Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's an admin panel that shows account information and allows for the staff to change details. What is the big deal?


>A little over ten years ago: Twitter settled with the FTC as a result of an internal tools breach. Their internal tooling was available directly over the web and accessed through an employee account protected by the password "happiness"

https://twitter.com/Magoo/status/1283520203679133696


I guess it implies that the attack was from the inside?


Inside attack / insider's admin account credentials compromised / admin panel itself compromised. Would love to see an RCA on this.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: