Live data from Hacker News

Twitter urges users to change passwords after computer 'glitch'

reuters.com

1–10 of 490 posts

Re: Twitter urges users to change passwords after computer 'glitch'

#4
post #3

So why are they not invalidating exposed passwords like Github did the other day? At the very least they should have a security alert at the top of your feed or something. Edit: Looks like they are alerting users.

Because it'd destroy their MAU numbers.

Re: Twitter urges users to change passwords after computer 'glitch'

#6
Actual twitter post: https://blog.twitter.com/official/en_us/topics/company/2018/...

"Due to a bug, passwords were written to an internal log before completing the hashing process. We found this error ourselves, removed the passwords, and are implementing plans to prevent this bug from happening again."

Exact same thing that github did just recently.

Re: Twitter urges users to change passwords after computer 'glitch'

#8
We need a regulatory rulebook codified in law by congress that fines companies that make these "mistakes". Enough of a fine will force companies to take these "mistakes" seriously.

In Yahoo's case, that might have forced Marissa to actually keep a cybersecurity team and not cut them when she knew the systems were in danger of being compromised. We aren't getting any jail time, but hefty fines that don't stifle growth, just punish negligence and carelessness that are codified and don't need long court hearings to pass are a must.

Re: Twitter urges users to change passwords after computer 'glitch'

#10
post #8

We need a regulatory rulebook codified in law by congress that fines companies that make these "mistakes". Enough of a fine will force companies to take these "mistakes" seriously. In Yahoo's case, that might have forced Marissa to actually keep a cybersecurity team and not cut them when she knew the systems were in danger of being compromised. We aren't getting any jail time, but hefty fines that don't stifle growth…

"Technology by legislation" - that's the new trend it seems. How about replacing passwords with something technologically superior instead?
Post reply on HN