Can we do without the condescending "Uh" and "Um" on HN?
An audit trail would tell you who was social-engineered, but it wouldn't have prevented the attack in the same way Wikipedia's revision history doesn't keep you from vandalizing it.
It wouldn't even necessarily tell you who was social-engineered. My understanding of this case was that CS tool credentials were posted globally in their Slack.
Auditing tells you what happened, it doesn't prevent it from happening.
If they have logs then they can use it in the future (and it seems they do) to design better protections but only active alarms and security controls can prevent something happening in real-time.
However that does raise the question of why Twitter ever needs such access to someone's account in the first place, especially without a combination of approvals to get that access.
100%. My work has really great auditing tools. I use them often to understand actions by other that are routine. It still doesn't prevent a employee emailing a datacenter to rack a malicious device or give someone service without paying. Record trails are not auditing. They are records.
Auditing, post mortems, whatever diagnose the situation afterwards.
At the end of the day Uber can't stop a driver from kidnapping people, but it can provide documentation and gps coordinates to police.
My point is companies need reasonable records and audit policies and when _really bad stuff happens_ you call in the big guns for the arm of the law.
At some point you also need to trust staff and weigh that against mistakes and malicious intent.
In short, security remains an imperfect balance of practicality