb question; all I can find in my moment of curiosity is something about VPNs.


Shadow Socks R


thank you


The only explanation? What if Chinese undercover agents are running SIM card sales operations?


Basically Twitter got pwned big time, and now denies it because GDPR will ruin them if breach is proven.

I don't know about any other allegations but this is wrong. GDPR revenue penalties don't apply to breaches.


I thought they applied with Abby negligence in protection of PII? A breach can be little more than an exposure of poor PII protection.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: