Jump to content

@LinusTech Twitter Account Hacked

SuperBailey
Go to solution Solved by LinusTech,

On June 28, 2016 the Linus Media Group domain registrar account was compromised.

 

The exact methodology of the "hack" won't be disclosed for obvious reasons, but I can assure you that despite any claims to the contrary, the appropriate safeguards were in place on our side, and as I type this Yvonne is having a very heated phone discussion with the 3rd party responsible for the breach.

 

Anyway, the thing most of you are probably wondering about right now is what this means for your forum account or personal information, and the answer is very simple:

 

NOTHING.

 

The "hacker" simply changed the DNS settings in the dashboard and did not at any time have access to the linustechtips.com server. Any claims of a database dump are categorically false.

 

The compromised accounts - including Twitter - have been restored.

 

I hope this clears things up.

 

Linus

2 minutes ago, thedarkdad3 said:

 

 

Salty Much? In the end buddy I still have a career and I am successful. I'm not the one getting hacked.

What do you have against Linus? Like you said before, this is just one of the many times he's been hacked and it likely won't be the last. It's not like this is going to singlehandedly ruin his career or reputation. Chill

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, MellowCream said:

I'm aware this is what Linus says, however, Poodle says otherwise. 

however neither provided proof, and poodle saying they no longer are selling basically means they have nothing to sell. 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Domain Registrar: Godaddy.

 

I am assuming the hackers got Linus's information, called in and went through a tier 1 to get a password reset. They probably gathered a bunch of information from misc. leaks and was enough to get past an after hours tier 1 tech at godaddy.

 

Tech then resets password. Said hacker gets access to DNS panel, redirects mxrecord for linustechtips.com to his own mail server or a catchall, initiates a twitter password reset and bob is your uncle. The reason they probably only had access to the twitter is it may of been the only service they could hit not running 2FA.

 

"Hacking" these days is nothing more than ctrl + f on a bunch of leaks and playing mind games with some tier 1 support guys at companies. A little social awareness and you can pretty much do what you want.

Bwoop Bwoop its the sound of the police'

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, guppy said:

What do you have against Linus? Like you said before, this is just one of the many times he's been hacked and it likely won't be the last. It's not like this is going to singlehandedly ruin his career or reputation. Chill

It could certainly hurt the reputation though.

Also, welcome to the forums.

1474409643.6492558

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, thedarkdad3 said:

 

 

Salty Much? In the end buddy I still have a career and I am successful. I'm not the one getting hacked.

No, but you can very well get hacked. 

See Boogie. His hack was at fault of Verizon and social engineering. There was absolutely nothing that could have prevented than except an act of God.

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, MellowCream said:

I'm aware this is what Linus says, however, Poodle says otherwise. 

The last time there was a breach, all passwords were automatically reset and it was well-known.

This time was simply DNS, the proof being that people are still complaining on Linus's twitter that they can't access the site. DNS, by design, is slow to update as information has to pass through many servers. I'd say within the next hour everyone's back on LTT.

 

I have my suspicions about who this 'third party' is

Speedtests

WiFi - 7ms, 22Mb down, 10Mb up

Ethernet - 6ms, 47.5Mb down, 9.7Mb up

 

Rigs

Spoiler

 Type            Desktop

 OS              Windows 10 Pro

 CPU             i5-4430S

 RAM             8GB CORSAIR XMS3 (2x4gb)

 Cooler          LC Power LC-CC-97 65W

 Motherboard     ASUS H81M-PLUS

 GPU             GeForce GTX 1060

 Storage         120GB Sandisk SSD (boot), 750GB Seagate 2.5" (storage), 500GB Seagate 2.5" SSHD (cache)

 

Spoiler

Type            Server

OS              Ubuntu 14.04 LTS

CPU             Core 2 Duo E6320

RAM             2GB Non-ECC

Motherboard     ASUS P5VD2-MX SE

Storage         RAID 1: 250GB WD Blue and Seagate Barracuda

Uses            Webserver, NAS, Mediaserver, Database Server

 

Quotes of Fame

On 8/27/2015 at 10:09 AM, Drixen said:

Linus is light years ahead a lot of other YouTubers, he isn't just an average YouTuber.. he's legitimately, legit.

On 10/11/2015 at 11:36 AM, Geralt said:

When something is worth doing, it's worth overdoing.

On 6/22/2016 at 10:05 AM, trag1c said:

It's completely blown out of proportion. Also if you're the least bit worried about data gathering then you should go live in a cave a 1000Km from the nearest establishment simply because every device and every entity gathers information these days. In the current era privacy is just fallacy and nothing more.

 

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, MellowCream said:

I'm aware this is what Linus says, however, Poodle says otherwise. 

Why would they no longer wish to sell the DB if they actually had it? Basically Linus called their bluff, and thus far, they haven't done anything to prove their cards. If they really had it, and wanted to call Linus out on being a "fucking retard" then they would paste the DB somewhere, and simply not sell it.

 

Link to comment
Share on other sites

Link to post
Share on other sites

14 minutes ago, Blade of Grass said:

Of course, anything can be cracked, it's just a matter of how hard and how long it will take. 

 

One-time pads cannot be cracked.

 

They're also completely ridiculous.

Link to comment
Share on other sites

Link to post
Share on other sites

@LinusTech Will we ever know the involved 3rd party ?

What for knowing what kind of problems we might be dealing with if we are partnering with them ?

~New~  BoomBerryPi project !  ~New~


new build log : http://linustechtips.com/main/topic/533392-build-log-the-scrap-simulator-x/?p=7078757 (5 screen flight sim for 620$ CAD)LTT Web Challenge is back ! go here  :  http://linustechtips.com/main/topic/448184-ltt-web-challenge-3-v21/#entry601004

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Stuff_ said:

No, but you can very well get hacked. 

See Boogie. His hack was at fault of Verizon and social engineering. There was absolutely nothing that could have prevented than except an act of God.

Even then, God is on MacOS, they probably couldn't have done anything.

1474409643.6492558

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, givingtnt said:

@LinusTech Will we ever know the involved 3rd party ?

What for knowing what kind of problems we might be dealing with if we are partnering with them ?

Probably not, confidentially agreements and stuff.

1474409643.6492558

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, rm -rf said:

Even then, God is on MacOS, they probably couldn't have done anything.

Mac doesn't = impenetrable. 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Arty said:

Mac doesn't = impenetrable. 

I wasn't suggesting that.

I was talking about incompatibilities.

1474409643.6492558

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, rm -rf said:

Probably not, confidentially agreements and stuff.

I think we have the right to know whatever compagnie is too lazy to protect a compagnie as big as lmg.

how about us ?

~New~  BoomBerryPi project !  ~New~


new build log : http://linustechtips.com/main/topic/533392-build-log-the-scrap-simulator-x/?p=7078757 (5 screen flight sim for 620$ CAD)LTT Web Challenge is back ! go here  :  http://linustechtips.com/main/topic/448184-ltt-web-challenge-3-v21/#entry601004

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, Sakkura said:

 

One-time pads cannot be cracked.

 

They're also completely ridiculous.

Thank you.

I am literally cringing at the amount of people here who don't understand the difference between hashing and encryption, claiming a hash can be cracked (which is true to some extent for md5 but requires excessive effort and computing power).

 

Rainbow tables != Cracking a hash (#inb4shutdown)

Speedtests

WiFi - 7ms, 22Mb down, 10Mb up

Ethernet - 6ms, 47.5Mb down, 9.7Mb up

 

Rigs

Spoiler

 Type            Desktop

 OS              Windows 10 Pro

 CPU             i5-4430S

 RAM             8GB CORSAIR XMS3 (2x4gb)

 Cooler          LC Power LC-CC-97 65W

 Motherboard     ASUS H81M-PLUS

 GPU             GeForce GTX 1060

 Storage         120GB Sandisk SSD (boot), 750GB Seagate 2.5" (storage), 500GB Seagate 2.5" SSHD (cache)

 

Spoiler

Type            Server

OS              Ubuntu 14.04 LTS

CPU             Core 2 Duo E6320

RAM             2GB Non-ECC

Motherboard     ASUS P5VD2-MX SE

Storage         RAID 1: 250GB WD Blue and Seagate Barracuda

Uses            Webserver, NAS, Mediaserver, Database Server

 

Quotes of Fame

On 8/27/2015 at 10:09 AM, Drixen said:

Linus is light years ahead a lot of other YouTubers, he isn't just an average YouTuber.. he's legitimately, legit.

On 10/11/2015 at 11:36 AM, Geralt said:

When something is worth doing, it's worth overdoing.

On 6/22/2016 at 10:05 AM, trag1c said:

It's completely blown out of proportion. Also if you're the least bit worried about data gathering then you should go live in a cave a 1000Km from the nearest establishment simply because every device and every entity gathers information these days. In the current era privacy is just fallacy and nothing more.

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, burnttoastnice said:

Thank you.

I am literally cringing at the amount of people here who don't understand the difference between hashing and encryption, claiming a hash can be cracked (which is true to some extent for md5 but requires excessive effort and computing power).

 

Rainbow tables != Cracking a hash (#inb4shutdown)

@LinusTech techquicky much ?

~New~  BoomBerryPi project !  ~New~


new build log : http://linustechtips.com/main/topic/533392-build-log-the-scrap-simulator-x/?p=7078757 (5 screen flight sim for 620$ CAD)LTT Web Challenge is back ! go here  :  http://linustechtips.com/main/topic/448184-ltt-web-challenge-3-v21/#entry601004

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, givingtnt said:

I think we have the right to know whatever compagnie is too lazy to protect a compagnie as big as lmg.

how about us ?

We have the 'right' to, though we don't have the 'legal right' to.

1474409643.6492558

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, givingtnt said:

I think we have the right to know whatever compagnie is too lazy to protect a compagnie as big as lmg.

how about us ?

GoDaddy is the registrar of the domain.  

 

AMD Ryzen 5 3600 | Corsair H100i Pro | ASRock X570 Phantom Gaming 4 | Corsair Vengeance 32GB 2x16gb @ 3200mhz  | Vega 64 @ Stock | Fractal Design Define R4 | Corsair RM750

 

ThinkPad T480 | Intel Core i7 8650u | Nvidia MX150 | 32GB DDR4 @ 2400mhz | Samsung 840 Pro 1tb | 1080p touchscreen

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, rm -rf said:

We have the 'right' to, though we don't have the 'legal right' to.

you sure ?
who knows it might be twitter ?
might be the companie who sold the domain to linustechtips

it could be anyone

~New~  BoomBerryPi project !  ~New~


new build log : http://linustechtips.com/main/topic/533392-build-log-the-scrap-simulator-x/?p=7078757 (5 screen flight sim for 620$ CAD)LTT Web Challenge is back ! go here  :  http://linustechtips.com/main/topic/448184-ltt-web-challenge-3-v21/#entry601004

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, MellowCream said:

GoDaddy is the registrar of the domain.  

 

Spoiler

I think it's cloudflare.svg

 

Speedtests

WiFi - 7ms, 22Mb down, 10Mb up

Ethernet - 6ms, 47.5Mb down, 9.7Mb up

 

Rigs

Spoiler

 Type            Desktop

 OS              Windows 10 Pro

 CPU             i5-4430S

 RAM             8GB CORSAIR XMS3 (2x4gb)

 Cooler          LC Power LC-CC-97 65W

 Motherboard     ASUS H81M-PLUS

 GPU             GeForce GTX 1060

 Storage         120GB Sandisk SSD (boot), 750GB Seagate 2.5" (storage), 500GB Seagate 2.5" SSHD (cache)

 

Spoiler

Type            Server

OS              Ubuntu 14.04 LTS

CPU             Core 2 Duo E6320

RAM             2GB Non-ECC

Motherboard     ASUS P5VD2-MX SE

Storage         RAID 1: 250GB WD Blue and Seagate Barracuda

Uses            Webserver, NAS, Mediaserver, Database Server

 

Quotes of Fame

On 8/27/2015 at 10:09 AM, Drixen said:

Linus is light years ahead a lot of other YouTubers, he isn't just an average YouTuber.. he's legitimately, legit.

On 10/11/2015 at 11:36 AM, Geralt said:

When something is worth doing, it's worth overdoing.

On 6/22/2016 at 10:05 AM, trag1c said:

It's completely blown out of proportion. Also if you're the least bit worried about data gathering then you should go live in a cave a 1000Km from the nearest establishment simply because every device and every entity gathers information these days. In the current era privacy is just fallacy and nothing more.

 

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, burnttoastnice said:

I think it's cloudflare.svg

could be

but if lmg is a client, then like anyone they don't have to hide that as a customer they have been compromised by them ?

 

unless they are on some kind of contract. wich I doubt

~New~  BoomBerryPi project !  ~New~


new build log : http://linustechtips.com/main/topic/533392-build-log-the-scrap-simulator-x/?p=7078757 (5 screen flight sim for 620$ CAD)LTT Web Challenge is back ! go here  :  http://linustechtips.com/main/topic/448184-ltt-web-challenge-3-v21/#entry601004

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, burnttoastnice said:

Thank you.

I am literally cringing at the amount of people here who don't understand the difference between hashing and encryption, claiming a hash can be cracked (which is true to some extent for md5 but requires excessive effort and computing power).

 

Rainbow tables != Cracking a hash (#inb4shutdown)

I mentioned this as well about a page ago, when replying to this silly man. 

54 minutes ago, thedarkdad3 said:

You realize encryption can be broken and deciphered.  Hell Let @LinusTech pay me and my firm $30,000k and we will do it within a month. I somehow doubt he wants to get rekt again. hahaha

 

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, burnttoastnice said:
  Hide contents

I think it's cloudflare.svg

 

For those who don't know what logo that is, it's CloudFlare

1474409643.6492558

Link to comment
Share on other sites

Link to post
Share on other sites

11 minutes ago, givingtnt said:

@LinusTech Will we ever know the involved 3rd party ?

What for knowing what kind of problems we might be dealing with if we are partnering with them ?

Linus claimed his registrar was hacked.. DNS lookup shows godaddy as the registrar. 

 

Godaddys authentication steps are usually pretty rock solid but I could see a tier 1 guy getting goofed up and getting social engineered'

Bwoop Bwoop its the sound of the police'

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, givingtnt said:

could be

but if lmg is a client, then like anyone they don't have to hide that as a customer they have been compromised by them ?

 

unless they are on some kind of contract. wich I doubt

Why do you doubt they'd be in a contract?

1474409643.6492558

Link to comment
Share on other sites

Link to post
Share on other sites

Guest
This topic is now closed to further replies.


×