The Tweet from the Twitter CTO on this: https://twitter.com/paraga/status/992135139994943488 "We are sharing this information to help people make an informed decision about their account security. We didn’t have to, but believe it’s the right thing to do." The "we didn't have to" is a little jarring given the scale of this.
>The "we didn't have to" is a little jarring given the scale of this. How come? I interpreted it to mean that no regulations required this, but they chose to anyway. Which is true.
Twitter urges users to change passwords after computer 'glitch'
111–120 of 490 posts
Re: Twitter urges users to change passwords after computer 'glitch'
#112I've seen this scenario unfold before: 1. User provides username/password. 2. An exception occurs somewhere. 3. The stack trace from the exception is logged. 4. The stack trace includes the credentials. 5. The exception ends up in a ticketing system (Trac, JIRA, etc.) 6. Nobody notices for years.
Re: Twitter urges users to change passwords after computer 'glitch'
#113I've seen this scenario unfold before: 1. User provides username/password. 2. An exception occurs somewhere. 3. The stack trace from the exception is logged. 4. The stack trace includes the credentials. 5. The exception ends up in a ticketing system (Trac, JIRA, etc.) 6. Nobody notices for years.
Re: Twitter urges users to change passwords after computer 'glitch'
#114The Tweet from the Twitter CTO on this: https://twitter.com/paraga/status/992135139994943488 "We are sharing this information to help people make an informed decision about their account security. We didn’t have to, but believe it’s the right thing to do." The "we didn't have to" is a little jarring given the scale of this.
Well, nothing ever left Twitter's servers. The logs themselves would probably be uninteresting to outside parties and inaccessible.
The fact it didn’t leave Twitter doesn’t mean everything is good. There are still a LOT of people who may have had some kind of access to this data.
Re: Twitter urges users to change passwords after computer 'glitch'
#115Re: Twitter urges users to change passwords after computer 'glitch'
#116The Tweet from the Twitter CTO on this: https://twitter.com/paraga/status/992135139994943488 "We are sharing this information to help people make an informed decision about their account security. We didn’t have to, but believe it’s the right thing to do." The "we didn't have to" is a little jarring given the scale of this.
>The "we didn't have to" is a little jarring given the scale of this. How come? I interpreted it to mean that no regulations required this, but they chose to anyway. Which is true.
Re: Twitter urges users to change passwords after computer 'glitch'
#117Actual twitter post: https://blog.twitter.com/official/en_us/topics/company/2018/... "Due to a bug, passwords were written to an internal log before completing the hashing process. We found this error ourselves, removed the passwords, and are implementing plans to prevent this bug from happening again." Exact same thing that github did just recently.
"[We] are implementing plans to prevent this bug from happening again" sure makes it sound like this bug is still happening. Should we wait a couple of days before changing passwords? Will it end up in this log right now, just like the old one?
Re: Twitter urges users to change passwords after computer 'glitch'
#118Earlier quoted context omitted.
Well, nothing ever left Twitter's servers. The logs themselves would probably be uninteresting to outside parties and inaccessible.
Last year a contractor deleted the president’s account. The fact it didn’t leave Twitter doesn’t mean everything is good. There are still a LOT of people who may have had some kind of access to this data.
The fact that they undeleted it is strong evidence that he didn't have discretion in how he performed his job, and thus was actually an employee and not a contractor.
Re: Twitter urges users to change passwords after computer 'glitch'
#119Earlier quoted context omitted.
Well, nothing ever left Twitter's servers. The logs themselves would probably be uninteresting to outside parties and inaccessible.
Last year a contractor deleted the president’s account. The fact it didn’t leave Twitter doesn’t mean everything is good. There are still a LOT of people who may have had some kind of access to this data.
Re: Twitter urges users to change passwords after computer 'glitch'
#120I highly recommend using a password manager. I finally bit the bullet and started using 1Password a few weeks ago, and I haven't looked back since. It's just so much better than having to remember a thousand different passwords. Besides securely managing passwords, you can also use a password manager to secure your digital legacy. 1Password has a feature where you can print out "emergency kit" sheets that has the inf…